home.social

Search

277 results for “zacpwhite”

  1. Bulgarian hacker “Emil Külev” arrested and detained:

    databreaches.net/2024/06/30/bu

    21--year-old Teodor Iliev accused of hacking and leaking 2.2 million records from LEV INS, the biggest insurance firm in Bulgaria in 2023. Also accused of hacking banks and other entities.

    #Magadans #EmilKülev #EmilKyulev #cybercrime #hacking #databreach

    @BleepingComputer @dangoodin @zackwhittaker @campuscodi @DarkWebInformer

  2. Bulgarian hacker “Emil Külev” arrested and detained:

    databreaches.net/2024/06/30/bu

    21--year-old Teodor Iliev accused of hacking and leaking 2.2 million records from LEV INS, the biggest insurance firm in Bulgaria in 2023. Also accused of hacking banks and other entities.

    #Magadans #EmilKülev #EmilKyulev #cybercrime #hacking #databreach

    @BleepingComputer @dangoodin @zackwhittaker @campuscodi @DarkWebInformer

  3. Bulgarian hacker “Emil Külev” arrested and detained:

    databreaches.net/2024/06/30/bu

    21--year-old Teodor Iliev accused of hacking and leaking 2.2 million records from LEV INS, the biggest insurance firm in Bulgaria in 2023. Also accused of hacking banks and other entities.

    #Magadans #EmilKülev #EmilKyulev #cybercrime #hacking #databreach

    @BleepingComputer @dangoodin @zackwhittaker @campuscodi @DarkWebInformer

  4. An email from the FBI to #NiceNIC that was shared with DataBreaches shows the FBI trying to explain to NiceNIC why they should transfer the #BreachForums domains back to FBI nameservers or at least prevent their use by the criminals.

    databreaches.net/2024/05/22/di

    And not for nothing, but it has been seven days since BreachForums.st was seized, and the DOJ and its partners in other countries have yet to issue a press release or confirm whether there were any arrests.

    @BleepingComputer @zackwhittaker @campuscodi

  5. So… it's a new year… 2024 at long last. It's literally new year's day, and the whole year now follows. We've got 366 days until we're doing the same thing again.

    Here are some people that you might consider following for your timeline. This is not an exhaustive list.

    #Journalists: @dangoodin, @benjedwards… both writers for @arstechnica

    @[email protected] #AmateurRadio operator and journalist for @VOANews

    @mmasnick journalist for #TechDirt

    @lorenzofb, @zackwhittaker journalists for #TechCrunch

    @codinghorror writer for #CodingHorror

    @briankrebs independent #InfoSec writer and journalist

    @[email protected] / @north@ꩰ.com playfully prodding sites' punycode domain compatibility 🙂

    #Ukraine

    @EugeneMcParland has been posting lots of news about the conflict

    @Gala posts lots of photos and videos showing life in Ukraine -- some beautiful scenery

    #RetroComputing and #RetroTech

    @Gammitin posts lots about restoring classic PCs

    @kenshirriff does lots of deep dives into old tech of all sorts… deep analysis of classic ICs, old mechanical avionics, all sorts.

    #Gambia

    @buba has been posting lots of photos from his native Gambia (west coast of Africa)

    #AmateurRadio

    @xssfox has been experimenting with all kinds of radio-related things (as well as putting monitors on crooked angles).

    #NewYearFollows

  6. So… it's a new year… 2024 at long last. It's literally new year's day, and the whole year now follows. We've got 366 days until we're doing the same thing again.

    Here are some people that you might consider following for your timeline. This is not an exhaustive list.

    #Journalists: @dangoodin, @benjedwards… both writers for @arstechnica

    @[email protected] #AmateurRadio operator and journalist for @VOANews

    @mmasnick journalist for #TechDirt

    @lorenzofb, @zackwhittaker journalists for #TechCrunch

    @codinghorror writer for #CodingHorror

    @briankrebs independent #InfoSec writer and journalist

    @[email protected] / @north@ꩰ.com playfully prodding sites' punycode domain compatibility 🙂

    #Ukraine

    @EugeneMcParland has been posting lots of news about the conflict

    @Gala posts lots of photos and videos showing life in Ukraine -- some beautiful scenery

    #RetroComputing and #RetroTech

    @Gammitin posts lots about restoring classic PCs

    @kenshirriff does lots of deep dives into old tech of all sorts… deep analysis of classic ICs, old mechanical avionics, all sorts.

