home.social

#navigate360 โ€” Public Fediverse posts

Live and recent posts from across the Fediverse tagged #navigate360, aggregated by home.social.

fetched live
  1. NEW by me:

    The U.S. military leaked more than 93,000 tips via insecure P3 Global Intel. Has anyone been notified?

    I had reported on the school-related tips in the Navigate360 breach, and then the Crime Stoppers tips. In this post, I looked at the tips to the U.S. military.

    databreaches.net/2026/09/18/th

    #Navigate360 #P3GlobalIntel #databreach #cybersecurity #incidentresponse

    @douglevin

  2. NEW by me: more analysis of the Navigate360 data breach, this one focusing on Crime Stoppers and crime-oriented tip lines using P3 Global Intel:

    Crime Stoppers assured people their tips would be anonymous. Then more than 1 million tips leaked:

    databreaches.net/2026/07/24/cr

    If anyone has a connection in their state attorney general's office, encourage them to read this and open an investigation. A table in the article shows how many tips were submitted for each chapter of Crime Stoppers that appeared in the dataset.

    #databreach #cybersecurity #infosec #Navigate360 #CrimeStoppers

    @zackwhittaker @campuscodi @jgreig @douglevin @ajvicens

  3. It has been four months since a hacktivist obtained 8.3 million tips submitted to organizations such as Crime Stoppers and Sandy Hook Promise. What the hacktivist found in terms of lack of security was appalling.

    In the four months since Navigate360 (the parent company for P3 Global Intel and P3 Campus) learned of the breach, they have made zero public statements after the first day when they said they were investigating. Their wall of silence, and the conspiracy of silence involving programs like Safe2Say, Safe2Tell, SilentWitness, and Crime Stoppers has been unacceptable. No one has been notified, it seems. And we cannot find any state regulator that has been notified, either.

    DataBreaches wrote about the disgraceful lack of transparency in a new post this week:

    Broken Promises of Anonymity: Four Months Later, Still No Transparency. Now Weโ€™re Seeking Accountability.
    databreaches.net/2026/07/20/br

    In conjunction with that post, I filed a formal FTC complaint against Navigate360 under Section 5 of the FTC Act and also notified the National Association of Attorneys General, saying that states should be protecting their residents by investigating the breach and incident response.

    And that's not all. Today, I have filed a complaint with one state attorney general's office and will be filing with others.

    I will also be publishing a post this week about the Crime Stoppers data in the dataset and the ridiculous response by legal counsel for Crime Stoppers USA to inquiries by DataBreaches about what was being done to improve security.

    I have not written up anything specific to all of the Canadian data in the dataset, but yes, Canadian crime stoppers and police organizations are in there, too.

    Take Action:

    If you know anyone in a state attorney general's office, encourage them to read up on the breach on my site, where I have also published tables with data for easy reference.

    If you know anyone in the FTC, encourage them to read the complaint I filed and to act on it.

    If you know any personal injury lawyer who should be handling a massive lawsuit alleging privacy harms, point them to my coverage.

    Children and adults who tried to be good citizens and relied on promises of anonymity have been put in harm's way. We cannot allow this to be minimized or covered up.

    @zackwhittaker @nytimes @caparsons @douglevin

    #databreach #infosec #Navigate360 #CrimeStoppers #Safe2Tell #Safe2Say #SilentWitness #SandyHookPromise #transparency #notification #NAAG #FTC

