Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Data Leak. Show all posts

Cyberattack Hits University of Munich, Exposing Student Data

 

Germany’s Ludwig Maximilian University of Munich (LMU) is investigating a significant cyberattack that potentially exposed sensitive student information, including financial aid and health insurance data. The breach, detected on a Wednesday, led the university to disconnect affected servers and engage external cyber security experts while cooperating with law enforcement. 

The compromised records reportedly include students’ names, dates of birth, contact details, LMU email addresses, bank account information, and details about their courses of study and prior educational qualifications. In some cases, health insurance numbers and identifiers linked to Germany’s student financial aid program may also have been accessed, along with data related to leaves of absence. However, the university confirmed that examination records, specific course content, and individual academic performance data were not affected. 

Operational impact and response 

Following the discovery of the breach, LMU took several systems offline as a precaution, temporarily disrupting some internal services. While teaching activities continued uninterrupted, enrollment processes were briefly suspended and are expected to resume with extended deadlines to ensure students are not disadvantaged. Some students reported difficulties accessing university services needed for semester preparation, including course registration and grade viewing. The institution has not disclosed the number of affected individuals or the duration of unauthorized access, and no ransom demand has been publicly confirmed. 

Universities remain attractive targets for cybercriminals due to their extensive networks containing vast amounts of personal and financial information across large populations of students, researchers, and staff. Recent ransomware attacks have affected prominent U.S. institutions such as the University of Texas, University of Oklahoma, Stanford University, and the University of Michigan, with several incidents occurring after holiday breaks. Other notable cases include disruptions at the University of Pennsylvania, Columbia University, and Harvard University over the past years.

LMU has enlisted specialists to monitor dark-web forums and other platforms for signs that the stolen information is being circulated or misused. While there is currently no evidence that the data has been altered, deleted, or published, the investigation remains ongoing to determine the full extent of the breach. The attacker has not yet been identified, and the university continues to work with cybersecurity professionals and authorities to secure its systems and protect affected students.

Florida Says Motor Vehicle Data Breach Tied to Credentials Stolen From Officer's Personal Device

 

Officials in Florida confirmed Thursday that the state Department of Motor Vehicles suffered a data breach after credentials were stolen from a police officer who had stored login information on a personal device. The ShinyHunters cybercriminal organization claimed on Monday that it had obtained access to data from the Florida Department of Highway Safety and Motor Vehicles (FLHSMV). 

The department did not respond to repeated requests for comment throughout the week but publicly confirmed the breach's legitimacy on Thursday night. Officials said they first learned of the breach on September 4 and initially attributed it to an unnamed "international cybercriminal organization." 

According to the department, an investigation determined that a criminal actor exploited a single Plant City Police Department user's credentials, which had been improperly stored on the employee's personal electronic device. Plant City is a small suburb outside Tampa. FLHSMV has since notified other Florida government offices and is partnering with the Florida Digital Service to investigate the incident. 

As proof of access, ShinyHunters shared alleged photos of a DMV record tied to American financier and convicted child sex offender Jeffrey Epstein. When claims of the breach first surfaced, some cybersecurity experts speculated it might be connected to the recently confirmed breach involving 153 million driver's licenses leaked by identity verification firm IDScan. ShinyHunters had previously attempted to purchase the ID database from the hackers behind the IDScan breach.

The group has recently claimed responsibility for attacks on bank IT provider Jack Henry, as well as pharmaceutical and healthcare technology company McKesson, which told regulators that data from its oncology and surgical business units had been stolen. ShinyHunters also caused widespread disruption across the U.S. in May with an attack on a widely used educational software suite and stole the information of more than four million people after targeting the world's largest medical device company in April. 

Other victims linked to the group include Carnival Cruises, Ticketmaster, AT&T, McGraw Hill, ADT, and gaming company Rockstar. In a related development, artificial intelligence company Anthropic released a report Thursday stating that suspected affiliates of ShinyHunters used AI to scan for credentials, map unfamiliar systems, and steal data from victims for extortion purposes. 

The report noted that in one case, an operator escalated from a stolen developer token to full administrative access over a victim's cloud environment in approximately three hours. Incident responders at Google also confirmed last week that members of the group are using Anthropic's AI tools at various stages of their attacks. 

The Florida breach adds to a growing list of incidents tied to ShinyHunters, underscoring the group's persistent targeting of both government systems and major corporations, as well as its evolving use of AI tools to accelerate and scale its intrusions.

Turner Discloses Data Breach Exposing Salary Info, Bank Accounts, and SSNs

 

Turner Construction has notified at least 6,098 people of a data breach that uncovered social security numbers, salaries, dates of birth and bank account information used for direct deposit, a filing with the California Office of Attorney General showed. The New York City-based firm found unauthorized access to its systems occurred between July 2 and July 15, the filing with the California Office of Attorney General said. 

Turner confirmed on July 27 that files that contained personal information had been accessed without authorization, and some of the files that were accessed may have also included individuals' passport numbers. Ransomware group Payouts King claimed responsibility for the attack, alleging that the data that had been breached extended far beyond personal data to include engineering documents, military project files, contracts and non-disclosure agreements, a post on ClaimDEPOT, a class-action lawsuit tracking website, said. 

Turner issued a statement that after discovering that unauthorized access to certain files had occurred, the company engaged third-party cybersecurity and forensic experts and that those experts continue to review the files that were accessed. The company said it would notify impacted individuals and other parties as necessary and provide complimentary identity protection services. Turner added it would not comment on claims made by criminal organizations. 

According to ClaimDEPOT, Payouts King first posted information relating to an unidentified victim on July 24 and publicly naming Turner on August 11. The group posted the claims on a Tor network site, which hides the users' locations and identifies, claiming it had obtained 27.2 terabytes of data. Apart from the file types stated in the California attorney general filing, Payouts King claimed it had also accessed documents that were protected under International Traffic in Arms Regulations, which are US government rules regulating the export and import of military items, technology and services. Turner is offering five years of identity protection services through IDShield and IDX, the notices filed with the California AG's office said. 