    #Gambia

    @buba has been posting lots of photos from his native Gambia (west coast of Africa)

    #AmateurRadio

    @xssfox has been experimenting with all kinds of radio-related things (as well as putting monitors on crooked angles).

    #NewYearFollows

  7. So… it's a new year… 2024 at long last. It's literally new year's day, and the whole year now follows. We've got 366 days until we're doing the same thing again.

    Here are some people that you might consider following for your timeline. This is not an exhaustive list.

    #Journalists: @dangoodin, @benjedwards… both writers for @arstechnica

    @[email protected] #AmateurRadio operator and journalist for @VOANews

    @mmasnick journalist for #TechDirt

    @lorenzofb, @zackwhittaker journalists for #TechCrunch

    @codinghorror writer for #CodingHorror

    @briankrebs independent #InfoSec writer and journalist

    @[email protected] / @north@ꩰ.com playfully prodding sites' punycode domain compatibility 🙂

    #Ukraine

    @EugeneMcParland has been posting lots of news about the conflict

    @Gala posts lots of photos and videos showing life in Ukraine -- some beautiful scenery

    #RetroComputing and #RetroTech

    @Gammitin posts lots about restoring classic PCs

    @kenshirriff does lots of deep dives into old tech of all sorts… deep analysis of classic ICs, old mechanical avionics, all sorts.

    #Gambia

    @buba has been posting lots of photos from his native Gambia (west coast of Africa)

    #AmateurRadio

    @xssfox has been experimenting with all kinds of radio-related things (as well as putting monitors on crooked angles).

    #NewYearFollows

  8. So… it's a new year… 2024 at long last. It's literally new year's day, and the whole year now follows. We've got 366 days until we're doing the same thing again.

    Here are some people that you might consider following for your timeline. This is not an exhaustive list.

    #Journalists: @dangoodin, @benjedwards… both writers for @arstechnica

    @[email protected] #AmateurRadio operator and journalist for @VOANews

    @mmasnick journalist for #TechDirt

    @lorenzofb, @zackwhittaker journalists for #TechCrunch

    @codinghorror writer for #CodingHorror

    @briankrebs independent #InfoSec writer and journalist

    @[email protected] / @north@ꩰ.com playfully prodding sites' punycode domain compatibility 🙂

    #Ukraine

    @EugeneMcParland has been posting lots of news about the conflict

    @Gala posts lots of photos and videos showing life in Ukraine -- some beautiful scenery

    #RetroComputing and #RetroTech

    @Gammitin posts lots about restoring classic PCs

    @kenshirriff does lots of deep dives into old tech of all sorts… deep analysis of classic ICs, old mechanical avionics, all sorts.

    #Gambia

    @buba has been posting lots of photos from his native Gambia (west coast of Africa)

    #AmateurRadio

    @xssfox has been experimenting with all kinds of radio-related things (as well as putting monitors on crooked angles).

    #NewYearFollows

  9. So… it's a new year… 2024 at long last. It's literally new year's day, and the whole year now follows. We've got 366 days until we're doing the same thing again.

    Here are some people that you might consider following for your timeline. This is not an exhaustive list.

    #Journalists: @dangoodin, @benjedwards… both writers for @arstechnica

    @[email protected] #AmateurRadio operator and journalist for @VOANews

    @mmasnick journalist for #TechDirt

    @lorenzofb, @zackwhittaker journalists for #TechCrunch

    @codinghorror writer for #CodingHorror

    @briankrebs independent #InfoSec writer and journalist

    @[email protected] / @north@ꩰ.com playfully prodding sites' punycode domain compatibility 🙂

    #Ukraine

    @EugeneMcParland has been posting lots of news about the conflict

    @Gala posts lots of photos and videos showing life in Ukraine -- some beautiful scenery

    #RetroComputing and #RetroTech

    @Gammitin posts lots about restoring classic PCs

    @kenshirriff does lots of deep dives into old tech of all sorts… deep analysis of classic ICs, old mechanical avionics, all sorts.

