ZeroHour

Search: “verifiability”

80 stories

Love Electric Breach: 877,000 Driver Records Offered for $600

A forum seller is offering 877,000 driver records from UK EV salary-sacrifice broker Love Electric for $600; researchers found the sample looks authentic.

A seller named seraphims advertised 877,000 records from Love Electric Financial Services, an Edinburgh-based FCA-regulated EV salary sacrifice broker, for $600 in cryptocurrency. Ransomnews analysts verified a 999-row SQL Server export containing names, addresses, National Insurance numbers, and driving licence numbers, with internal relationships and licence-format checks consistent with genuine production data. The full record count remains unverified, and the company had not commented at publication; the breach highlights risks from third-party payroll-adjacent providers.

Security Affairs · 19d agoData breach

McDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records Stolen

A seller offers 1.7 million McDonald's employee records allegedly taken from its Azure tenant via compromised credentials; an 8,000-row sample verifies as genuine.

A forum seller named TheHatman posted an 8,000-row sample of McDonald's employee directory data, claiming a 1.7 million-record haul pulled directly from the company's Azure tenant using compromised credentials. Ransomnews analysis found authentic Entra ID export artifacts, including genuine domains, tenant-internal addresses, encoding errors, and truncated HR fields, but could not verify the data's age or the 1.7 million figure. The same seller listed nine datasets in 16 days covering about 3.6 million records across McDonald's, Vodafone, Gap, hotels, and IT outsourcers, suggesting infostealer-driven credential resale. No passwords or hashes appear in the sample, so the primary risk is social engineering.

Security Affairs · Aug 17, 2026Data breach in the wild1

Revolut Data Leak May Trace Back to Compromised Italian Government Accounts

Attackers using a compromised Italian government PEC account impersonated law enforcement to obtain data on ~680 Revolut customers.

Revolut confirmed its systems were not breached; fraudulent data requests came from a compromised PEC mailbox tied to the Prefecture of Reggio Calabria on the pec.interno.it domain. Per the Financial Times, roughly 680 customers had identity documents, addresses, banking information, verification selfies and cryptocurrency transaction histories exposed. Researcher Korra of Duel described a 'spray and pray' operation using hundreds of crypto transaction IDs and fraudulent European Investigation Orders. Threat actor IAmNotAVillain claims six months of access and 147 GB exfiltrated from Italian law-enforcement systems, though this remains unverified.

Security Affairs · 17h agoData breach in the wild

Security Incident – BGP Hijacking

Attackers BGP-hijacked Softaculous' Hetzner IP block for 33 hours, obtained valid TLS certificates, and delivered a malicious Virtualizor update to some servers.

Between August 28 and 30, 2026, AS62390 (NexonHost) announced 162.55.80.0/24 via transit AS6204 (Zet.net) without authorization, diverting traffic while retaining Hetzner's AS24940 on the AS path. The attacker obtained valid Let's Encrypt certificates for virtualizor.com domains because the CA's domain validation was also routed through the hijack, so affected connections showed no TLS warnings. A malicious Virtualizor update package reached a handful of installations; routing was fully restored, and reconstruction from RIPE RIS data showed all 368 collector peers carried the hijacked route at some point with roughly 28% time-weighted diversion.

Lobsters · security · 14d agoData breach

Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo

Mozilla revoked the Firefox and Thunderbird Linux RPM signing subkey after an unencrypted copy landed in a private repo; no unauthorized access found.

Mozilla revoked the OpenPGP signing subkey (fingerprint 09BE ED63 F346 2A2D FFAB 3B87 5ECB 6497 C1A2 0256) used for Firefox and Thunderbird Linux downloads after an unencrypted copy was committed to one of its private repositories, citing reason code 2, 'key material has been compromised.' Audit records showed no sign of unauthorized access, and a replacement subkey (827E 6586 0867 9618 CD34 9F93 678E 455D 7676 7AA3) valid until August 5, 2028 was published. Users who verify signatures manually or install from Mozilla RPM packages may need to import the new key and remove the old one. The rotation came roughly seven months ahead of Mozilla's usual two-year subkey cycle.