One of the two notices set a November 18 deadline for affected individuals to enroll. The incident comes amid a wave of attacks targeting construction-related domains, an August 6 post on Google's Threat Intelligence blog identifying potentially compromised sites said. Turner is the largest contractor in the industry by revenue and focuses on data centers and advanced technology construction. The booming data center sector drove the firm to build a $44.3 billion backlog by the end of 2025.  

Several law firms have since posted notices of investigations into the Turner incident, seeking plaintiffs for potential class-action lawsuits. Turner also reported that at least 38 Vermont residents were affected by the breach, according to the Office of the Vermont Attorney General.

IDScan Sued Over Alleged Data Breach Affecting 153 Million Drivers

 

Identity verification company IDScan is being sued in multiple cases after hackers allegedly gained unauthorized access to the service and started selling more than 153 million driver’s licenses via dark web. Markovits, Stock & DeMarco and Hall Attorneys law firms are investigating the class-action claims against the company, which is based in Louisiana. 

Plaintiffs allege that IDScan failed to protect the information of its clients, including car rental company Hertz. Everything started on September 1 when Krebs revealed that a dark-web illegal identity-theft service called Nexus was selling more than 153 million scans of American and Canadian’s driver’s licenses, 10 million ID cards, 3 million travel documents, and 579,000 medical cards. 

He confirmed his sources by searching for his own data and the data of other people who gave their consent to do so. His research showed that all the resources were stolen from IDScan. IDScan sells scanners and specialized software for extracting personal data from official documents. Its technology is used in numerous car rental companies, retail stores, gun shops, banks, pot shops, and hotels across the United States. 

The company has not responded to media inquiries about the data breach, leaving the situation unclear. For now, it is unknown how exactly the breach occurred and how many people were affected. According to Krebs, the Federal Bureau of Investigation (FBI) in New Orleans is investigating the issue, confirming the story, Reuters noted. The FBI spokesperson told Bleepingcomputer that the bureau is looking into the reports but declined further comments due to the sensitivity of the case. The illegal website Nexus that was distributing people’s personal data is closed now. 

However, criminals who stole the information from IDScan still have access to the database. According to Krebs, the compromised data includes the documents of the Secretary of Defense Pete Hegseth and an assistant director of the FBI, which could not be confirmed. Markovits, Stock & DeMarco law firm revealed that IDScan started informing some of its business customers around September 1. The company’s representatives stated that if someone’s ID was scanned in their system, they would contact them to discuss the situation and represent their interests in court. 

In addition, the firm is looking for other organizations to file a class-action lawsuit against the company. Because of the potential number of affected people, other class-action lawsuits may arise, which will have to be consolidated in multidistrict litigation. In addition, other states’ attorneys general and federal regulators may also launch separate investigations into this data security breach. Similar situations with 23andMe, Marriott, and Equifax data compromises happened before and ended in multi-state inquiries or even criminal charges.

Origin Energy Data Breach Traced to Manila Call Centre, Ex-Accenture Employee Identified

 

An ex Accenture worker from Manila is suspected to be behind last month's security breach. Accenture has an office in the city, which supports the energy business in Origin with its customer call centres. It was alleged by a Nine report that the worker attempted to extort the energy provider for money, for its return of the stolen information. 

When approached by ABC News, an Accenture representative said it would be inappropriate to comment on Origin's data security incident. It stated that it is under active investigation. Origin Energy also refused to comment, citing that the breach is the subject of an ongoing criminal investigation. It was revealed the extent of the incident was apparent when, last month, an The Australian reported a hacker had supplied a sample of 50 customer records including names, addresses, emails, dates of birth, phone numbers and billing histories.

Origin Energy reported it to the authorities a potential data breach. The company later told the Business it believed the information of up to 900,000 current and former customers had been accessed. Origin customers told the ABC they felt their personal data could have been breached and expressed frustration with not being given enough detail on the nature of the incident. 

It is the latest in a series of major cybersecurity incidents affecting Australian companies. Qantas suffered a significant hack in 2025, while Optus and Medibank both experienced mass data breaches in 2022. Origin confirmed it became aware of a potential security threat in early July, but did not initially take it seriously. It has advised affected customers to be on guard against scams and said specialist identity and cyber support services are available. 

Origin chief executive Frank Calabria addressed the incident in July, saying the company had completed the first of its review into the customer data security breach. It apologised to customers for placing trust in Origin to safeguard its information. The Australian Federal Police (AFP) confirmed it is working closely with Origin Energy and relevant partners after the reported cyber incident.

An AFP spokesperson said the focus of investigators is on gathering evidence, identifying those responsible and disrupting any associated criminal activity. It added Origin Energy has been cooperative and transparent in its engagement with investigators, and continues to assist the ongoing investigation. No information has yet been released about possible charges against the former Accenture employee identified by the investigation.

Baylor Genetics Confirms Cyberattack Exposed Patient Data

 

Baylor Genetics has disclosed a cybersecurity incident that may have exposed personal information belonging to some patients and employees, but the company says laboratory operations were not interrupted and genetic testing services continued as normal. The incident was detected around June 15, 2026, after suspicious activity appeared in a limited part of its IT environment. 

According to the notice, an unauthorized third party accessed certain parts of Baylor Genetics’ network between June 11 and June 17, 2026. The company then launched a forensic investigation with outside cybersecurity specialists and spent weeks reviewing what data may have been involved and which people were potentially affected. That review was completed on or about July 30, 2026, after which written notices were sent to affected individuals when address information was available. 

