Discover the shocking extent of the Toronto Zoo's January 2024 cyberattack, where ransomware crooks snatched visitor data dating back to 2000. Learn about the impact and implications of this massive data breach.
Insight Partners, a major New York-based venture capital and private equity firm, suffered a ransomware attack that compromised thousands of personal records, including PII, financial data, and corporate documents. The breach highlights the targeting of high-value firms by cybercriminals and the critical need for enhanced cybersecurity defenses. Affected individuals and partners must brace for potential identity theft or financial fraud.
A former FinWise Bank employee improperly retained and accessed sensitive customer data of 689,000 American First Finance (AFF) clients after employment termination, exposing personal details tied to loans, lease-to-own accounts, and retail installment agreements. The breach, discovered on May 31, 2024, underscores risks of insider threats in financial institutions and highlights the need for robust offboarding and access controls. FinWise Bank is offering 12 months of free credit monitoring to affected individuals.
In August 2025, Swedish system supplier Miljödata suffered a ransomware attack that exposed 870,000 unique email addresses and highly sensitive personal data, including government-issued identity numbers, names, and physical addresses. The stolen data was published on the dark web, impacting individuals whose data was stored by Miljödata and raising concerns about identity theft and fraud.
The U.S. Department of Homeland Security (DHS) experienced a critical data breach due to a misconfigured intelligence-sharing platform, exposing sensitive national security information including surveillance records to thousands of unauthorized users. This incident directly compromises classified intelligence operations and raises serious concerns about both national security risks and the privacy of American citizens. Immediate remediation and stricter access controls are urgently required to mitigate further exposure.
Unauthorized actors exploited Google's Law Enforcement Request System (LERS) by creating a fraudulent account, gaining access to sensitive user data under the guise of legitimate law enforcement requests. This breach impacts Google's secure portal, law enforcement agencies, and potentially millions of users whose data was requested. The incident underscores systemic vulnerabilities in authentication and monitoring protocols for high-privilege systems.
Hackers exploited a fraudulent account creation vulnerability in Google's Law Enforcement Request System (LERS), gaining unauthorized access to a portal used by law enforcement agencies for sensitive data requests. The breach risks exposing confidential investigations, user data, and enabling impersonation attacks. Google has not disclosed the full scope of compromised data or affected requests.
A former employee of FinWise Bank exploited retained system access post-termination to steal sensitive customer data from 689,000 American First Finance clients. The breach highlights critical vulnerabilities in insider threat mitigation and post-employment access controls. Affected individuals face heightened risks of identity theft and financial fraud.
A cybersecurity breach in one organization can trigger cascading reputational and operational damage to interconnected partners, suppliers, or industry peers due to shared supply chains, public perception, or regulatory scrutiny. Businesses with third-party dependencies face heightened risks of customer distrust, compliance audits, and supply chain disruptions even without direct involvement in the breach. Proactive risk assessment and vendor due diligence are critical to mitigate association risk.
A former employee of FinWise, a US-based fintech company, accessed nearly 700,000 customer records undetected for over a year, raising concerns about insider threats and weak access controls. The breach affects customers of FinWise and highlights systemic failures in post-employment access management. Affected parties must verify exposure and monitor for fraud.
The Black Basta ransomware group breached Fairmont Federal Credit Union (FFCU) between September 30 and October 18, 2023, exposing personal, financial, and medical data of 187,038 members. The breach was discovered in January 2024 and confirmed in August 2025, prompting free credit monitoring offers to affected individuals. No fraud has been reported to date.
Companies face severe financial, legal, and reputational risks due to improper data destruction during IT hardware refreshes, particularly during Windows 10 end-of-life transitions. Failure to securely erase decommissioned devices exposes sensitive data, violating regulations like GDPR, CCPA, and HIPAA. Affected industries include healthcare, finance, and technology, with fines exceeding $2.5M and lawsuits from data breaches.
The ShinyHunters hacking group breached Vietnam’s National Credit Information Center (CIC) via an unpatched 'n-day' vulnerability in outdated end-of-life software, exposing sensitive financial data linked to major Vietnamese banks. The attack, which did not involve ransomware but instead listed stolen data for sale on the Dark Web, poses severe risks of identity theft, financial fraud, and systemic instability in Vietnam’s financial sector. Immediate mitigation and forensic investigations are critical to limit damage.
A third-party vendor breach exposed LNER customer contact details and travel history, including names, emails, phone numbers, and booking data. Affected customers may face phishing risks, though financial or password data remains secure. The incident highlights vulnerabilities in third-party supply chain security, requiring heightened vigilance.
A shocking data breach exposed 1.6 million audio files containing voicemails and calls online. Discover the implications, risks, and how such vulnerabilities can impact individuals and organizations.
UK rail operator LNER confirms a data breach after an attacker steals customer data during a break-in at a third-party supplier. Learn about the incident, its implications, and the growing trend of third-party cybersecurity risks.
Discover the critical lessons from the TeleMessage data breach in 2025 and learn how financial services can enhance their cybersecurity strategies to protect sensitive communications and data.
The Scattered Lapsus$ Hunters group executed a cyberattack on Jaguar Land Rover (JLR) in September 2025, disrupting factory operations and confirming a data breach. The attack compromised sensitive internal systems, halting production at JLR’s Solihull plant and affecting retail registrations and supply chains.
An unsecured Elasticsearch instance exposed 116GB of user data from Vyro AI’s AI chatbots, including prompts, authentication tokens, and device details, due to a lack of basic security controls. Over 150 million app downloads across ImagineArt, Chatly, and Chatbotx were impacted, risking account hijacking, privacy violations, and further exploitation. This highlights systemic vulnerabilities in AI chatbot security requiring immediate regulatory and technical action.
Microsoft Teams introduced a real-time feature to detect and warn users about malicious links in private chats, reducing phishing risks. This update affects all Microsoft Teams users globally, enhancing workplace cybersecurity by proactively blocking potential threats before they cause harm.
A significant data breach at a Birmingham secondary school exposed hundreds of students' personal information due to an email error involving flu jab notifications. Learn about the incident, its impact, and the broader implications for data privacy in educational institutions.
Jaguar Land Rover confirms a cyberattack led to data theft, forcing system shutdowns and operational disruptions. Learn about the impact, response, and implications for cybersecurity in the automotive industry.
Discover how the KillSec ransomware group exploited an insecure AWS S3 bucket to breach MedicSolution, a Brazilian healthcare software provider, exposing 34GB of sensitive patient data. Learn about the broader implications for healthcare cybersecurity in Brazil and beyond.
Plex confirms a data breach exposing user emails, usernames, and hashed passwords. Learn how to secure your account, enable 2FA, and protect your digital identity.
Jaguar Land Rover confirms a cyberattack exposed 'some data' as systems remain offline. Learn about the breach, its impact, and the ongoing investigation.
Discover how leading Chief Information Security Officers (CISOs) successfully secure budget approval by aligning cybersecurity investments with business goals, demonstrating ROI, and communicating risks effectively.
Plex, the popular media streaming platform, has suffered a data breach exposing user authentication data. Learn about the incident, its implications, and the steps users should take to secure their accounts.
Discover how a compromised GitHub account led to a supply chain breach affecting 22 companies through Salesloft's Drift application. Learn about the threat actor UNC6395, the timeline of the attack, and the broader implications for cybersecurity.