    #Gambia

    @buba has been posting lots of photos from his native Gambia (west coast of Africa)

    #AmateurRadio

    @xssfox has been experimenting with all kinds of radio-related things (as well as putting monitors on crooked angles).

    #NewYearFollows

  10. I guess I'll be getting a hack notification letter from Mr. Cooper soon.

    My wife and I were so excited and proud to pay off our mortgage a few years ago. Sounds like that may not have been enough to get us off Cooper's books and protect our data.

    Story from @zackwhittaker techcrunch.com/2023/12/18/mr-c

    #infosec #hacking #hack #realestate #mrcooper #mortgage

  11. CW: Sexual Content

    I got a few boosts and likes on my last Alicyn Sterling, Classic Porn video so I thought I would share a whole goddamn hour and a half movie of some of her best scenes in one fucking movie. Jesus Christ I still lust for her. Find the download link on my NewTumbl page! See pinned Toots..
    mrblasphemy.newtumbl.com/post/
    #alicynsterling #classicporn #porn #missileboobs #bigtits #blond #90's #retroporn #zarawhites #ttboy #puffynipples #lesbian #outdoorsex #kitchensex #titworship #buckadams

  12. NEW: My post on the student/k-12 tips exposed in "BlueLeaks 2.0" is now up.

    P3 Campus and its partner programs like Safe2Say Something PA, Safe2Tell, and Sandy Hook Promise were supposed to provide secure and anonymous ability to report tips.

    Promises of security and anonymity do not appear to have been kept. A hacker claims it was easy to gain access and repeatedly access the database to acquire more than 8 million tips.

    There is not much anonymous about what I reviewed in the dataset.

    Many of the school-related tips I reviewed reported concerns over named students with suicidal ideation or cutting, students being bullied or bullying others, and drugs (mostly vaping) in school. Some students reported cybercriminal activity.

    Navigate360, the parent company of P3, still hasn't publicly acknowledged that it was breached and that sensitive information was involved. Their lack of transparency was noted by @douglevin

    The dataset has not been leaked publicly, but the "Internet Yiff Machine" who provided it to #ddosecrets and infosec.exchange/@mikaelthalen -- and then to me -- has listed it for sale.

    My focus in this post was on the student/school -related tips, but the 93.51 GB dataset has millions of tips that include adult issues and crimes, including drugs, homicide, assaults, etc. I provide one or two examples from the non-student tips to illustrate how sensitive the tips are in this dataset.

    This may be the worst breach I've ever seen involving sensitive student information, and I've seen many student-related data breaches over the past two decades.

    Read: "P3 Advertised 20+ Years and 0 Security Breaches. You Can Guess What Happened Next.'" at databreaches.net/2026/04/16/p3

    #BlueLeaks2 #DDoSecrets #databreach #P3Campus #P3Tips #Navigate360 #CrimeStoppers #Safety #Safe2tell #InternetYiffMachine

    @zackwhittaker @campuscodi @jgreig @euroinfosec @funnymonkey @mkeierleber @JayeLTee

  13. NEW: My post on the student/k-12 tips exposed in "BlueLeaks 2.0" is now up.

    P3 Campus and its partner programs like Safe2Say Something PA, Safe2Tell, and Sandy Hook Promise were supposed to provide secure and anonymous ability to report tips.

    Promises of security and anonymity do not appear to have been kept. A hacker claims it was easy to gain access and repeatedly access the database to acquire more than 8 million tips.

    There is not much anonymous about what I reviewed in the dataset.

    Many of the school-related tips I reviewed reported concerns over named students with suicidal ideation or cutting, students being bullied or bullying others, and drugs (mostly vaping) in school. Some students reported cybercriminal activity.

    Navigate360, the parent company of P3, still hasn't publicly acknowledged that it was breached and that sensitive information was involved. Their lack of transparency was noted by @douglevin

    The dataset has not been leaked publicly, but the "Internet Yiff Machine" who provided it to #ddosecrets and infosec.exchange/@mikaelthalen -- and then to me -- has listed it for sale.