The data at issue varied by person, but for patients it may have included names, dates of birth, medical testing information, laboratory test results, and possibly health insurance details. In a very limited number of cases, a Social Security number may also have been involved. For current or former employees, the exposed information may have included Social Security numbers, government-issued identification numbers, and financial account information. 

Baylor Genetics says it immediately secured affected systems, strengthened identity and access controls, enhanced monitoring, and coordinated with law enforcement and appropriate regulators. The company also said it has not found evidence of confirmed identity theft, fraud, or misuse tied to the incident so far. It added that test results remain accurate and that no testing data or results were altered, so no retesting is necessary. 

The notice urges people to watch financial account statements, Explanation of Benefits statements, and credit reports for unusual activity. It also points readers to identitytheft.gov, the Federal Trade Commission, and state attorneys general for help with fraud alerts, credit freezes, and identity-theft complaints. Baylor Genetics has set up a dedicated assistance line at 1-866-200-0985, available Monday through Friday from 9 a.m. to 9 p.m. ET.

Trezor Data Breach Rises to 67,000 US Customers


Hardware cryptocurrency wallet organization Trezor has disclosed that additional 67,000 customers in the US have been impacted by a data breach consisting of its shipping provider, ShipMonk. 

The recent news has notably increased the number of consumers potentially exposed in the incident.  “We're deeply saddened to share the news that the recent data breach affects more customers than originally thought,” Trezor said on X. 

As per Trezor, the additional 67000 customers placed orders from November 2019 to August 2021. 

What is leaked?

The leaked data consists of customers' email, phone numbers, names, addresses, order numbers, and shipping addresses. According to Trezor, the data was stored by ShipMonk even though Trezor had earlier received assurance that previous consumer data had been erased. 

“Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications. We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems,” Trezor said.

According to experts, the breach is not impacting Trezor’s own systems. 

Who are impacted?

Trezor said its hardware wallets are safe and there are no signs that customers’ recovery seed phrases or private keys were breached in the leak. 

As per Trezor, “All affected customers have been emailed directly. If you didn’t receive an email, then you are not affected.”

Potential impact

But Trezor and cybersecurity experts are worried that the stolen data could be exploited for social engineering and targeted phishing attacks. Threat actors could misuse customers’ details regarding their Trezor purchases to create scam phone calls or fraud messages.

This can be a serious problem for cryptocurrency users. A threat actor could mimic a company employee if they know someone owns a Trezor wallet and ask the target to verify their wallet or account. 

User advisory

If successful, the attacker could steal the target’s recovery seed phrase, which can allow access to cryptocurrency funds. “Trezor systems were not compromised, and your device is secure. But please be alert for fake emails, phone calls, fraudulent letters, and potential risks to physical security,” the company added. 

The announcement comes after the August incident when 13,689 customers had been impacted by the same shipping-provider. At the time, Trezor estimated around 14,000 customers to have been affected by the breach. The recent disclosure of 67,000 suggests the scope of the incident was larger than expected.

Thomson Reuters Court Records Breach Exposes Sensitive Data Across North America

 

Sensitive court records and personal information were spilled from a data breach in the court system, which impacts at least 12 states in the U.S., including the U.S. Virgin Islands and Canada, Thomson Reuters announced on Wednesday. The breach occurred in C-Track, a court case management software, run by one of Thomson Reuters’ subsidiaries. 

The company remains silent on how the hackers accessed the program, who was responsible and how much data was compromised, as well as the number of individuals impacted. Thomson Reuters stressed that the breach was within their own environment and “not related to security vulnerabilities in the networks, systems or data of the courts.” The company discovered unauthorized access to its system on June 30, and it initiated an investigation alongside outside cyber security experts and law enforcement. 

Their probe established that unauthorized intruders accessed some C-Track files in March. Meanwhile, a separate disclosure by the Montana Supreme Court revealed that Thomson Reuters advised the state court officials that unauthorized access to C-Track persisted up to June, which means that hackers may have remained undetected within the system for several months. The sensitive information spilled includes names, Social Security numbers, driver licenses, medical information, dates of birth, and health insurance. 

Thomson Reuters added that confidential, redacted, or otherwise restricted information from court records may have been accessed in some jurisdictions, but the company confirmed that no abuse of the situation has occurred. The data breach did not impact the operations of C-Track, which continues to function normally. Thomson Reuters implemented additional security measures, following the breach, after they were approved by outside cybersecurity experts, although the company did not disclose who they were. 

The courts in the U.S. whose data is at risk, according to the company, are the appellate courts in Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, South Carolina, Tennessee, and Wyoming. In addition, several Pennsylvania courts, 10 Ohio district courts of appeals, the Supreme Court, and the Superior Court of the U.S. Virgin Islands are also on the list. The breach in Oregon Judicial Department added another state to the list, expanding the reach to at least 12 states. 

Nevada officials reminded their residents that the types of data compromised differs from state to state, and that not all the data in each state is necessarily confidential or protected. They added that, for example, in Montana, most of the data already was publicly available, but the state’s court system acknowledged the breach of the drivers’ licenses and dates of birth. 

In addition, several of the jurisdictions were notified weeks after Thomson Reuters became aware of the security threat. For example, the court administrator of Montana and the Ontario Ministry of the Attorney General were notified of the unauthorized access to the data on July 23. The chief justices of Ontario agreed that it still remains unclear what information was at risk and how many people were impacted. Thomson Reuters notifies affected individuals that they can receive 12 months of free of credit monitoring and identity theft protection.

Clop-Linked Web Shell Targets PTC Windchill Servers in Data Theft Attacks

 

A custom Java web shell, associated with the Clop ransomware group, was created to target the PTC Windchill and FlexPLM servers by decrypting their credentials, enumerating file repositories, and stealing data. Researchers at cybersecurity firm ReliaQuest discovered the web shell after analyzing the recent data-theft campaign that abused the critical remote code execution vulnerability, CVE-2026-12569, affecting PTC Windchill. 

