ZeroHour

Search: “TechCrunch”

21 stories

Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far

TechCrunch's 2026 roundup covers SSA data exposure, Iranian water-utility attacks, Klue breach hitting ~200 firms, and Meta AI chatbot account hijacks.

TechCrunch's mid-year roundup highlights a whistleblower claim that DOGE uploaded a live Social Security database copy to an unsecured third-party server, which House Democrats called potentially the largest US breach in history. CISA reported Iranian hackers targeted over 100 US water providers over the summer, while Russian-linked attacks hit Polish, Swedish, and Norwegian energy and water infrastructure. Market research firm Klue was breached via a stale 2022 pilot credential, exposing cloud keys of ~200 customers including Jamf, HackerOne, and LastPass to extortion gang Icarus. Separately, tens of thousands of Instagram accounts were hijacked by abusing Meta's AI chatbot to trigger password resets to attacker-controlled emails.

TechCrunch · Security · 1d agoData breach in the wild

Revolut confirms customer data breach through fake government requests

Revolut disclosed customer identity data, including passports and possibly selfies, to an attacker using a legitimate government email domain.

Attackers impersonating a government agency used a legitimate agency email domain to submit fraudulent information requests, prompting Revolut to disclose customer identity and contact data to an unauthorized third party. Exposed data included birth dates, postal and email addresses, phone numbers, passport and driver's license copies, and possibly verification selfies, account statements, and transaction histories. Revolut said a limited number of customers were affected, blocked the email address, and notified the agency, law enforcement, and regulators, adding that systems and customer funds were unaffected. Security researcher ZachXBT reported the scam appeared to target high net worth users of the fintech, which serves over 80 million customers.

TechCrunch · Securityupdated · 2d agofirst · 4d agoData breach in the wild 3 sources3

ID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolen

ID verification firm IDScan confirms hackers stole over 150 million driver's license records, including names and license numbers, from its cloud.

IDScan confirmed that threat actors stole driver's license records — full names, license numbers, and other government ID numbers — from the company's cloud systems during a roughly year-long intrusion. Brian Krebs previously reported a dark web service exposing data on over 150 million US and Canada residents, including license photos and records of high-profile individuals such as Defense Secretary Pete Hegseth. The FBI is investigating, and IDScan indicated hackers apparently demanded payment for full access to the stolen cache; the investigation is ongoing.

TechCrunch · Securityupdated · 5d agofirst · 6d agoData breach in the wild 4 sources1

It sure looks like hackers breached a major ID card verification service

Suspected breach of ID verification firm IDScan exposed over 150 million US and Canadian driver's licenses and passports, sold via dark web site Nexus.

Independent journalist Brian Krebs reported that a dark web site called Nexus is selling searchable access to more than 150 million driver's licenses and passports belonging to people in the United States and Canada, adding roughly 500,000 documents daily from a 'major identity verification company.' Krebs and researcher Zach Edwards identified Louisiana-based identity verification service IDScan as the likely source; Krebs' own license and Defense Secretary Pete Hegseth's records appeared in the database. The FBI confirmed it is looking into the incident and IDScan says it is investigating; Nexus went offline shortly after the report went live.

TechCrunch · Security · 14d agoData breach in the wild

Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider

Third-party breaches at Trezor's email and shipping vendors exposed customer data, fueling phishing campaigns targeting hundreds of thousands of crypto wallet owners.

Trezor confirmed that a breach at Brevo, its marketing email provider, exposed customer contact data and let hackers send roughly 347,000 phishing emails claiming a fake 'STM32 Entropy Vulnerability' and asking victims for their wallet backup password. Brevo said attackers accessed 138 accounts by abusing overly broad, improperly scoped access privileges. Trezor was also hit weeks earlier by a breach at shipping partner ShipMonk that exposed names, phone numbers, email addresses, and postal addresses of at least 81,000 wallet buyers. Trezor stated its own products, wallets, and account systems were unaffected and warned customers to expect further phishing attempts.

TechCrunch · Securityupdated · 5d agofirst · 5d agoData breach in the wild 4 sources1

IDScan confirms breach after hackers offer 153 million driver’s license scans for sale

IDScan confirmed hackers accessed customer data in its cloud after scans of roughly 153 million driver's licenses surfaced for sale on a dark web marketplace.

IDScan.net published a breach notice on September 4, after learning around September 1 that an unauthorized third party may have accessed or copied customer information in its cloud platform, potentially including full names and government-issued ID numbers. KrebsOnSecurity tied the incident to Nexus, a Russia-linked dark web marketplace selling access to over 153 million US and Canadian driver's license scans, plus 10 million ID cards, more than 3 million travel documents, and at least 579,000 medical cards. The company did not disclose how many customers were affected, is offering free credit monitoring, faces multiple lawsuits, and the FBI has opened an inquiry. IDScan's government ID authentication is widely used by banks, cannabis retailers, and gun stores.

The Record · 6d agoData breach in the wild