TransUnion
Data breach exposed credit and personal data of 37,000 people in 2019
E-commerce platforms, point-of-sale systems, loyalty programs, and customer databases remain frequent targets for credential theft and card-skimming campaigns. Below is every retail-sector breach LeakTrace has indexed.
Data breach exposed credit and personal data of 37,000 people in 2019
Hacking led to 165 confirmed breaches affecting 100+ million people
Information system hacked; resulted in €5 million fine
Over 11 million gaming account credentials exposed in 2024 data leaks discovered by Kaspersky
Exposed personal information of approximately 70,000 individuals due to supply chain vulnerability
1,988,331 records exposed — Email addresses, Geographic locations, Names, Phone numbers and 1 more
Medical business management company data breach affecting 1.2 million individuals
Healthcare company breach affecting 62.2 million people, third-largest US health hack
Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass fl
The data breach was initially believed to affect roughly 350,000 people, but the HHS breach tracker shows a far bigger impact. The post CareCloud Data Breach Impact Grows to 3.7 Million Individuals appeared first on Secu
Medical business management company suffered data breach affecting 1.2 million individuals
U.S. healthcare IT company CareCloud disclosed that the data breach incident it suffered earlier this year has impacted more than 3.7 million individuals. [...]
Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. [...]
Rich Mogull, chief analyst with the Cloud Security Alliance, joins the Dark Reading News Desk with what defenders need to take away from AI agents escaping their environments to launch attacks.
A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging from
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability — Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware w
Microsoft SharePoint Weak Authentication Vulnerability — Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.
The first 24 hours after a cyber incident are messy. Teams are moving fast, and a lot gets said on Slack or email that can come back later. People are scrambling to contain the issue, figure out what happened and keep th
The University of Texas at San Antonio, which serves 40,000 students across six campuses, said its IT team identified threat activity on its academic campus over the weekend and took some systems, including phones, offli
The security defect allows unauthenticated attackers to modify or delete user data and public projects. The post GitLab Patches Critical Code Injection Vulnerability appeared first on SecurityWeek.
Hackers stole names, addresses, phone numbers, Social Security numbers, and financial information from a third-party platform. The post Heights Finance Data Breach Impacts at Least 1.2 Million Individuals appeared first
Tiffany Wang reports: A prolific Russian-speaking extortion group known for supply-chain attacks claimed to have stolen data from more than 40 firms including heavyweight corporations such as oil giant Shell and manufact
Broadcom VMware vCenter Path Traversal Vulnerability — Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.