ZeroHour

Search: “data-leak”

31 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

McKesson copes with fallout from data theft extortion attack

McKesson discloses a data theft extortion attack by ShinyHunters affecting oncology and medical-surgical customers, with a reported $55 million demand.

McKesson disclosed that attackers gained access to some of its third-party applications and stole data associated with a subset of customers in its oncology, multispecialty, and medical-surgical business units; the intrusion ran for four days from August 21 and was discovered August 25. ShinyHunters claimed responsibility and listed McKesson on its data-leak site, reportedly demanding more than $55 million with a September 1 deadline. Flashpoint analysts say the group typically uses social engineering and identity weaknesses with valid credentials to access cloud-hosted environments, making the intrusion hard to detect. McKesson, which distributes about one-third of pharmaceuticals used in North America with $403.4 billion in annual revenue, says operations continue and it has reasonable assurance of no ongoing unauthorized activity.

CyberScoop · 15d agoData breach in the wild

Health data of more than 9.5 million people leaked from Aesto record system

Health data firm Aesto reported a breach affecting over 9.5 million people after hackers accessed its AWS infrastructure between December 2 and 18.

Alabama-based healthcare data company Aesto notified the Department of Health and Human Services that more than 9.5 million people had sensitive information leaked in a December cyberattack, after previously warning customers in June without disclosing scope. Attackers broke into the company's Amazon Web Services infrastructure between December 2 and December 18, stealing names, Social Security numbers, medical information, driver's license numbers, financial account numbers, and health insurance data. Aesto provides data migration and archiving services for medical facilities, and at least 30 healthcare organizations were affected, with breach notices filed for customers including Together Women's Health. Related healthcare incidents disclosed this year include Baylor Genetics (2.8 million people), CareCloud (3.7 million), and recent attacks at McKesson, Nutex, Paylogix, and Park Dental Partners.

The Record · 13d agoData breach

New pro-Ukraine hacker group targets Russian companies with custom ransomware

F6 links new pro-Ukraine ransomware group VantaCore, likely a Thor rebrand, to seven attacks on Russian firms using custom tooling and multimillion-dollar demands.

Russian cybersecurity firm F6 reports that VantaCore, a ransomware group believed to be a rebrand of pro-Ukrainian group Thor, has targeted at least seven Russian organizations with ransom demands reaching millions of dollars, operating as a ransomware-as-a-service operation with a Tor-based victim chat and a leak site. The group uses custom-built tooling including the VantaCore ransomware that encrypts servers and workstations, VantaCoreLoader for distribution, the VantaCoreRAT backdoor, and SnowKiller, which disables antivirus and security software. Initial access relies on poorly secured VPNs and remote-access tools, flaws in internet-facing applications, and credentials stolen from business partners. F6 notes pro-Ukrainian groups increasingly abandoned stock ransomware like LockBit 3 Black and Babuk in 2025-2026 in favor of custom malware.

The Record · 13d agoRansomware

Berlin Ransomware Leak Exposes State Secrets

Rhysida ransomware leaked 5.79 TB of Berlin state government data on the dark web after the city refused a 30 Bitcoin ransom.

The Rhysida ransomware group published 5.79 TB (about 1.44 million files) of Berlin state administration data on its leak site on August 28, 2026, after the city-state refused a 30 Bitcoin ransom. The claimed dataset includes personal data on 12,076 individuals, over 5,000 personnel files, payroll records, plaintext credentials for systems like PAYONE and Z_ADMIN, Bundesrat committee protocols, and documents allegedly containing state secrets. Leaked material reportedly covers national defense emergency plans, federal secret communication channels, a CBRN threat planning folder, and vulnerability analyses of Berlin's water supply. Berlin's government has activated a central crisis unit to review the leaked data and notify affected citizens and businesses.

Security Affairs · 9d agoRansomware

Revolut confirms customer data breach, falling for fake government requests

Revolut confirmed a breach of sensitive customer data after complying with forged government information requests.

Revolut confirmed that sensitive customer data was exposed after the fintech fell for fake government data requests, Reuters reported. The incident is a form of legal-process fraud in which attackers impersonate law-enforcement or government agencies to trick compliance teams into disclosing user data. The number of affected customers and specific data types were not detailed in the available text.

Hacker News · securityupdated · 2d agofirst · 3d agoData breach 3 sourcesHN 20↑ · 2 comments

Chess.com Leak Exposes 7.3 Million Users — Evidence Points to Scraping

A free 15.5 GB leak exposed 7.3 million Chess.com user records; analysis suggests large-scale scraping via find-friends rather than a server breach.

A 15.5 GB dump containing 7,337,395 Chess.com records appeared on leak forums posted by user V0idix at no cost. Ransomnews confirmed the data is genuine by validating embedded v1 UUID timestamps against registration dates, but found daily-batch collection over nine days and ~7.4% duplicate records, pointing to scraping. The schema includes emails, ratings, subscription tiers and internal Google Ad Manager audience segments not exposed in the public API, and contains no passwords or payment data. Chess.com reported a similar 828,000-record 2023 leak from find-friends abuse and said then that it was not a breach.

