// DATA BREACHES

// ВИТОКИ ДАНИХ

12 articles
All Zero-Day Ransomware Phishing Supply Chain AI Security Data Breaches Malware Vulnerabilities Attacks Security
Florida woman imprisoned for massive Microsoft license fraud scheme

A Florida woman was sentenced to 22 months in prison for operating a years-long scheme involving the trafficking of thousands of stolen Microsoft Certificate of Authenticity (COA) labels. This represents an actual criminal incident involving fraud and theft of Microsoft intellectual property, resulting in legal prosecution and conviction.

Madison Square Garden Data Breach Confirmed Months After Hacker Attack

Madison Square Garden confirmed as a victim of a 2025 Oracle E-Business Suite (EBS) hacking campaign, with the breach discovered months after the initial attack. This represents an actual data breach incident affecting a specific, named organization.

$4.8M in crypto stolen after Korean tax agency exposes wallet seed

South Korea's National Tax Service accidentally exposed a cryptocurrency wallet's mnemonic seed phrase in an official press release, enabling hackers to steal 6.4 billion won ($4.8M) in cryptocurrency from a seized wallet. This represents an actual security incident involving credential exposure and subsequent theft of digital assets from a government agency.

Canadian Tire Data Breach Impacts 38 Million Accounts

Canadian Tire suffered a data breach affecting 38 million accounts, with personal information including names, addresses, email addresses, phone numbers, and encrypted passwords being compromised. This is an actual security incident involving a specific real-world victim and exposed personal data.

QuickLens Chrome extension steals crypto, shows ClickFix attack

A Chrome extension called QuickLens was compromised and removed from the Chrome Web Store after being used to distribute malware and attempt cryptocurrency theft from thousands of users. The incident demonstrates a ClickFix attack vector targeting vulnerable users.

DoJ Seizes $61 Million in Tether Linked to Pig Butchering Crypto Scams

The U.S. Department of Justice seized $61 million in Tether cryptocurrency linked to pig butchering scams, which are fraudulent cryptocurrency investment schemes. The funds were traced to addresses used for money laundering from victims of these cryptocurrency investment scams.

Microsoft Warns Developers of Fake Next.js Job Repos Delivering In-Memory Malware

Microsoft disclosed an active malware campaign targeting developers through fake Next.js job repositories designed to deliver in-memory malware. The coordinated attack uses job-themed lures to trick developers into executing malicious code, establishing persistent access to compromised systems.

Claude Code Flaws Exposed Developer Devices to Silent Hacking

Anthropic patched vulnerabilities in Claude Code that could expose developer devices to silent hacking attacks. Security researchers at Check Point demonstrated the impact by creating malicious configuration files that exploited these flaws.

European DYI chain ManoMano data breach impacts 38 million customers

ManoMano, a European DIY retail chain, suffered a data breach affecting 38 million customers due to a compromised third-party service provider. This is an actual confirmed security incident involving a real organization and a substantial number of victims.

Google Disrupts UNC2814 GRIDTIDE Campaign After 53 Breaches Across 42 Countries

Google disrupted UNC2814 (GRIDTIDE), a China-linked cyber espionage group that breached at least 53 organizations across 42 countries, primarily targeting governments and telecommunications companies globally. This represents an actual active malware campaign with real victims across multiple sectors and regions.

Medical device maker UFP Technologies warns of data stolen in cyberattack

UFP Technologies, a medical device manufacturer, disclosed a cyberattack that compromised its IT systems and data. This is an actual security incident involving a real organization and confirmed data theft, making it a legitimate breach disclosure.

Chinese cyberspies breached dozens of telecom firms, govt agencies

Google's Threat Intelligence Group, Mandiant, and partners disrupted a confirmed espionage campaign attributed to a Chinese threat actor that targeted dozens of telecom firms and government agencies. The attackers used SaaS API calls to conceal malicious traffic in their operations against these organizations.