A threat actor has released databases allegedly tied to 12 websites, exposing customer accounts, password hashes, addresses, session metadata, and payment identifiers.
A credential-stealing worm spread through hundreds of npm packages by using stolen publisher tokens to automatically compromise additional projects and organizations.
Amgen disclosed a material cloud data breach after attackers stole patient protected health information and proprietary corporate data from third-party cloud environments.
Everest claims to have breached cannabis company STIIIZY, alleging the theft of approximately 420,000 customer records containing identity documents and medical cannabis cards.
A threat actor claims Dante AI was breached, alleging the exposure of 73,547 user accounts and millions of analytics events tied to platform activity.
A threat actor claims King of the Curve was breached, alleging the theft of 330,853 customer profiles and more than 26 million application event records.
ShinyHunters has added Questel, Alcon, and Lumenis to its leak site, alleging the theft of Salesforce records and internal corporate data.
A threat actor claims to have stolen Skywalk Group's WordPress database and website source code, publishing a directory tree as purported evidence of the alleged...
A threat actor claims an IDOR vulnerability in Silvi AI exposed more than 16,000 user records, including email addresses, names, and subscription information.
Researchers who analyzed an alleged SplitVPN database say it contains millions of user records and 58 million VPN connection logs despite the provider's no-logs policy.
A threat actor claims to have stolen Go-Flare's database and Shopware administration source code, though the alleged breach has not been independently verified.
Help support breach monitoring, investigations, infrastructure, and reporting.
Support the site →