  4. ๐—ก๐—ฎ๐˜ƒ๐—ถ๐—ด๐—ฎ๐˜๐—ฒ๐Ÿฏ๐Ÿฒ๐Ÿฌ ๐—ฎ๐—ป๐—ฑ ๐—ฃ๐Ÿฏ ๐—š๐—น๐—ผ๐—ฏ๐—ฎ๐—น ๐—œ๐—ป๐˜๐—ฒ๐—น: ๐—™๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ฒ ๐—ฝ๐—ฟ๐—ผ๐—บ๐—ถ๐˜€๐—ฒ ๐—ผ๐—ณ โ€œ๐Ÿฎ๐Ÿฌ+ ๐˜†๐—ฒ๐—ฎ๐—ฟ๐˜€ ๐—ฎ๐—ป๐—ฑ ๐˜‡๐—ฒ๐—ฟ๐—ผ ๐˜ƒ๐—ถ๐—ผ๐—น๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐˜€โ€ ๐˜๐—ผ ๐˜๐—ต๐—ฟ๐—ฒ๐—ฒ ๐—บ๐—ผ๐—ป๐˜๐—ต๐˜€ ๐—ผ๐—ณ ๐˜€๐—ถ๐—น๐—ฒ๐—ป๐—ฐ๐—ฒ

    The P3 Global Intel platform was designed to collect reports regarding potentially critical situations within school communities.

    This means that the information involved could pertain to incidents, behaviors, or circumstances that fall within an extremely private aspect of the lives of students and their families.

    suspectfile.com/navigate360-an

    #Anonymous_Reporting #BlueLeaks_2.0 #Navigate360 #P3_Global_Intel #Privacy #School_Security

  5. NEW by me:

    The โ€œAnonymousโ€ Tip System That Wasnโ€™t: Three Months Later, Why Hasnโ€™t Navigate360 Notified Anyone?

    Note: there is a trigger warning at the top of this article as it contains sensitive material from tips submitted to and about students on what were supposed to be "anonymous" tiplines.

    databreaches.net/2026/07/06/th

    This is the longest post I have ever done because people need to be more aware that this was the worst breach EVER in terms of highly sensitive personal information of students and their peers and families.

    Great thanks to @douglevin for his comments and suggestions on the post.

    @funnymonkey @mkeierleber @euroinfosec @jgreig @zackwhittaker @campuscodi @politico @dustinvolz

    #databreach #anonymity #infosec #cybersecurity #Navigate360 #P3Campus #P3Global

  6. RE: infosec.exchange/@douglevin/11

    I am waiting for a response to a public records request I filed with PA over safe2say PA. They'll likely exempt everything, but we'll see. I will be reporting on some of the sensitive tips involving children.

    And yes, there are tips in the dataset involving Canada although I haven't attempted to dive into those. I think it's shameful that entities still haven't been given details on what data of theirs was involved.

    #Navigate360 #Crimestoppers #databreach

  7. ๐’๐ข๐ง๐œ๐ž ๐–๐ก๐ž๐ง ๐ƒ๐ข๐ ๐€๐ฌ๐ค๐ข๐ง๐  ๐Ÿ๐จ๐ซ ๐„๐ฏ๐ข๐๐ž๐ง๐œ๐ž ๐๐ž๐œ๐จ๐ฆ๐ž โ€œ๐ƒ๐ž๐Ÿ๐ž๐ง๐๐ข๐ง๐  ๐‚๐ซ๐ข๐ฆ๐ข๐ง๐š๐ฅ๐ฌโ€?

    Dissent responded harshly to these accusations, firmly rejecting any insinuation of collusion with criminal groups. The journalist pointed out that every time she asks for evidence to support certain claims, she is labeled โ€œcriminal-friendlyโ€ or accused of being a mouthpiece for cybercriminals, simply for refusing to uncritically accept statements lacking public verification.

    suspectfile.com/since-when-did

    #Canvas #Data_Breach #Instructure #Navigate360 #Ransom #ShinyHunters

  8. ๐‘๐š๐ง๐ฌ๐จ๐ฆ๐ฐ๐š๐ซ๐ž, ๐“๐ซ๐š๐ง๐ฌ๐ฉ๐š๐ซ๐ž๐ง๐œ๐ฒ, ๐š๐ง๐ ๐ˆ๐ง๐ฏ๐ข๐ฌ๐ข๐›๐ฅ๐ž ๐•๐ข๐œ๐ญ๐ข๐ฆ๐ฌ: ๐ƒ๐ข๐ฌ๐ฌ๐ž๐ง๐ญ ๐‘๐ž๐ฌ๐ฉ๐จ๐ง๐๐ฌ ๐ญ๐จ ๐ญ๐ก๐ž ๐ˆ๐ง๐ฌ๐ญ๐ซ๐ฎ๐œ๐ญ๐ฎ๐ซ๐ž ๐‚๐š๐ฌ๐ž