According to the researchers, the attackers did not use a traditional web shell to gain persistent access to the targeted servers. Instead, they used a custom component that demonstrated an in-depth understanding of the target application’s internal API, database schema, keystore, and file-vault structure. ReliaQuest notes that the discovered resource is an application-specific variation of the Clop ransomware group’s known mass exploitation framework. The web shell was linked to the Clop ransomware group because of extortion e-mails sent by the threat actors using the e-mail addresses associated with the data-leakage web site operated by Clop. 

In addition, the researchers identified X-windchill-req headers used by the web shell, which were also used by the Clop ransomware group in the past, as well as similar tactics, techniques, and procedures (TTPs). Earlier this year, Clop ransomware group’s infrastructure was found to target enterprise business software solutions such as Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer. This campaign, which affected the MOVEit Transfer application, compromised more than 2,770 organizations worldwide. 

The web shell is implemented as JavaServer Pages (JSP), which directly imports the PTC Windchill-specific classes such as MethodContext, WTConnection, and WTKeyStoreUtil, giving the threat actors’ access to PTC Windchill’s native functions, including the database, encrypted credentials decryption, and locating files stored in the application’s vaults. The web shell’s command execution capability was established using the custom protocol that utilizes the HTTP X-windchill-req header. 

Overall, the custom component allowed the attackers to achieve multiple malicious objectives, including Windchill secrets and configuration data theft, file vault discovery and enumeration, directory listing, file retrieval and deletion, executing additional Java classes, and identifying the server’s operating system. Besides that, ReliaQuest reports that the web shell’s implementation contains the Windchill vault enumeration code that queries multiple Windchill database tables, namely ApplicationData, FVITEM, FVMOUNT, and MasteredOnReplicaItem. 

The PTC released a set of security updates to address CVE-2026-12569 on June 17. Additionally, the vulnerability was included in the CISA’s Known Exploited Vulnerabilities catalog earlier this week after the PTC reported active exploitation attempts in the wild. Ransom-ISAC confirmed that ransomware group Clop was behind the attacks by sending extortion emails to the employees of the targeted organizations. ReliaQuest recommends that all the JSP files found in the PTC Windchill directories should be investigated for any suspicious content and that the researchers should look for the X-windchill-req string. 

Moreover, the organizations that determined that their Windchill servers were compromised by the ransomware group should change the LDAP manager’s password and other user credentials because they are considered insecure and may have been leaked.

Chick-fil-A Warns Customers After Credential Stuffing Attack Compromises User Accounts

 

Chick-fil-A notifies customer about personal information exposure after data breach occurred due to credential stuffing attack Chick-fil-A company has announced that personal and account information about some of its customers may have been exposed due to a data breach. This breach occurred through the use of credential stuffing, which is not a vulnerability within the corporation’s website or mobile application.

As explained in the company note to customers, unauthorized access attempts came from bad actors using credentials stolen elsewhere. The company discovered unauthorized access attempts to customer accounts after noticing anomalous activity in the login database, and the phishing campaign occurred between June 17-19, 2026, targeting Chick-fil-A One loyalty program accounts. The corporation concluded its investigation on July 13 th and established that attackers had used compromised credentials to access the account information of some customers. 

The information available to bad actors and potentially at risk of being misused varies depending on the customer’s account. It may include names, contact information, mailing addresses, phone numbers, dates of birth, and Chick-fil-A One account information like ID or QR code and mobile payment credentials. Moreover, attackers may have gained access to reward balances, gift card balances, and the last four digits of payment cards. Although the corporation has not revealed the number of affected clients, the number exceeds several thousand. 

According to the documents filed with the state, 2,182 Texas residents and 39 Massachusetts residents were impacted by the breach. However, there are also other states affected, as notifications to state attorney generals in charge of consumer protection have also been filed, including the District of Columbia. After discovering the issue, the corporation remediated the security risks and notified the affected clients. 

Moreover, Chick-fil-A took measures to enhance account security for all customers, including allowing password reset, account logout, and removing payment methods in the application. Some customers also received bonus points on their accounts as compensation for the issues experienced. Chick-fil-A corporation acknowledges the concern caused by the data breach and assures clients that it takes customer account security seriously. Moreover, the company has recommended that customers change passwords to strong and unique words or phrases not used for other accounts. 

Credential stuffing works only when the same or similar passwords are used across different accounts, so changing them to unique ones decreases the chances of experiencing another breach. Chick-fil-A data breach demonstrates once more that it is crucial to make sure that each online account, including email, banking, and social media accounts, uses a unique and strong password. 

If one suspects that an account may have been compromised, it should be changed to a strong password immediately. Also, it is essential to use multi-factor authentication when available and to monitor account activity regularly for unauthorized transactions or unauthorized access attempts.

Estée Lauder Discloses HR Data Breach Linked to Oracle E-Business Suite Vulnerability

 

Estee Lauder announced that their Oracle E-Business Suite (EBS) system that manages human capital operations was targeted by cyber criminals who managed to steal personal data of some of the company’s employees. The company confirmed that some of the information on the intranet belonged to third parties who were not authorized to access it. 

According to the company’s statement, Estee Lauder learned about the breach following an internal investigation into the cybersecurity incident. Specifically, investigators discovered on June 19, 2026, that unauthorized users accessed the Oracle EBS system on or around August 9, 2025. The data exfiltrated by the hackers varied depending on the individual’s details but generally included names, addresses, and email, birth dates, social security numbers, passport numbers, bank information, medical data, and records of payroll and performance reviews. 

