Data Breaches

Latest data breaches news, vulnerabilities, CVEs, and threat intelligence from 50+ trusted cybersecurity sources.

Ransomware Attack on Insight Partners: Thousands of Personal Records Compromised

Insight Partners, a major New York-based venture capital and private equity firm, suffered a ransomware attack that compromised thousands of personal records, including PII, financial data, and corporate documents. The breach highlights the targeting of high-value firms by cybercriminals and the critical need for enhanced cybersecurity defenses. Affected individuals and partners must brace for potential identity theft or financial fraud.

#ransomware #data breach #cybersecurity

Read full article →

Insider Data Breach at FinWise Bank: 689,000 American First Finance Customers Exposed

A former FinWise Bank employee improperly retained and accessed sensitive customer data of 689,000 American First Finance (AFF) clients after employment termination, exposing personal details tied to loans, lease-to-own accounts, and retail installment agreements. The breach, discovered on May 31, 2024, underscores risks of insider threats in financial institutions and highlights the need for robust offboarding and access controls. FinWise Bank is offering 12 months of free credit monitoring to affected individuals.

#data breach #insider threat #cybersecurity

Read full article →

Miljödata Data Breach: 870,000 Swedish Records Exposed in Ransomware Attack

In August 2025, Swedish system supplier Miljödata suffered a ransomware attack that exposed 870,000 unique email addresses and highly sensitive personal data, including government-issued identity numbers, names, and physical addresses. The stolen data was published on the dark web, impacting individuals whose data was stored by Miljödata and raising concerns about identity theft and fraud.

#data breach #cybersecurity #ransomware

Read full article →

DHS Data Breach: How a Misconfigured Platform Exposed Sensitive National Security Information

The U.S. Department of Homeland Security (DHS) experienced a critical data breach due to a misconfigured intelligence-sharing platform, exposing sensitive national security information including surveillance records to thousands of unauthorized users. This incident directly compromises classified intelligence operations and raises serious concerns about both national security risks and the privacy of American citizens. Immediate remediation and stricter access controls are urgently required to mitigate further exposure.

#dhs #data breach #cybersecurity

Read full article →

Google's Law Enforcement Request System Breached: How Criminals Exploited a Critical Vulnerability

Unauthorized actors exploited Google's Law Enforcement Request System (LERS) by creating a fraudulent account, gaining access to sensitive user data under the guise of legitimate law enforcement requests. This breach impacts Google's secure portal, law enforcement agencies, and potentially millions of users whose data was requested. The incident underscores systemic vulnerabilities in authentication and monitoring protocols for high-privilege systems.

#cybersecurity #data breach #law enforcement

Read full article →

Google Confirms Security Breach: Hackers Infiltrate Law Enforcement Request System

Hackers exploited a fraudulent account creation vulnerability in Google's Law Enforcement Request System (LERS), gaining unauthorized access to a portal used by law enforcement agencies for sensitive data requests. The breach risks exposing confidential investigations, user data, and enabling impersonation attacks. Google has not disclosed the full scope of compromised data or affected requests.

#google #cybersecurity #data breach

Read full article →

FinWise Bank Insider Breach Exposes Data of 689,000 American First Finance Customers

A former employee of FinWise Bank exploited retained system access post-termination to steal sensitive customer data from 689,000 American First Finance clients. The breach highlights critical vulnerabilities in insider threat mitigation and post-employment access controls. Affected individuals face heightened risks of identity theft and financial fraud.

#data breach #insider threat #cybersecurity

Read full article →

Navigating Association Risk: How Third-Party Breaches Impact Your Business

A cybersecurity breach in one organization can trigger cascading reputational and operational damage to interconnected partners, suppliers, or industry peers due to shared supply chains, public perception, or regulatory scrutiny. Businesses with third-party dependencies face heightened risks of customer distrust, compliance audits, and supply chain disruptions even without direct involvement in the breach. Proactive risk assessment and vendor due diligence are critical to mitigate association risk.

#cybersecurity #third-party risk #data breaches

Read full article →

FinWise Data Breach: Former Employee Accessed Nearly 700,000 Customer Records Undetected for Over a Year

A former employee of FinWise, a US-based fintech company, accessed nearly 700,000 customer records undetected for over a year, raising concerns about insider threats and weak access controls. The breach affects customers of FinWise and highlights systemic failures in post-employment access management. Affected parties must verify exposure and monitor for fraud.

#data breach #insider threat #cybersecurity

Read full article →

Fairmont Federal Credit Union Data Breach: 187,000 Affected by 2023 Cyberattack

The Black Basta ransomware group breached Fairmont Federal Credit Union (FFCU) between September 30 and October 18, 2023, exposing personal, financial, and medical data of 187,038 members. The breach was discovered in January 2024 and confirmed in August 2025, prompting free credit monitoring offers to affected individuals. No fraud has been reported to date.

#data breach #cybersecurity #black basta ransomware

Read full article →

The Hidden Costs of Improper Data Destruction: How Companies Risk Millions in Fines and Lawsuits

Companies face severe financial, legal, and reputational risks due to improper data destruction during IT hardware refreshes, particularly during Windows 10 end-of-life transitions. Failure to securely erase decommissioned devices exposes sensitive data, violating regulations like GDPR, CCPA, and HIPAA. Affected industries include healthcare, finance, and technology, with fines exceeding $2.5M and lawsuits from data breaches.

#data destruction #cybersecurity #it compliance

Read full article →

ShinyHunters Cyberattack: Vietnam’s National Credit Information Center Data Breach Exposed

The ShinyHunters hacking group breached Vietnam’s National Credit Information Center (CIC) via an unpatched 'n-day' vulnerability in outdated end-of-life software, exposing sensitive financial data linked to major Vietnamese banks. The attack, which did not involve ransomware but instead listed stolen data for sale on the Dark Web, poses severe risks of identity theft, financial fraud, and systemic instability in Vietnam’s financial sector. Immediate mitigation and forensic investigations are critical to limit damage.

#data breach #cyberattack #shinyhunters

Read full article →

AI Chatbot Data Leaks: Causes, Risks, and the Urgent Need for Security Regulations

An unsecured Elasticsearch instance exposed 116GB of user data from Vyro AI’s AI chatbots, including prompts, authentication tokens, and device details, due to a lack of basic security controls. Over 150 million app downloads across ImagineArt, Chatly, and Chatbotx were impacted, risking account hijacking, privacy violations, and further exploitation. This highlights systemic vulnerabilities in AI chatbot security requiring immediate regulatory and technical action.

#ai security #data leaks #cybersecurity regulations

Read full article →