Security Affairs · Aug 14, 2026Data breach in the wild

The GTA VI leaks are breaking the internet. Security researchers have seen this before.

A hacker or insider leaked GTA VI gameplay footage before launch, triggering Take-Two DMCA subpoenas against Discord, Google, Microsoft and X.

The persona "CyberLeek" published stolen Grand Theft Auto VI gameplay footage and a manifesto, in what experts call a familiar data extortion playbook with monetization via watermarks, crypto wallets and a memecoin. Take-Two Interactive obtained DMCA subpoenas against Discord, Microsoft and X, and sent copyright notices to Google, treating the case like an insider threat investigation. GTA VI is projected to earn $3.3–5.2 billion in launch-week sales, raising financial and reputational stakes. Related leak websites went offline after the subpoenas.

CyberScoop · 21d agoData breach

Berlin investigates new data leak after hackers publish stolen login credentials

Berlin investigates a fresh leak after Rhysida hackers published stolen login credentials; the city refuses to pay the ransom demand.

Berlin confirmed hackers published additional stolen data, including login credentials, from a mid-August cyberattack on two city ministries responsible for urban development/housing and transport/climate. The Rhysida ransomware group claimed the breach in late August, saying it stole 5.79 TB of data including contracts, emails, passwords and classified information; Berlin acknowledged an extortion demand but refused to pay. Berlin's data protection regulator said the leak includes personal data on public employees and possibly residents, such as names, addresses, dates of birth and bank information. Germany's BSI separately linked the campaign to the TerminalFix fake-CAPTCHA technique and the LoremIpsumLoader/AxolotLoader malware tied to financially motivated Rhysida-associated hackers, days before Berlin's Sept. 20 election.

The Record · 9d agoRansomware in the wild1

Nearly 750k had financial info, SSNs leaked in South Carolina loan company breach

Heights Finance breach of a third-party cloud platform exposed SSNs and banking data of 734,828 loan customers across 11 states.

Attackers breached a third-party cloud platform used by Heights Finance in May, exposing data on 734,828 customers, according to the company's filing with Texas regulators. Stolen data includes contact details, bank account and routing numbers, Social Security numbers, tax IDs and driver's license numbers. The breach, discovered on May 7, was limited to the cloud platform and did not affect loan management systems. No group has claimed the attack and dark web monitoring has found no evidence of the data being leaked.

The Record · 29d agoData breach

153GB of stolen credentials surface after LiteLLM supply chain attack

153GB archive from the LiteLLM supply chain attack exposes secrets from about 2,500 companies, including AWS, Samsung, Cisco and Salesforce.

Hudson Rock obtained and analyzed a 153GB archive stolen in the LiteLLM supply chain attack, containing 433,909 files with secrets attributed to 2,488 corporate domains, including AWS, Samsung, Cisco, Salesforce, NVIDIA, Microsoft and Siemens. TeamPCP compromised Trivy on March 19, 2026, stole LiteLLM's PyPI publishing tokens through the build pipeline, and published malicious LiteLLM versions 1.82.7 and 1.82.8 on March 24. CloudSEK separately estimated close to 2,500 exposed organizations, and Kevin Beaumont confirmed the data is legitimate. Hudson Rock is running a global ethical disclosure effort and urges organizations to rotate secrets before the trove leaks publicly.

Help Net Security · Aug 13, 2026Data breach in the wild

Revolut Data Breach Exposes Customers’ Passport Copies and Full Transaction Histories to Hackers

Revolut leaked KYC documents and full transaction histories after a fraudulent, domain-authenticated email request impersonating a government agency.

Revolut disclosed that an attacker using an unauthorized email account on a legitimate government domain, with valid domain-authentication credentials, tricked the fintech into releasing customer data. The exposed data includes passport and driver's license copies, identity-verification selfies, full names, dates of birth, addresses, IBANs, and complete transaction histories including Bitcoin activity. Revolut says core systems, accounts, and funds were not compromised, and it blocked the email source and notified authorities. On-chain investigator ZachXBT and others indicated the operation targeted high-net-worth users facing elevated phishing, SIM-swap, and extortion risk.

Cyber Security News · 3d agoData breach3· 1 read

CenterPoint Energy confirms customer data stolen in cyberattack

CenterPoint Energy confirms attackers stole customer personal data, with a threat actor leaking 7.49 million records scraped from an unprotected API.

CenterPoint Energy, a utility serving about 7 million metered customers across Indiana, Minnesota, Ohio, and Texas, confirmed in an SEC filing that an unauthorized third party obtained customer personal information via an external-facing system. A threat actor using the alias "4d722e4d656f77" leaked 7.49 million records containing names, phone numbers, service and billing addresses, account numbers, billing amounts, and partial Social Security numbers. The actor claims the data was exfiltrated by iterating through millions of IDs on CenterPoint's public API, which lacked rate limiting and WAF protections. Electric and gas services were not impacted, but multiple federal class-action lawsuits have already been filed.