Since the breach involved PII, financial information, and employment data, there is a risk of identity theft and financial fraud for the affected employees. After detecting the anomaly, Estee Lauder contracted cybersecurity experts to conduct a forensic audit, report the pertinent information to the relevant law enforcement agencies, and take additional measures to secure the site. The company is offering 24 months of identity and restoration services through Kroll to all the affected parties free of charge, and the services will be available until October 31, 2026. All the affected employees should remain on the lookout for possible suspicious activities, including monitoring financial accounts, credit reports, and other relevant personal information. 

Even though Estee Lauder did not disclose the identity of the perpetrators, in the context of the discovered timeline, it is plausible to assume that the threat actors who targeted the company are part of the Cl0p extortion group. According to reports by Google and Mandiant, the hacking group utilized several Oracle EBS vulnerabilities, including the zero-day flaw with the reference number CVE-2025-61882, to initiate attacks against other companies. 

The vulnerability that was most likely used in the attack allowed malicious cyber actors to deploy arbitrary code via an unauthenticated HTTP request and affected all Oracle EBS versions from 12.2.3 to 12.2.14. Notably, Oracle released a security patch on October 4, 2025, after detecting that the vulnerability was being actively exploited. The latest breach serves as a reminder of the potential risks associated with the use of enterprise resource planning software that has the capability to store PII and other sensitive information about employees. 

It is strongly advised that organizations that use similar systems remain wary of the threats and make sure that all the relevant software has been updated with the latest security patches while also configuring the tools in a manner that minimizes the attack surface. In addition, enterprise systems should be constantly monitored for any suspicious activities that could indicate possible threats to data security.

Location Sharing: Convenience at the Cost of Safety

 

Location sharing has become a routine feature in messaging, navigation, and social apps, yet it carries security and privacy risks that many users underestimate. While convenient for coordinating meetups or ensuring family safety, careless configuration can expose sensitive patterns about your daily life to strangers, advertisers, and even attackers who compromise the platforms you trust. 

The most immediate danger is physical safety. Continuous location sharing reveals where you live, work, study, and spend leisure time, effectively mapping your routine for anyone with access. Stalkers, harassers, or opportunistic criminals can exploit this data to time thefts, orchestrate impersonation scams, or physically follow you. Real-time updates on platforms like Snapchat’s Snap Maps make it trivial to see when you are home or away, turning a social feature into a surveillance tool if permissions are too broad. 

Beyond individual bad actors, the apps themselves and their data ecosystems present another layer of risk. Many services collect and retain location histories, which can be sold to data brokers, advertisers, or accessed by third parties through data breaches. Incidents like the Gravy Analytics hack show how aggregated location data can leak at scale, exposing users who never intended their movements to be public. Even when companies claim strong security, breaches and insider misuse remain persistent threats in today’s threat landscape. 

Location data also fuels more sophisticated cyberattacks through social engineering and targeted fraud. Attackers can correlate your whereabouts with spending habits, social posts, and device usage to craft convincing phishing messages, fake support calls, or credential-reset scams. For example, seeing that you just visited a shopping mall or a specific campus building can help criminals personalize spam about credit-card fraud or IT alerts, increasing the chance you click a malicious link. Geotagged photos and live stories further amplify this risk by publicly broadcasting your precise coordinates. 

Mitigating these risks requires deliberate permission management and a mindset Of location sharing has become a routine feature in messaging, navigation, and social apps, yet it carries security and privacy risks that many users underestimate. While convenient for coordinating meetups or ensuring family safety, careless configuration can expose sensitive patterns about your daily life to strangers, advertisers, and even attackers who compromise the platforms you trust.

Ernst & Young Notifies Clients Following Third-Party Support Platform Data Breach

 

The company Ernst & Young (EY) has sent out notices to the affected clients about the data breach involving the third-party support ticket platform, which EY’s employees used, and therefore, potentially exposed documents with sensitive tax details to hackers. EY is one of the world’s largest accounting firms that is known to have faced a cybersecurity incident when the unauthorized party gained access to the third-party support ticket platform used by EY’s IT staff on March 28, 2026, and removed several documents from it, reported on April 23, 2026. 

A company statement noted, after reviewing the activity within its environment with the help of outside cybersecurity experts, that the threat actors accessed the EY environment between March 28, 2026, and April 12, 2026. As per the breach notification letter, the documents removed from the support platform could include personal information or financial information, as well as details provided to EY’s support teams during the process of submitting the tickets or in connection with the preparation of the clients’ tax returns. 

EY acknowledges that tax-related information may have been involved in the data security incident but chose not to identify what specific details were affected, as the breach notification letters also include placeholders for the affected customers’ personal information. The company also declined to indicate how many clients were affected by the breach or whether it was limited to the U.S., as there are other EY entities around the globe. EY announced that after detecting the issue, the company took measures to secure the affected systems by cutting down the unauthorized access, and notified the appropriate federal agencies. 

Furthermore, EY has found no evidence that the information from the breach had been deployed or that any particular individuals were the specific targets. Nevertheless, the firm offered its affected clients with credit monitoring and identity theft protection services for 24 months for free from Experian. The customers whose data was at risk were encouraged to sign up for the monitoring services by October 31, 2026. 

At the moment of the announcement, neither ransomware gangs nor data extortionists have claimed responsibility for the cyberattack, nor did any bad actors leak the data or sell it on the dark web. The attack involving the third-party support ticket platform yet again demonstrated the challenges organizations face regarding their ability to protect clients’ data and ensure that their vendors and partners do the same. 

Experts note that companies should invest in making sure their third-party vendors have reliable security practices in place, monitor their activity on a regular basis, and avoid storing any sensitive data on the platforms that can be accessed by numerous individuals, as in the case of EY’s tickets system, to mitigate the risks of supply chain breaches and data leakage incidents.

UK Biobank Data Breach Rekindles Debate Over Research Data Security

 

A recent case concerning the UK Biobank has once again brought up the topic of securing medical research databases, as well as the importance of keeping research data both accessible and private. Professor of Cancer Medicine at the University of Oxford David Kerr pointed out that while sharing scientific data is important, it is also essential to maintain the trust of the general public and ensure the privacy of those whose data is being used. 