The Hacker News · Aug 11, 2026Data breach

Spain reports first alleged AI-powered data theft attack

Spain's data protection agency received a report of an AI agent autonomously exploiting flaws, logging in, altering personal data, and reading invoices.

The Spanish Data Protection Agency (AEPD) was notified of an incident in which an AI agent powered by a known LLM reportedly searched for vulnerabilities, gained access to systems, modified personal data, and accessed financial documents. AEPD has not yet investigated or verified the report but says it shows AI-related data breaches are no longer theoretical. The agency urged defenders to revise incident-response procedures, strengthen credential and identity security, and explicitly account for machine-speed AI-assisted attacks.

BleepingComputer · 12h agoData breach in the wild 2 sources

CenterPoint Energy Confirms Data Breach Exposing Customers’ Personal Information

CenterPoint Energy confirmed an unauthorized third party accessed customer personal data via an external system, disclosed in an SEC Form 8-K filing.

CenterPoint Energy disclosed in a September 14, 2026 Form 8-K that an unauthorized third party obtained personal information of some customers through one of the company's external systems. The company learned of the incident after an online post claimed possession of a customer dataset, then activated incident-response protocols and engaged external forensic specialists. Electric and gas delivery operations were unaffected and the company does not expect a material financial impact, though response, notification, and compliance costs are being incurred. The number of affected customers, data types, and threat actor remain undisclosed as the investigation continues.

GBHackersupdated · 14h agofirst · 18h agoData breach 5 sources

Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far

TechCrunch's 2026 roundup covers SSA data exposure, Iranian water-utility attacks, Klue breach hitting ~200 firms, and Meta AI chatbot account hijacks.

TechCrunch's mid-year roundup highlights a whistleblower claim that DOGE uploaded a live Social Security database copy to an unsecured third-party server, which House Democrats called potentially the largest US breach in history. CISA reported Iranian hackers targeted over 100 US water providers over the summer, while Russian-linked attacks hit Polish, Swedish, and Norwegian energy and water infrastructure. Market research firm Klue was breached via a stale 2022 pilot credential, exposing cloud keys of ~200 customers including Jamf, HackerOne, and LastPass to extortion gang Icarus. Separately, tens of thousands of Instagram accounts were hijacked by abusing Meta's AI chatbot to trigger password resets to attacker-controlled emails.

TechCrunch · Security · 1d agoData breach in the wild

Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider

Third-party breaches at Trezor's email and shipping vendors exposed customer data, fueling phishing campaigns targeting hundreds of thousands of crypto wallet owners.

Trezor confirmed that a breach at Brevo, its marketing email provider, exposed customer contact data and let hackers send roughly 347,000 phishing emails claiming a fake 'STM32 Entropy Vulnerability' and asking victims for their wallet backup password. Brevo said attackers accessed 138 accounts by abusing overly broad, improperly scoped access privileges. Trezor was also hit weeks earlier by a breach at shipping partner ShipMonk that exposed names, phone numbers, email addresses, and postal addresses of at least 81,000 wallet buyers. Trezor stated its own products, wallets, and account systems were unaffected and warned customers to expect further phishing attempts.

TechCrunch · Securityupdated · 5d agofirst · 5d agoData breach in the wild 5 sources1

412,000 The Town 2025 Ticket Buyers’ Data Hits the Dark Web

A forum seller is offering 412,192 The Town 2025 ticket buyer records, mostly Brazilian with CPF numbers, marketed for bank fraud, loans and SIM registration.

