#data-breach — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #data-breach, aggregated by home.social.
-
Apollo Breach Exposes Sensitive Data Via Social Engineering
A recent data breach at Apollo Global Management exposed sensitive personal info, including Social Security numbers, when an unauthorized user gained cloud access for just four days, from July 6 to July 10, 2026. The breach was triggered by a social engineering attack, highlighting the importance of robust security measures.
#DataBreach #SocialEngineering #SensitivePii #CloudSecurity #EmergingThreats
-
Encryption Key Exposed in South Korean Startup Platform Breach
A data breach at South Korea's Modu-ui Changup startup platform exposed sensitive info from around 5,000 applicants, including email addresses, comments, and startup ideas. The leak happened when an encryption key was collected by external crawlers, compromising personal data stored on the government-backed site.
#DataBreach #StartupSecurity #EncryptionKeyExposure #SouthKorea #GovernmentbackedPlatform
-
@XposedOrNot += Oz Hair and Beauty Data Breach
The Oz Hair and Beauty #databreach occurred in August 2026 when the online beauty retailer was breached. The incident exposed 2M unique email addresses and associated personal information.
Exposed data: Email addresses, Names, Phone numbers, and Geographic locations
Potential risks: Identity theft, Phishing, Targeted scams, and Privacy breaches
-
Strano che Spiaggiari, l'azienda dietro una delle applicazioni(*) più pettose dell'universo e che dovrò usare ancora per un anno, abbia anche dei problemi di sicurezza.
(*) Classeviva sembra uscita dalla mente contorta di un programmatore degli anni '90: complicata, lenta, con un interfaccia obsoleta.
-
xpl0itrs colpisce il Gruppo Spaggiari: 6,1 TB rivendicati da 3.000 scuole italiane, l’azienda ridimensiona
Il gruppo di cybercrime xpl0itrs rivendica l'esfiltrazione di 6,1 terabyte di dati dall'infrastruttura di Spaggiari, storico fornitore del registro elettronico ClasseViva usato da 4,5 milioni di utenti al giorno. L'azienda ridimensiona l'incidente a un solo modulo, ma il profilo del gruppo — già dietro rivendicazioni contro Spotify, Treasury e OpenAI — invita alla cautela. -
MANTRA Chain Restores Block Production After Cosmos-EVM Module Exploit
MANTRA Chain resumed operations after a 30-hour halt caused by an attacker exploiting a vulnerability in its Cosmos-EVM module's upstream dependencies. The incident affected two managed wallets but did not compromise user funds.
****
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/mantra-chain-restores-block-production-after-cosmos-evm-module-exploit-z-b-z-7-s/gD2P6Ple2L -
Billions of records do not mean billions of hacked accounts.
Social-platform incidents can involve breaches, scraping, credential stuffing or exposed databases—and the data and risk vary widely.
Verizon’s 2025 DBIR found compromised credentials were the initial access method in 88% of confirmed attacks against basic web applications.
-
An interesting case here of the hacker claiming one thing - a huge record count - and the victim refuting those claims - they don't have nearly that many customers.
Who's right? I like to believe the victim.
-
NIUS - 6,090 breached accounts - https://www.redpacketsecurity.com/nius-6-090-breached-accounts/
#databreach #HaveIBeenPwnedLatestBreaches #HIBP #OSINT #Security #threatintel #TroyHunt
-
Google Threat Intelligence Group and Mandiant both flagged this exact playbook in June. The boss mechanic was announced. Twice.
Train your staff to verify IT support requests through known internal contact methods before handing over anything — that one step breaks the entire combo.
Reward: You've received a Melted Headset of Foolish Trust. It doesn't do anything. It never did.
#DataBreach #SocialEngineering #Cybersecurity #ApolloGlobal #SilentRansomGroup #PhishedOrFished (2/2)
-
Hundreds of leaked #AWS keys give full control over corporate accounts
-
#PrivateEquity firm #Apollo confirms #DataBreach amid hacking wave targeting financial giants
-
SFR Fiber Customer Data Exposed in Internal Tool Breach
SFR confirms a data breach after attackers compromised a legitimate account to access an internal fiber management tool, exposing the personal and technical data of estimated approximately 2.1 million customers. The company has disabled the account, notified regulators, and warned users of potential phishing risks.