    My focus in this post was on the student/school -related tips, but the 93.51 GB dataset has millions of tips that include adult issues and crimes, including drugs, homicide, assaults, etc. I provide one or two examples from the non-student tips to illustrate how sensitive the tips are in this dataset.

    This may be the worst breach I've ever seen involving sensitive student information, and I've seen many student-related data breaches over the past two decades.

    Read: "P3 Advertised 20+ Years and 0 Security Breaches. You Can Guess What Happened Next.'" at databreaches.net/2026/04/16/p3

    #BlueLeaks2 #DDoSecrets #databreach #P3Campus #P3Tips #Navigate360 #CrimeStoppers #Safety #Safe2tell #InternetYiffMachine

    @zackwhittaker @campuscodi @jgreig @euroinfosec @funnymonkey @mkeierleber @JayeLTee

  14. NEW: My post on the student/k-12 tips exposed in "BlueLeaks 2.0" is now up.

    P3 Campus and its partner programs like Safe2Say Something PA, Safe2Tell, and Sandy Hook Promise were supposed to provide secure and anonymous ability to report tips.

    Promises of security and anonymity do not appear to have been kept. A hacker claims it was easy to gain access and repeatedly access the database to acquire more than 8 million tips.

    There is not much anonymous about what I reviewed in the dataset.

    Many of the school-related tips I reviewed reported concerns over named students with suicidal ideation or cutting, students being bullied or bullying others, and drugs (mostly vaping) in school. Some students reported cybercriminal activity.

    Navigate360, the parent company of P3, still hasn't publicly acknowledged that it was breached and that sensitive information was involved. Their lack of transparency was noted by @douglevin

    The dataset has not been leaked publicly, but the "Internet Yiff Machine" who provided it to #ddosecrets and infosec.exchange/@mikaelthalen -- and then to me -- has listed it for sale.

    My focus in this post was on the student/school -related tips, but the 93.51 GB dataset has millions of tips that include adult issues and crimes, including drugs, homicide, assaults, etc. I provide one or two examples from the non-student tips to illustrate how sensitive the tips are in this dataset.

    This may be the worst breach I've ever seen involving sensitive student information, and I've seen many student-related data breaches over the past two decades.

    Read: "P3 Advertised 20+ Years and 0 Security Breaches. You Can Guess What Happened Next.'" at databreaches.net/2026/04/16/p3

    #BlueLeaks2 #DDoSecrets #databreach #P3Campus #P3Tips #Navigate360 #CrimeStoppers #Safety #Safe2tell #InternetYiffMachine

    @zackwhittaker @campuscodi @jgreig @euroinfosec @funnymonkey @mkeierleber @JayeLTee

  15. NEW: My post on the student/k-12 tips exposed in "BlueLeaks 2.0" is now up.

    P3 Campus and its partner programs like Safe2Say Something PA, Safe2Tell, and Sandy Hook Promise were supposed to provide secure and anonymous ability to report tips.

    Promises of security and anonymity do not appear to have been kept. A hacker claims it was easy to gain access and repeatedly access the database to acquire more than 8 million tips.

    There is not much anonymous about what I reviewed in the dataset.

    Many of the school-related tips I reviewed reported concerns over named students with suicidal ideation or cutting, students being bullied or bullying others, and drugs (mostly vaping) in school. Some students reported cybercriminal activity.

    Navigate360, the parent company of P3, still hasn't publicly acknowledged that it was breached and that sensitive information was involved. Their lack of transparency was noted by @douglevin

    The dataset has not been leaked publicly, but the "Internet Yiff Machine" who provided it to #ddosecrets and infosec.exchange/@mikaelthalen -- and then to me -- has listed it for sale.

    My focus in this post was on the student/school -related tips, but the 93.51 GB dataset has millions of tips that include adult issues and crimes, including drugs, homicide, assaults, etc. I provide one or two examples from the non-student tips to illustrate how sensitive the tips are in this dataset.

    This may be the worst breach I've ever seen involving sensitive student information, and I've seen many student-related data breaches over the past two decades.