UK Biobank is one of the biggest biomedical research databases in the world, established in the early 2000s. It consists of the medical information of half a million people aged between 40 and 69, who volunteered to participate in the program from 2006 to 2010. The database contains genetic, imaging, metabolic, and clinical data on each of the volunteers, making it extremely useful for research into cancer, heart disease, brain conditions, and many other illnesses. Scientists from various corners of the world can apply to use the anonymized data of the UK Biobank volunteers for research purposes. 

According to Professor Kerr, the data from the database has been used to facilitate over 18,000 scientific publications to date. The information contained in the database is anonymized, meaning that the names and other obvious personal identifiers of the donors are removed. However, their ages and sexes are still available for scientific use. The data is invaluable to scientific research, as it has been found to be instrumental in facilitating major medical breakthroughs. 

However, the controversy involving the UK Biobank occurred when three scientists who had accessed the data were accused of trying to sell a part of the database containing the information on thousands of anonymous donors through Alibaba, an international Chinese online marketplace. It is reported that both the UK and Chinese authorities managed to remove the data from the marketplace before any purchases had been made. 

As a result, the three scientists lost their access to the database, and an investigation is currently underway to determine the full extent of the breach and whether personal information has been compromised. UK Biobank has issued a formal apology, calling the security breach a serious matter and stating that they are currently reviewing their security measures. 

According to Professor Kerr, while the database contains a wealth of information that has led to unprecedented international collaboration and research opportunities, such data has to be protected at all times. He noted that with the growing importance of biomedical research, large-scale health data sets have become targets for similar breaches, which has raised multiple concerns for the general public. 

Therefore, both the UK Biobank and the wider scientific community must continue working on protecting medical data sets while allowing unrestricted international collaboration and research.

AssuranceAmerica Data Breach Exposes Personal Information of Nearly 7 Million Individuals

 

Auto insurance company AssuranceAmerica is notifying almost 6.99 million people of the possible exposure of their private information after experiencing a data breach. The company appeared on the state attorney generals earlier this month to reveal the cyberattack occurred on March 16th 2026. 

Almost 7 million clients’ personal information was copied after hackers infiltrated the system using company employees’ credentials before being discovered a day later; they are now alerting policyholders and advising them to remain wary of contacting financial institutions as imposters may be using the stolen information to impersonate them Company officials stated that the information acquired from the breach includes customer’s name, address, social security numbers, driver license numbers, tax ID numbers, insurance policies, and claims history. 

South Carolina, for instance, has over 611,000 customers affected by the data theft, making it the state with the most affected people. The security analysts note that the exposure of personal information such as social security and driver’s license numbers increases the risk of identity theft since the stolen data provides an avenue for thieves to open credit accounts in someone’s name, take out loans, submit fraudulent taxes, circumvent identification processes, and even more. 

Edelson Lechtzin LLP law firm, which is investigating the exposure case, reports that the collected data can offer a wide window for committing financial fraud crimes against the unsuspecting ones. Though the company responded promptly to the issue by taking down their systems after discovering the unusual activity in their network on March 17th, the day after the cyberattack, customers were not notified of what occurred until mid-June, nearly 3 months later. 

According to the insurer’s report, the review of the compromised data concluded on June 15th, days before the customers were informed of what happened, which prompted consumer advocates to criticize the sluggish response by AssuranceAmerica. Furthermore, even though the company asserts that it has reinforced its system and reminded workers of the importance of cybersecurity awareness, it has not stated whether the affected people will be offered free credit monitoring or other services to guarantee their safety. 

The current case comes at a time when there has been a series of data breaches involving the exposure of people’s identities, with hackers targeting government-issued credentials such as licenses and passports. The attacks have been recorded in various industries, including the hospitality, finance, government, and technology sectors, and put every citizen at risk as their personal information is stored in numerous places. 

For instance, the individuals in the states affected by the breach should remain extra cautious when dealing with financial services, whether online or not, and apply for a security alert for their credit reports to help detect unauthorized applications for credit. They can also turn to their respective state attorney’s office to get more significant help. 

The AssuranceAmerica incident is a sobering reminder that the most effortless way to protect oneself is by changing passwords after such an occurrence, especially since other measures such as social security or driver’s license numbers may take longer to replace if they get into the wrong hands.

Govt: Kudankulam Data Breach Did Not Impact Nuclear Security, No Immediate Review Planned

 

The Centre has attempted to reassure the public that the data breach incident involving electronic files of the Kudankulam Nuclear Power Plant (KKNPP) has no implication on the nation’s nuclear security or reactor operations. Union Minister of State for Atomic Energy Jitendra Singh stated that the breach did not affect any sensitive nuclear facility or infrastructure. 

Singh stated during an interaction with reporters on the sidelines of the press conference on July 16 that there was no need for an immediate security review since the breach did not concern nuclear activities or reactors. Nuclear Power Corporation of India Limited (NPCIL), which manages the Kudankulam plant, claimed that the data breach incident did not disclose any sensitive information about reactors. 

“In the given scenario, the data breach is related to the Engineering, Procurement and Construction (EPC) contract for the Common Services–Balance of Plant (BoP) package for Units 3 and 4 under Implementation Agreement 7 (IA-7),” the NPCIL stated. It added that the EPC contract is signed with Reliance Infrastructure via a public tender process in 2018 for Kudankulam NPP. “The balance of plant involves many elements such as auxiliary systems, services, and infrastructure like cooling towers, which are comparable to those in conventional thermal power stations,” NPCIL noted.

