ZeroHour

Search: “Conditional Access”

6 stories in the last 30d

SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

SafePal disclosed an order-tracking plug-in authorization flaw exposing names, emails, addresses and purchase details of 39,798 hardware wallet customers; no wallet credentials affected.

Hardware wallet maker SafePal disclosed that an authorization flaw in an order-tracking plug-in exposed names, email addresses, shipping addresses, phone numbers and purchase details of approximately 39,798 customers. No seed phrases, private keys, wallet credentials or financial information were exposed, and SafePal found no evidence of wallet or fund compromise. A separate configuration error left a data-cleanup process broken between September 2025 and April 2026, extending the affected order window back to March 2025. A threat actor has advertised a matching dataset on a cybercrime forum, and the company has fixed the flaw, cut data retention to 90 days, purged affected records, engaged third-party validators and taken down over 30 phishing sites.

The Hacker News · 29d agoData breach in the wild

Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs

Week in review: Medusa ransomware hit 500+ orgs per CISA, millions of Azure tenant records allegedly stolen, SafePal and French tax authority breaches disclosed.

Help Net Security's weekly roundup covers the FBI, CISA, and HHS joint advisory update reporting Medusa ransomware has breached more than 500 organizations since June 2021, and threat actor TheHatman's claim of millions of employee records stolen from Azure tenants of Fortune 500 firms including McDonald's, Vodafone, Kyndryl, and Tata Consultancy Services, per Hudson Rock. It also covers the SafePal breach affecting 39,798 customers, France's DGFiP breach exposing data on 678,000 individuals, and UT San delaying its fall semester after a cyberattack. Security items include critical unauthenticated GitLab flaw CVE-2026-19478, an actively exploited patched macOS Screen Sharing flaw deploying a cryptominer, US charges against 17 Mabna Institute Iranian hackers over 31TB of stolen academic data, and Google Mandiant's AI agents finding 100+ high-severity vulnerabilities.

Help Net Security · 25d agoData breach in the wildCVE-2026-19478

Revolut Exposed KYC Data After Fraudulent Government Email Passed Security Checks

Revolut handed over KYC documents, selfies, and Bitcoin transaction histories to attackers after a fraudulent email from a genuine government domain passed authentication checks.

Revolut confirmed on September 12, 2026 that it disclosed sensitive customer KYC data to an unauthorized third party after a fraudulent information request was sent from an email account operating inside a real government agency's domain, carrying valid domain authentication credentials. The exposed data included identity documents (passports, driver's licenses), verification selfies, birth dates, contact details, IBANs, account statements, and full transaction histories including Bitcoin. Revolut discovered the fraud only after independently verifying with the agency, blocked the sender, and notified law enforcement and financial regulators, but did not disclose the number of affected customers or the agency involved. Researcher ZachXBT assessed the operation was targeted at high-net-worth users, useful for fraud, impersonation, or extortion.

Security Affairs · 4d agoData breach

Veradigm warns of patient data breach after ransomware gang claims attack

Healthcare vendor Veradigm disclosed a patient data breach via a third-party vendor's credentials, which the Gentlemen ransomware gang claims involved 3.5 million records.

Veradigm, formerly Allscripts, told the SEC that an attacker used compromised credentials from a third-party vendor to access a customer-service API and copy patient data, including personal details and Social Security numbers, without touching clinical data or the broader network. The Gentlemen ransomware group listed Veradigm on its leak site claiming 3.5 million patient records and threatened to publish the data by September 11 unless ransom negotiations start. The gang, active since mid-2025, runs double extortion across Windows, Linux, NAS, BSD and ESXi, lists 800+ victims in 86 countries, and has been linked to a SystemBC proxy botnet and the GentleKiller EDR killer. Veradigm is notifying affected individuals, offering credit monitoring, and says it does not expect a material business impact.

BleepingComputer · 7d agoData breach

Boston Scientific left nursing its bottom line after cyberattack

Boston Scientific says its August 25 network intrusion will materially hit third-quarter and full-year sales and earnings, likely missing guidance.

Boston Scientific detected unauthorized activity on its network on August 25 and took systems offline, disrupting order processing and shipping operations worldwide. In an SEC filing, the medical device maker warned of a material impact on Q3 and full-year results, making it unlikely to meet the net sales growth and adjusted EPS guidance issued in July. Its distribution network has been substantially restored, sterilization facilities are operational, manufacturing resumed at most sites, and an interruption affecting cardiac device remote-monitoring activations was resolved. The company has not revealed the attack vector, whether ransomware was involved, or whether data was stolen; no ransomware group has claimed responsibility and the investigation continues.

The Register · Security · 8d agoData breach

CenterPoint Energy confirms customer data stolen in cyberattack

CenterPoint Energy confirms attackers stole customer personal data, with a threat actor leaking 7.49 million records scraped from an unprotected API.

CenterPoint Energy, a utility serving about 7 million metered customers across Indiana, Minnesota, Ohio, and Texas, confirmed in an SEC filing that an unauthorized third party obtained customer personal information via an external-facing system. A threat actor using the alias "4d722e4d656f77" leaked 7.49 million records containing names, phone numbers, service and billing addresses, account numbers, billing amounts, and partial Social Security numbers. The actor claims the data was exfiltrated by iterating through millions of IDs on CenterPoint's public API, which lacked rate limiting and WAF protections. Electric and gas services were not impacted, but multiple federal class-action lawsuits have already been filed.

BleepingComputerupdated · 12h agofirst · 1d agoData breach 5 sources