    Read: "P3 Advertised 20+ Years and 0 Security Breaches. You Can Guess What Happened Next.'" at databreaches.net/2026/04/16/p3

    #BlueLeaks2 #DDoSecrets #databreach #P3Campus #P3Tips #Navigate360 #CrimeStoppers #Safety #Safe2tell #InternetYiffMachine

    @zackwhittaker @campuscodi @jgreig @euroinfosec @funnymonkey @mkeierleber @JayeLTee

  16. NEW: My post on the student/k-12 tips exposed in "BlueLeaks 2.0" is now up.

    P3 Campus and its partner programs like Safe2Say Something PA, Safe2Tell, and Sandy Hook Promise were supposed to provide secure and anonymous ability to report tips.

    Promises of security and anonymity do not appear to have been kept. A hacker claims it was easy to gain access and repeatedly access the database to acquire more than 8 million tips.

    There is not much anonymous about what I reviewed in the dataset.

    Many of the school-related tips I reviewed reported concerns over named students with suicidal ideation or cutting, students being bullied or bullying others, and drugs (mostly vaping) in school. Some students reported cybercriminal activity.

    Navigate360, the parent company of P3, still hasn't publicly acknowledged that it was breached and that sensitive information was involved. Their lack of transparency was noted by @douglevin

    The dataset has not been leaked publicly, but the "Internet Yiff Machine" who provided it to #ddosecrets and infosec.exchange/@mikaelthalen -- and then to me -- has listed it for sale.

    My focus in this post was on the student/school -related tips, but the 93.51 GB dataset has millions of tips that include adult issues and crimes, including drugs, homicide, assaults, etc. I provide one or two examples from the non-student tips to illustrate how sensitive the tips are in this dataset.

    This may be the worst breach I've ever seen involving sensitive student information, and I've seen many student-related data breaches over the past two decades.

    Read: "P3 Advertised 20+ Years and 0 Security Breaches. You Can Guess What Happened Next.'" at databreaches.net/2026/04/16/p3

    #BlueLeaks2 #DDoSecrets #databreach #P3Campus #P3Tips #Navigate360 #CrimeStoppers #Safety #Safe2tell #InternetYiffMachine

    @zackwhittaker @campuscodi @jgreig @euroinfosec @funnymonkey @mkeierleber @JayeLTee

  17. And it's out!

    Zack Whittaker and I have released our report on the pilot survey we conducted to increase awareness about threats security researchers and journalists who report on cybersecurity and cybercrime experience.

    We are grateful to all those who responded to the survey and shared a bit of their experiences. Based on what we found in a pilot survey with a non-random sample, I really think we need to do a bigger study that can also do a deeper dive into some questions.

    You can read the report in html or download the .pdf version:

    html: databreaches.net/2026/02/02/un

    pdf: databreaches.net/wp-content/up

    In conjunction with the release of the report, I've also added a new "Threats" category to DataBreaches.net.

    You can also read some overview comments from Zack at
    this.weekinsecurity.com/new-su

    My post explaining how this all started is at databreaches.net/2026/02/02/th

    #cybersecurity #securityresearch #legalthreats #threats #criminals #databreach #vulernabilities #malware #lawsuit #survey

    @zackwhittaker @campuscodi @amvinfe @jgreig @dangoodin @GossiTheDog @lawrenceabrams @euroinfosec

  18. Updating my update: I got answers from Dos-OP in response to Nova RaaS's objections to the reporting. They also sent me a 66-page file on Nova, under embargo. I've updated my post with publicly available info and their responses to specific claims by Nova. databreaches.net/2025/11/30/br

    It seems kind of stupid for threat actors to claim that IP addresses are all wrong when there's publicly available evidence linking them to the IP addresses.

    Updating: Nova contacted me this morning to dispute the claims in the report. I've forwarded their criticisms to Dos-OP for response.

    ------ original post:

    BREAKING: Dos-OP exposes the Nova RaaS gang

    Dos-OP, in collaboration with CBSecurity, has released a preliminary version of the first part of their planned 3-part report on the Nova RaaS gang and its affiliates.

    Information and more details have reportedly already been provided to law enforcement.

    It's something else to be thankful for this week, if it's correct.