It added that the BoP does not contain any nuclear power plant equipment or components or safety and security features. “In this context, NPCIL is not contemplating any First Information Report (FIR) as the cyber-attack was on the data of Reliance Infrastructure,” an NPCIL spokesperson said. They added that the information shared with Reliance Infrastructure during the tendering procedure included indicative drawings and technical specifications on the common services balance of plant, typically provided to all bidders. “This information did not include any sensitive nuclear safety information,” the spokesperson added. 

NPCIL stated that Reliance Infrastructure develops engineering drawings using the technical specifications and drawings provided by NPCIL in coordination with original equipment manufacturers (OEMs) for the approval process. The breach of data came after Reuters reported that ransomware group World Leaks exfiltrated more than 19,000 files from servers hosting Kudankulam Nuclear Power Plant, covering the 2016 fiscal year through mid-2025. 

According to the report, the documents contain details on control, cooling, and ventilation systems, suppliers, inspections conducted by Indian and Russian personnel, meeting records, and insurance data. The breach was attributed to a server managed by data centre infrastructure provider Yotta, hosted by third-party Reliance Group, which was responsible for the EPC contract for the Kudankulam NPP, admitting that the attack resulted in a partial data breach. 

Tamil Nadu-based Kudankulam Nuclear Power Plant currently operates two 1,000 MW VVER reactors and is set to commission four more reactors under the Russian technical collaboration agreement. The project aims to make Kudankulam one of India’s largest nuclear power parks with a total capacity of 6,000 MW. The data breach incident does not appear to affect the nuclear security or safety of the nation, as the government and NPCIL continue to emphasize. 

The breach did, however, raise concerns about the safety of digital assets and data security in various contracts, including those of critical infrastructure like Kudankulam NPP.

Japan's Largest Taxi Service Goes Offline After Cyberattack


Nihon Kotsu, Japan’s largest taxi operator, said that its systems were impacted in a cyberattack, causing the company to close down some of its infrastructure.

The incident happened last week and impacted business operations such as the company’s taxi dispatch system, currently offline.

Nihon Kotsu has an annual revenue of around $1 billion.

The company has 18,228 employees and has 8,588 taxis and over 2000 chauffeur vehicles.

Nihon Kotsu said in a statement, “We have confirmed that our internal systems were subjected to unauthorized external access (malware infection)”. It further added that “immediately after detecting the unauthorized access, we implemented emergency measures, such as disconnecting systems to prevent further damage.”

The impact

The company has closed down systems to offline to stop the threat but it has widely caused disruption in services.

The incident has disrupted web booking, car hire, reservation management, few internal systems, and telephone dispatch service.

Nihon Kotsu advised people to use the ‘GO’ taxi app instead, or use a taxi stand for booking a Nihon Kotsu vehicle. It is a major operational damage for a company that has one of  Tokyo’s biggest fleets but the manual working is still operational. The hire car reservation system is offline.

In a different announcement, Nihon Kotsu said that the “labor taxi” service for pregnant women is shut down in a few areas.

Investigation

The firm has brought in external cybersecurity experts to assist in investigating if there has been a data leak. The internal network has been separated to limit further spread.

Currently, no data leak has been confirmed and Nihon Kotsu will provide updates via official channels. “We are currently conducting a detailed investigation with specialized agencies into whether and to what extent data has been leaked. At this time, no information leak has been confirmed. However, in the unlikely event that we discover any leak or potential leak of personal information of our customers or related parties, we will promptly make an official announcement and contact those affected individually, in accordance with the law,” Nihon Kotsu said.

What next

Customers of Nihon Kotsu are cautioned not to click on any links in suspicious communications purporting to be from the company and not to open anything they receive. 

Mount Royal University says hackers stole and deleted files following June cyberattack





Mount Royal University (MRU) has confirmed that threat actors stole data and deleted files after breaching the university's network in a cyberattack that continues to affect recovery efforts weeks after the incident.

In an update published on its website, the Calgary-based public university said the attack occurred on June 17 and that internal technical teams are working alongside external cybersecurity specialists to investigate the intrusion, determine its full scope, and restore affected systems.

The cyberattack disrupted a wide range of university services, including internet connectivity, online platforms, and several internal systems used across campus. Recovery efforts remain ongoing, with the university warning that restoring all affected services may take several weeks or, in some cases, months.

According to the university's investigation, attackers gained unauthorized access to data stored on the institution's "H drive," a file storage system used by students and employees. Investigators have confirmed that files stored within certain folders were accessed and exfiltrated before the attackers deleted the original copies, a move that has further complicated recovery operations.

"We regret to inform our community that our investigation has now shown that data within certain folders on the University's 'H drive' was accessed and taken by an unauthorized actor," the university said in its advisory.

MRU said the affected folders contained information relating to current and former students, current and former employees, as well as other individuals whose data was stored within the impacted environment. The university has not yet disclosed the exact categories of information exposed or the total number of people affected.

The investigation also found that attackers deleted data stored on a separate departmental file storage system known as the "J drive." While the university said there is currently no evidence that information from the J drive was accessed or copied before it was erased, officials cautioned that recovering the deleted data remains an ongoing process and acknowledged that a complete restoration may not be possible.

The university has reported the incident to the Alberta Information and Privacy Commissioner and notified law enforcement authorities. Officials added that determining the precise impact for each affected individual will take time because the deletion of files has made forensic analysis more complex. Individuals whose information is confirmed to have been affected will receive direct notifications as the investigation progresses.

Responsibility for the attack has been claimed by the cybercrime group CMD Organization, which has published samples of what it alleges is stolen university data, including passport scans and other sensitive documents.

The group is demanding a ransom of 30 Bitcoin, valued at approximately $1.9 million at current exchange rates, and has reportedly given the university six days to respond before releasing additional data. CMD Organization also appears to operate an auction-based extortion model, advertising exclusive access to stolen datasets for the highest bidder through both clear web and dark web leak sites. At the time of writing, the group lists approximately 30 organizations on its extortion portal.

