The trojan can also lock devices for ransom if direct fraud attempts fail, showing its operators’ intent to maximize profit from every infection. Its ability to blend overlay attacks, NFC relay components, and automated transactions makes it highly dangerous. After gaining privileges, it installs a third module known as NFSkate, which was originally designed for NFC relay attacks. A new Android banking trojan called RatOn appeared in mid-July 2025 and is already considered one of the most advanced threats of its kind. The company emphasized that no funds were stolen and all accounts remained secure. The luxury retailer said the compromised information was obtained through a third-party provider and was limited to names, contact details, and marketing or loyalty card data.
A significant data breach has hit SplitVPN, a Russian VPN provider formerly known as NotVPN, exposing the personal records of roughly 865,000 unique users. Swiss federal authorities have confirmed a cyberattack targeting SharePoint servers operated by the Federal Office for Information Technology and Telecommunication (BIT). Gain insights to prepare and respond to cyberattacks with greater speed and effectiveness with the IBM X-Force® Threat Intelligence Index. These breaches not only affect the individuals whose data was irretrievably exposed, but also embolden the criminals who profit from their malicious cyberattacks. The company has not publicly confirmed a data breach, but The Los Angeles Times reported that it has been telling people who contacted via email that “we are aware of certain third-party claims about consumer data and are investigating these issues.” SafePay’s unusual approach to cyberattacks — shunning the prevalent ransomware-as-a-service model — makes the hacker group more formidable to defend against, security experts have told CRN.
- Panera reported notifying authorities while investigating the access path and reviewing what data left its environment.
- After containment, SoundCloud experienced denial-of-service attacks, with two incidents briefly disrupting web availability.
- A contractor improperly accessed customer data in Dec, 2025, affecting about 30 people, according to Coinbase.
- A reported DHS insider leak exposed details tied to about 4,500 ICE and Border Patrol workers, and the ICE List project said it would publish verified names as it expanded its database from about 2,000 to roughly 6,500.
- At least 100 million people are now known to be affected by the breach, but the final number is likely to rise.
Overall, cyberattacks in 2025 have continued to pose steep and complex challenges for cybersecurity teams and security service providers. Around 70% of cyberattacks target business email accounts, so having staff that can recognize danger when it’s present is just https://e-beginner.net/category/cybersecurity-fundamentals/ as important as any software. The company managed to shut down the exposed API, but the attackers still managed to obtain roughly 20% of consumer data, which includes people’s names, addresses, dates of birth, and Social Security numbers. Close to 13 million people in Australia — roughly half of the country’s population — had personal and health data stolen in a ransomware attack on prescriptions provider MediSecure in April. In 2025, companies and government agencies have been targeted by a seemingly nonstop series of cyberattacks — including both disruptive ransomware attacks and incidents focused on data theft and extortion.
Plenty of Fish Reportedly Breached as 170 Million User Records Are Offered for Sale
According to reports, the company’s CRM system was compromised, with names, email addresses, telephone numbers, delivery addresses, and some dates of birth exposed during the breach. MailChimp claims that a threat actor was able to gain access to its systems through a social engineering attack, and was then able to access data attached to 133 MailChimp accounts. According to recent reports, customer contact information, ID cards, and/or social security numbers were scraped from PIN-protected accounts, as well as other personal information pertaining to T-Mobile https://www.wrestlingvalley.org/category/general-articles/page/13 customers. The country’s authorities have shut down email and mobile services for government employees in response. The Healthcare provider is one of the biggest in the state, with more than 40 clinics dotted in and around Kentucky’s state capital, Louiseville, TechCrunch reports.
ShinyHunters leaks data from Madison Square Garden and the Knicks
- The data broker allowed its paying customers access to its vast databases of names, dates of birth, email and postal addresses, phone numbers, and Social Security numbers (even though not all of the data was accurate).
- You should also manually remove old accounts, adjust social media privacy settings, and opt out of people-search sites.