    Read my post at databreaches.net/2025/11/30/br

    #ransomware #Nova #RaaS #databreach #cybersecurity #doxxing

    @campuscodi @zackwhittaker @euroinfosec @amvinfe

  19. Some folks may recall my anger on August 18 over a vendor who wasn't responding to alerts about exposing their clients' data. The data included court files or records that were confidential or even sealed. At the time, researchers had discovered two entities that were exposed. They subsequently discovered more.

    Yesterday, the vendor -- who had even ignored a call from the FBI -- finally secured one of the two after the client finally reached them on the phone.

    The vendor told them they had fixed the problem. But did they?

    [SPOILER ALERT: No.]

    You won't believe what happened next, or maybe you will, but you'll have to stay tuned for this story, which has now gotten astronomically bigger because not only were the data still not secured but the vendor -- after claiming that the researchers had used hacking techniques to access unsecured data -- inexplicably sent the client a list of ALL of vendor's clients with their technical details AND ALL OF THEIR LOGIN CREDENTIALS.

    [WTF!?]

    I have never been as tempted to issue an actual press release warning all entities about a specific vendor, but... wow.

    Stay tuned. Eventually, I will write this all up, but first, I want to hear what the client's lawyers and insurers decide to do to hold the vendor accountable.

    (August 18 post: infosec.exchange/deck/@PogoWas)

    #databreach #dataleak #incidentresponse #incidentmanagement #thirdparty #vendor #accountability

    @zackwhittaker @aj_vicens @politico

  20. So many news reports have repeated the BBC's mistaken estimate about the number of customers affected by the Kering data breaches. So...

    No, folks, it's not 7.4 million affected or fewer. It's a lot more because the BBC's estimate was based on just the second and smaller breach (Balenciaga, Brioni, and Alexander McQueen), and not the Gucci data which allegedly has more than 43 million records. Even assuming repeat customers are in there, there are likely a lot of unique customers in the Gucci data.

    If we use the same percent based on 7.4 million out of almost 13 million recordsin the second data set, then that would yield 24-25 million unique email addresses for the Gucci data set, for an estimated total of more than 31 million customers all told.

    I didn't estimate the number of unique customers in my reporting because it's too sloppy. But it's highly unlikely to be 7.4 million or fewer as BBC reported.

    #Kering #Gucci #Balenciaga #Brioni #AlexanderMcQueen #databreach #Salesforce #ShinyHunters #UNC6040 #incidentresponse #transparency

    My reports:
    databreaches.net/2025/09/11/ex

    databreaches.net/2025/09/15/up

    @euroinfosec @zackwhittaker

  21. So many news reports have repeated the BBC's mistaken estimate about the number of customers affected by the Kering data breaches. So...

    No, folks, it's not 7.4 million affected or fewer. It's a lot more because the BBC's estimate was based on just the second and smaller breach (Balenciaga, Brioni, and Alexander McQueen), and not the Gucci data which allegedly has more than 43 million records. Even assuming repeat customers are in there, there are likely a lot of unique customers in the Gucci data.

    If we use the same percent based on 7.4 million out of almost 13 million recordsin the second data set, then that would yield 24-25 million unique email addresses for the Gucci data set, for an estimated total of more than 31 million customers all told.

    I didn't estimate the number of unique customers in my reporting because it's too sloppy. But it's highly unlikely to be 7.4 million or fewer as BBC reported.

    #Kering #Gucci #Balenciaga #Brioni #AlexanderMcQueen #databreach #Salesforce #ShinyHunters #UNC6040 #incidentresponse #transparency

    My reports:
    databreaches.net/2025/09/11/ex

    databreaches.net/2025/09/15/up

    @euroinfosec @zackwhittaker

  22. So many news reports have repeated the BBC's mistaken estimate about the number of customers affected by the Kering data breaches. So...

    No, folks, it's not 7.4 million affected or fewer. It's a lot more because the BBC's estimate was based on just the second and smaller breach (Balenciaga, Brioni, and Alexander McQueen), and not the Gucci data which allegedly has more than 43 million records. Even assuming repeat customers are in there, there are likely a lot of unique customers in the Gucci data.