    A recent article published by DataBreaches.net by journalist Dissent addresses one of the most controversial issues in modern cybersecurity: the payment of ransoms following a cyberattack and the consequences such decisions can have not only on the companies involved, but also on the individuals whose data has been compromised.

    suspectfile.com/ransomware-tra

    #Canvas #Data_Breach #Instructure #Navigate360 #Ransom #Ransomware #ShinyHunters

  9. Senators Probe Navigate360 Over Hacked Student Data

    Senators Maggie Hassan and Jim Banks are demanding answers from Navigate360 after a cyberattack compromised its anonymous tip line, putting the sensitive data of students, staff, and schools at risk. The breach allegedly exposed 93 gigabytes of data, sparking concerns over the safety and security of those who rely on the company'sโ€ฆ

    osintsights.com/senators-probe

    #StudentDataBreach #Navigate360 #P3GlobalIntel #EmergingThreats #EducationSector

  10. NEW by me:

    BlueLeaks 2.0: 7,300+ Schools, Referral Systems Reported, and a Breach Navigate360 Still Hasnโ€™t Publicly Confirmed

    P3's parent firm responded to me, but only to say they are quite concerned about my reporting data on their breach. They are concerned that partial or incomplete data without context, etc., might upset folks downstream. That would be the same folks they haven't addressed at all, I guess.

    My post, with newly reported data (thanks to the incredibly patient and diligent @JayeLTee's help) and my response to #Navigate360:

    databreaches.net/2026/04/22/bl

    Previous coverage by me about this breach that has compromised what were supposed to be anonymous and SECURE tips from and about students:

    databreaches.net/2026/04/16/p3

    #databreach #transparency #incidentresponse #infosec #cybersecurity #P3Tips

    @zackwhittaker @jgreig @dangoodin @mkeierleber @ddosecrets

  11. NEW: My post on the student/k-12 tips exposed in "BlueLeaks 2.0" is now up.

    P3 Campus and its partner programs like Safe2Say Something PA, Safe2Tell, and Sandy Hook Promise were supposed to provide secure and anonymous ability to report tips.

    Promises of security and anonymity do not appear to have been kept. A hacker claims it was easy to gain access and repeatedly access the database to acquire more than 8 million tips.

    There is not much anonymous about what I reviewed in the dataset.

    Many of the school-related tips I reviewed reported concerns over named students with suicidal ideation or cutting, students being bullied or bullying others, and drugs (mostly vaping) in school. Some students reported cybercriminal activity.

    Navigate360, the parent company of P3, still hasn't publicly acknowledged that it was breached and that sensitive information was involved. Their lack of transparency was noted by @douglevin

    The dataset has not been leaked publicly, but the "Internet Yiff Machine" who provided it to #ddosecrets and infosec.exchange/@mikaelthalen -- and then to me -- has listed it for sale.

    My focus in this post was on the student/school -related tips, but the 93.51 GB dataset has millions of tips that include adult issues and crimes, including drugs, homicide, assaults, etc. I provide one or two examples from the non-student tips to illustrate how sensitive the tips are in this dataset.

    This may be the worst breach I've ever seen involving sensitive student information, and I've seen many student-related data breaches over the past two decades.

    Read: "P3 Advertised 20+ Years and 0 Security Breaches. You Can Guess What Happened Next.'" at databreaches.net/2026/04/16/p3

    #BlueLeaks2 #DDoSecrets #databreach #P3Campus #P3Tips #Navigate360 #CrimeStoppers #Safety #Safe2tell #InternetYiffMachine

    @zackwhittaker @campuscodi @jgreig @euroinfosec @funnymonkey @mkeierleber @JayeLTee

Share on Mastodon

Enter the server where you have an account.