- Employee contact lists can fuel spearphishing, SIM swap attempts, and impersonation of newsroom staff, which can pressure sources and disrupt reporting.
- Volvo Group confirmed a significant data breach on 25 September 2025, following a ransomware attack on its Swedish HR software provider, Miljödata.
- The company advises users not to delay updating their browsers to stay protected against potential attacks.
According to reports, the breach potentially exposed phone numbers of targets under surveillance by federal agents. The gang has been behind some of the largest breaches by the number of records stolen, including some 40 million records from internet provider Charter and at least 6 million customer records from cruise liner Carnival, among other victims in higher education, finance, and government. Few companies know better the toll a hack from the ShinyHunters can have than education tech giant Instructure. The English-speaking hackers are adept at tricking companies into turning over access to their internal systems by pretending to be IT support, or conversely, an employee who forgot their password. But as part of the deal, the hackers conceded that another hacking group also had a portion of Klue’s customers’ data and urged those victim companies not to pay them.
ADT said stolen data was limited to names, phone numbers, and addresses, with dates of birth and last-four SSN or tax ID digits included in a small share of cases. ShinyHunters claimed theft of more than10 million records and set a27 Apr, 2026 leak deadline, while Have I Been Pwned later measured the exposed dataset at5.5 million people. Bright Defense can help medical device companies test corporate IT access paths and validate cybersecurity compliance controls before extortion groups turn exposed data into operational and regulatory pressure. The company contained the incident, activated response protocols, hired external cybersecurity experts, and continued reviewing whether personal information was accessed so notifications and support services could follow. Bright Defense can help software companies test vendor access paths and validate compliance controls before third-party support environments become breach entry points.
Vendor risk management governs how healthcare providers assess, contract with, and monitor the platforms holding patient record The official release says the attack may have exposed some staff names and mobile numbers, the system was cleaned within 9 hours, and no mobile devices were compromised. Reporting linked the activity to attacks targeting Ivanti Endpoint Manager Mobile, following Ivanti’s advisory on 29 Jan, 2026 and the Commission’s cybersecurity package announcement on 20 Jan, 2026.
Employee contact lists can fuel spearphishing, SIM swap attempts, and impersonation of newsroom staff, which can pressure sources and disrupt reporting. Qilin still claimed nearly 1TB of data theft and posted sample files, while Conpet reported that operational technology, SCADA, and telecom systems continued to function. The company filed a criminal complaint with DIICOT, engaged national cyber authorities, and is restoring affected business systems while the investigation continues. The Council reported the breach to the regulator, and the regulator filed its own report internally, with both organizations notifying staff and coordinating response with the Dutch NCSC.
The breach exposed personal data for most of Allianz Life’s 1.4 million customers, as well as information on financial professionals and some employees. The organization offered 12 months of https://labverra.com/articles/full-time-job-opportunities-little-rock/ Experian IdentityWorks monitoring to eligible people whose Social Security numbers were involved. Aspire had not found evidence of identity theft or financial fraud connected to the breach when it issued its notice. Michigan-based Aspire Rural Health System disclosed a data breach affecting 138,386 people after an unauthorized party accessed its internal network between 4 November 2024 and 6 January 2025.
Their tactics rely heavily on phishing and social engineering schemes, rather than exploiting vulnerabilities in Salesforce technology itself. The hacking group ShinyHunters has claimed responsibility, with some intelligence hinting at cooperation between ShinyHunters and Scattered Spider, a group recently focused on airline targets. While the vendor’s name remains undisclosed, early signs suggest the cybersecurity breach is part of a broader series of attacks on external CRM platforms. Telecommunications companies continue to face intense pressure from cybercriminals due to the sensitive nature of the financial, governmental, and business information they handle. The Orange breach adds to a string of security incidents targeting the telecom provider in 2025. The incident, reported to national authorities at the end of July, involved ransomware linked to a group calling itself Warlock.