    If we use the same percent based on 7.4 million out of almost 13 million recordsin the second data set, then that would yield 24-25 million unique email addresses for the Gucci data set, for an estimated total of more than 31 million customers all told.

    I didn't estimate the number of unique customers in my reporting because it's too sloppy. But it's highly unlikely to be 7.4 million or fewer as BBC reported.

    #Kering #Gucci #Balenciaga #Brioni #AlexanderMcQueen #databreach #Salesforce #ShinyHunters #UNC6040 #incidentresponse #transparency

    My reports:
    databreaches.net/2025/09/11/ex

    databreaches.net/2025/09/15/up

    @euroinfosec @zackwhittaker

  23. So many news reports have repeated the BBC's mistaken estimate about the number of customers affected by the Kering data breaches. So...

    No, folks, it's not 7.4 million affected or fewer. It's a lot more because the BBC's estimate was based on just the second and smaller breach (Balenciaga, Brioni, and Alexander McQueen), and not the Gucci data which allegedly has more than 43 million records. Even assuming repeat customers are in there, there are likely a lot of unique customers in the Gucci data.

    If we use the same percent based on 7.4 million out of almost 13 million recordsin the second data set, then that would yield 24-25 million unique email addresses for the Gucci data set, for an estimated total of more than 31 million customers all told.

    I didn't estimate the number of unique customers in my reporting because it's too sloppy. But it's highly unlikely to be 7.4 million or fewer as BBC reported.

    #Kering #Gucci #Balenciaga #Brioni #AlexanderMcQueen #databreach #Salesforce #ShinyHunters #UNC6040 #incidentresponse #transparency

    My reports:
    databreaches.net/2025/09/11/ex

    databreaches.net/2025/09/15/up

    @euroinfosec @zackwhittaker

  24. So many news reports have repeated the BBC's mistaken estimate about the number of customers affected by the Kering data breaches. So...

    No, folks, it's not 7.4 million affected or fewer. It's a lot more because the BBC's estimate was based on just the second and smaller breach (Balenciaga, Brioni, and Alexander McQueen), and not the Gucci data which allegedly has more than 43 million records. Even assuming repeat customers are in there, there are likely a lot of unique customers in the Gucci data.

    If we use the same percent based on 7.4 million out of almost 13 million recordsin the second data set, then that would yield 24-25 million unique email addresses for the Gucci data set, for an estimated total of more than 31 million customers all told.

    I didn't estimate the number of unique customers in my reporting because it's too sloppy. But it's highly unlikely to be 7.4 million or fewer as BBC reported.

    #Kering #Gucci #Balenciaga #Brioni #AlexanderMcQueen #databreach #Salesforce #ShinyHunters #UNC6040 #incidentresponse #transparency

    My reports:
    databreaches.net/2025/09/11/ex

    databreaches.net/2025/09/15/up

    @euroinfosec @zackwhittaker

  25. Domain names are a vulnerable spot affecting freedom of communication, and governments are not the only threats.

     Dissent Doe :cupofcoffee: wrote the following post Tue, 04 Mar 2025 12:32:09 -0800 Last Friday I received a letter from a U.K. law firm with an attached injunction. The law firm claimed I must remove two posts about their client.

    That is not going to happen. I am not under the jurisdiction of the U.K. or the High Court of Justice. My lawyer informed them of that yesterday.

    But DataBreaches.net might disappear tomorrow because the U.K. law firm sent the injunction to my domain registrar who, innocently believing them, informed me they will suspend my site if I don't remove the posts within 24 hours. I have replied to them but have not heard back.

    So...

    If my site is gone tomorrow, I will let you know where you can read a lot more about the injunction and how the injunction poses a serious risk of censorship in the U.K.

    If my site is still online tomorrow, I will still let you know here where you can read about the over-reaching injunction obtained in a private hearing where no one represented journalists whose reporting was being censored.

    #censorship #injunction #pressfreedom
    #AssociatedPress #RCFP #databreach #ransomware #journalism

    @[email protected] @[email protected] @[email protected] @[email protected] @[email protected] @[email protected] @[email protected] @[email protected] @[email protected]