Founded more than a century ago, Mount Royal University currently serves about 11,560 students, including roughly 12,500 undergraduate learners.

As recovery work continues, the university said it will provide additional updates as more information becomes available. MRU is also offering two years of credit monitoring and identity theft protection to current employees and individuals who have worked at the university within the past five years.

Council of Europe Data Breach Exposes Records of 10000 Employees After ShinyHunters Leak


 

Council of Europe is investigating a major data breach following the public release of approximately 297 GB of sensitive employee data by cybercriminal group ShinyHunters following the expiration of a ransom deadline. 

An archive has been leaked that contains information regarding more than 10,000 current and former employees, contractors, and job applicants dating from 15 years ago. As one of Europe's leading human rights organizations since 1949, the Council of Europe has been an official observer at the United Nations since 1949. It represents 46 member states and is a central force in promoting democracy, human rights, and the rule of law throughout Europe. 

Since the information it holds is sensitive, the breach of confidentiality is particularly significant. As reported by ShinyHunters, more than 429,000 files, including personnel data, were obtained from multiple Council departments, including human resources and administrative units. This was one of the largest breaches of personal data involving an intergovernmental organization in Europe. 

Information available indicates that payroll records, bank account information, medical information, tax information, social security information, salary histories, personnel files, and thousands of CVs were exposed. Due to the large size of the dataset, identity theft, financial fraud, and highly targeted phishing are significantly more likely to occur. It has been reported that the breach is related to CVE-2026-35273, a critical 9.8-severity zero-day vulnerability affecting Oracle PeopleSoft's Environment Management Hub (PSEMHUB). 

According to security researchers, the vulnerability allowed attackers to execute arbitrary code remotely without authentication. According to Google's Mandiant team, more than 100 organizations had actively exploited the vulnerability prior to Oracle's release of security guidance. Using the zero-day vulnerability in combination with older vulnerabilities, ShinyHunters obtained persistent access, migrated laterally through compromised environments, and exfiltrated data while posing as legitimate users. 

The exploit was conducted between May 27 and June 9, before mitigations were available. ShinyHunters has also altered its extortion strategy significantly following the Council of Europe declining to meet the ransom demand. In response to the Council's refusal to pay the ransom, ShinyHunters announced it would permanently distribute stolen datasets through multiple mirror sites and torrent networks, thereby reducing the likelihood of future takedown efforts.

In addition, the incident adds to the growing number of campaigns involving ShinyHunterS Researchers have recently linked the group to attacks targeting multiple organizations, while Google's threat intelligence team has linked the group's latest activity to widespread exploitation of the Oracle PeopleSoft zero-day vulnerability before mitigations were available. 

According to a brief statement issued by the Council of Europe, the organization was "investigating the matter and assessing the situation." Further comment was not provided. The organization has not yet announced a formal notification process or measures to protect individuals' identities. Zero-day exploitation and data extortion campaigns are becoming increasingly prevalent, with public disclosure increasingly taking precedence over traditional ransomware encryption. 

The threat of persistent leak strategies is increasing, which is why organizations are being urged to strengthen vulnerability management, accelerate patch deployment, and improve incident response to minimize both institutions and individuals' long-term risks.

Nissan Confirms Employee Data Breach Following Oracle PeopleSoft Zero-Day Cyberattack

 

Nissan has confirmed that it fell victim to a third-party cyberattack after being targeted as an Oracle PeopleSoft user, making it the latest company to suffer an attack due to a yet-revealed vulnerability. The breach is currently under investigation, with Nissan reporting that the attackers could have accessed the personal data of thousands of employees worldwide. 

Based on the breach notification sent to the California Department of Consumer Affairs, Nissan Americas uses Oracle PeopleSoft to perform essential employee management functions, including payroll, taxes, and record-keeping. The attack relied on a zero-day flaw, CVE-2026-35273, which was patched later, with the vulnerability already being actively exploited. There breached data is reported to affect current and former employees in the United States, Canada, Mexico, and Brazil. 

Notably, the data includes social security, banking, financial, and tax information. Nissan is currently investigating the scope of the damage, with the company yet to conclude its research. Researchers report that ShinyHunters extortion gang is behind the identified Oracle PeopleSoft-related attacks, with over 100 companies already reportedly identified as victims of the zero-day flaw. 

Although Nissan was not found on the ShinyHunters data leak site, reports suggest that the cybercriminals might still use the data for extortion. It remains unclear whether the breached data would be published or utilized in ransomware attacks by the threat actors. The vulnerability affecting Oracle PeopleSoft, which has been reported to affect thousands of enterprise users worldwide, continues to raise concerns. 

Since the affected software is designed for critical data, including employee management, the security flaw may have severe implications. Besides Nissan, several companies have been reported to fall victim to the vulnerability, with Everest Ransomware Group recently claiming to have stolen customer data from the car manufacturer. Cybercriminals seem to target major manufacturers, including those based in the United States and threatening to expose the data for extortion. 

Although only a handful of companies have officially confirmed to be victims of the Oracle PeopleSoft cyberattack, others are likely to suffer due to the scale of the problem. National Association of Insurance Commissioners recently confirmed being a victim of the attack, with the University of Nottingham also reportedly being among the affected institutions. 

The most significant damage, however, seems to be related to the education sector, with Illinois Central College and Moody Bible Institute being the only two confirmed victims at the time of the publication. According to cybersecurity analysts, the sector has suffered the largest fallout from the PeopleSoft attack, with several universities reportedly being targeted by the ShinyHunters extortion gang. 

Another PeopleSoft cyberattack serves as a reminder of the constant security challenges facing enterprise users relying on the application to protect sensitive employee data. With investigations into the breach underway, more companies may be identified as victims of the attack in the coming weeks.