A seller on a Russian-language forum listed a database of 412,192 Latin American ticket purchase records from The Town 2025 festival in Sao Paulo for $10,000, with 251,557 Brazilian records (61% of the total). Data includes names, emails, CPF numbers, phones, neighborhoods, ticket types and payment details, and the seller explicitly markets CPFs for Brazilian bank fraud, loans and SIM registration. Ransomnews validated the sample as genuine ticket-buyer data, but identical October 1, 2025 processing timestamps suggest a single post-event batch export rather than a direct Ticketmaster breach.

Security Affairs · 13d agoData breach

I Think the Military Commissary Freezers Were Hacked

Refrigeration failures at six-plus US military commissaries prompt speculation of a cyber attack on DeCA's remote monitoring systems; Pentagon acknowledges possible disruption.

The author documents near-simultaneous freezer and refrigeration failures at confirmed installations including Fort Huachuca, F.E. Warren AFB, Fort Irwin and Travis AFB on August 26-27, with freezers entering defrost mode that heated and spoiled food. DeCA's Remote Monitoring Control System controls defrost across roughly 182 locations, and an unverified comment attributed the Fort Huachuca failure to a network issue. Stars and Stripes and Military Times independently reported the multi-base failures, and the Pentagon acknowledged a 'possible refrigeration disruption,' though no evidence of hacking has been confirmed.

Lobsters · security · 14d agoData breach

Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs

Week in review: Medusa ransomware hit 500+ orgs per CISA, millions of Azure tenant records allegedly stolen, SafePal and French tax authority breaches disclosed.

Help Net Security's weekly roundup covers the FBI, CISA, and HHS joint advisory update reporting Medusa ransomware has breached more than 500 organizations since June 2021, and threat actor TheHatman's claim of millions of employee records stolen from Azure tenants of Fortune 500 firms including McDonald's, Vodafone, Kyndryl, and Tata Consultancy Services, per Hudson Rock. It also covers the SafePal breach affecting 39,798 customers, France's DGFiP breach exposing data on 678,000 individuals, and UT San delaying its fall semester after a cyberattack. Security items include critical unauthenticated GitLab flaw CVE-2026-19478, an actively exploited patched macOS Screen Sharing flaw deploying a cryptominer, US charges against 17 Mabna Institute Iranian hackers over 31TB of stolen academic data, and Google Mandiant's AI agents finding 100+ high-severity vulnerabilities.

Help Net Security · 25d agoData breach in the wildCVE-2026-19478

SafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impacted

SafePal confirmed nearly 40,000 customers' order data was stolen, the third hardware wallet maker breached in a month after Trezor and Coinkite.

SafePal confirmed a breach exposing names, emails, shipping addresses, phone numbers, and purchase details of customers who ordered between March 2, 2025 and April 11, 2026, caused by a flaw in an order-tracking plugin. The company stressed wallets, seed phrases, and private keys remain secure, and all impacted customers were notified by email. A hacker advertised the stolen data on a dark web forum, and SafePal warned of targeted phishing via fake support calls and refund offers. CertiK data cited in the report shows 52 wrench attacks worldwide in H1 2026 with $124 million in losses, up 33% year-over-year.

The Record · Aug 17, 2026Data breach in the wild

Chess.com Leak Exposes 7.3 Million Users — Evidence Points to Scraping

A free 15.5 GB leak exposed 7.3 million Chess.com user records; analysis suggests large-scale scraping via find-friends rather than a server breach.

A 15.5 GB dump containing 7,337,395 Chess.com records appeared on leak forums posted by user V0idix at no cost. Ransomnews confirmed the data is genuine by validating embedded v1 UUID timestamps against registration dates, but found daily-batch collection over nine days and ~7.4% duplicate records, pointing to scraping. The schema includes emails, ratings, subscription tiers and internal Google Ad Manager audience segments not exposed in the public API, and contains no passwords or payment data. Chess.com reported a similar 828,000-record 2023 leak from find-friends abuse and said then that it was not a breach.

Security Affairs · Aug 14, 2026Data breach in the wild