****
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/sfr-fiber-customer-data-exposed-in-internal-tool-breach-g-p-r-t-m/gD2P6Ple2L -
Breach monitor, 2/12: the trap.
A clean address returns {"Error":"Not found","email":null} with HTTP 200, not a 404.
So if your script branches on the status code, every clean address reads as a hit and you page someone at 3 am for nothing.
Branch on the body. Check for the breaches key.
Verify it yourself, no key needed:
curl https://api.xposedornot.com/v1/check-email/[email protected]
-
Golf Canada - 568,972 breached accounts - https://www.redpacketsecurity.com/golf-canada-568-972-breached-accounts/
#databreach #HaveIBeenPwnedLatestBreaches #HIBP #OSINT #Security #threatintel #TroyHunt
-
Japan’s Sakura Internet says hackers accessed its sales management system, potentially exposing data from up to 1.36M member accounts. #databreach
-
Apollo Global Management confirms hackers stole personal data after using social engineering to access its cloud systems between July 6–10.
Exposed data includes names, birth dates, contact details, and Social Security numbers. #databreach
-
SickKids says a flaw in third-party software exposed personal information belonging to some current/former employees and job applicants.
Patient records and clinical systems were unaffected, and its Careers site has been restored. #databreach
-
#SickKids #DataBreach exposes employee and job applicant info
-
ASOS US Sales LLC Reports Data Breach Exposing Financial Records
ASOS US Sales LLC reported a data breach affecting nearly 9,500 individuals, exposing sensitive personal and financial information including credit card numbers.
****
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/asos-us-sales-llc-reports-data-breach-exposing-financial-records-1-l-d-j-j/gD2P6Ple2L -
DATE: August 21, 2026 at 04:48PM
SOURCE: HEALTHCARE INFO SECURITYDirect article link at end of text block below.
#ShinyHunters Leaks 7.1 Million #BaxterInternational Records: Gang Claims It Stole #MedicalDevice Maker's #Salesforce Info Including Personal Data https://t.co/bNj9DIYtG9 #HIPAA #databreach
Here are any URLs found in the article text:
Articles can be found by scrolling down the page at https://www.healthcareinfosecurity.com/ under the title "Latest"
-------------------------------------------------
Private, vetted email list for mental health professionals: https://www.clinicians-exchange.org
Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.
-------------------------------------------------
#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering
-
"Private equity giant Apollo Global Management has confirmed a data breach in which hackers stole reams of personal information from the company’s cloud systems.
The breach comes a month after security researchers sounded the alarm on a new hacking campaign targeting financial and private equity giants.
The financial giant confirmed the incident in a letter filed with California’s attorney general. Apollo’s human resources chief Matthew Breitfelder said that hackers used a social engineering attack to gain access to the company’s cloud environment between July 6 and July 10. The hackers took names, birth dates, contact information (including home addresses), and Social Security numbers.
The letter does not specifically say who had their personal information stolen, such as Apollo employees or individuals at companies it owns. Apollo is one of the world’s largest private equity firms with $938 billion in assets under its management."
-
Kingston Technology Investigates Everest Ransomware Claims of 138 GB of Stolen Data
Kingston Technology is investigating claims by the Everest ransomware group that it stole approximately 138 GB of corporate data. The group published screenshots as evidence and is threatening to release the files.
****
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/kingston-technology-investigates-everest-ransomware-claims-of-138-gb-of-stolen-data-j-u-7-1-h/gD2P6Ple2L -
Mon Health Medical Center Discloses Phishing Breach Affecting Patient Data
Mon Health Medical Center reported a data breach affecting 2,173 individuals after a phishing attack allowed unauthorized access to internal email mailboxes. The hospital is providing two years of credit monitoring and has notified federal authorities.
****
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/mon-health-medical-center-discloses-phishing-breach-affecting-patient-data-0-1-l-j-f/gD2P6Ple2L -
Another big law firm was hit -- and leaked -- by Silent Ransom Group.
New, by me:
Troutman Pepper Locke Silent as Threat Actors Leak Client Data, Tens of Thousands of SSNs
#databreach #cybersecurity #hack-and-leak #SilentRansomGroup #TroutmanPepperLocke