BleepingComputerupdated · 44m agofirst · 19h agoData breach 4 sources

Three intrusions at UK criminal records office went undetected for two years

UK ICO reprimands ACRO criminal records office after three undetected intrusions over two years exposed thousands of records, including domestic violence victims.

The UK Information Commissioner's Office reprimanded ACRO Criminal Records Office after three intrusions between July 2021 and June 2023 exploited a Kentico customer portal unpatched since September 2019 and ignored Trend Micro antivirus alerts, including four quarantined Mimikatz detections. An attacker maintained persistent access for roughly seven months and staged data of nearly 11,000 people for exfiltration, though ACRO could not confirm exfiltration due to insufficient logging. ACRO notified more than 84,000 people on a precautionary basis; the Medusa ransomware group claimed the incident, and network segmentation kept attackers out of the Police National Computer.

The Record · Aug 12, 2026Data breach in the wild

Mathspace breach exposes data on over a million students and parents

Mathspace confirmed attackers exploited an unpatched Metabase SQL injection flaw to steal personal data of 1,079,819 students, parents, and staff in Australia and New Zealand.

Attackers accessed Mathspace's self-hosted Metabase reporting system without legitimate login, with unauthorized access dating back to 10 August 2026 and data downloaded on 27 August. Exposed data includes names, usernames, email addresses, country, and account metadata; no passwords, academic records, SSO tokens, or API credentials were taken. Framework, Tally, and Kilo Code disclosed similar breaches via the same Metabase SQL injection flaw in August 2026.

Help Net Security · 8d agoData breach in the wild

Mathspace discloses data breach affecting over 1 million people

Mathspace disclosed a Metabase breach exposing data of 1,079,819 students, parents, and staff in Australia and New Zealand.

Mathspace confirmed attackers exploited a vulnerability in its self-hosted Metabase reporting system, gaining administrator access without legitimate login and downloading data on over 1 million people (1,079,819 total) in Australia and New Zealand. Access began August 10, data was downloaded August 27, and the theft was confirmed September 3, 2026. No credentials, academic records, or school-account links were exposed, but affected individuals are warned of targeted phishing. The incident joins a broader campaign against Metabase instances, including Trezor's provider ShipMonk, Framework, and Tally, linked to ShinyHunters via extortion emails and leak-site listings.

BleepingComputer · 8d agoData breach in the wild

Revolut Data Breach Via Fake Government Requests – What We Know So Far

Revolut confirmed attackers extracted customer KYC records by sending fraudulent data requests from a spoofed or compromised government agency email domain.

Revolut confirmed a data breach in which an unauthorized party obtained sensitive customer records by submitting fraudulent information requests from an email account on a legitimate government agency domain with valid SPF/DKIM/DMARC authentication. Disclosed data could include full names, dates of birth, passport or driving-license copies, onboarding facial images, IBANs, account statements, withdrawal records, and complete transaction histories including Bitcoin activity. Crypto investigator ZachXBT assessed the operation targeted high-net-worth users, while a threat actor using the name 'IAmNotAVillain' claimed Italian law-enforcement departments were compromised over six months with 147 GB of material, claims that remain unverified. Revolut says only a limited number of customers were affected, blocked the email address, and notified regulators and affected customers, stating its systems and funds were not compromised.

Cyber Security News · 1d agoData breach

Cloudflare Workers Spectre Attack Leaks JWT From Co

Researchers demonstrated a remote Spectre attack leaking a JWT between co-located Cloudflare Workers at 12 bits per second, 360x the 2021 rate.

Security researchers showed a remote Spectre attack against Cloudflare Workers that leaked a JWT from a co-located Worker at up to 12 bits per second with 99.16% accuracy, 360 times the 2021 demonstration rate. The attack exploited weaknesses in DyPrIs dynamic process isolation, where long-lived Durable Object invocations could run before isolation and WebSocket-heavy I/O suppressed the branch-misprediction signal. Cloudflare deployed improved DyPrIs, the V8 Sandbox, and MPK-based in-process isolation, and found no indicators of active exploitation over three years.

The Hacker News · 27d agoVulnerability

Terabytes of credentials leaked in massive supply-chain attack

Compromise of an AI software package led to scraping and exfiltration of terabytes of credentials from about 2,500 users.

A supply-chain attack involving a compromised AI software package resulted in data being scraped and exfiltrated. Roughly 2,500 users were affected, with terabytes of credentials leaked. The article provides limited technical detail on the package or attackers involved.

Ars Technica · Security · Aug 12, 2026Data breach in the wild

Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations

Researchers confirmed extortion group ExfilSquad holds stolen sensitive data from at least 13 organizations, publishing leaked datasets via torrents.

Security researchers verified that the extortion group ExfilSquad possesses sensitive data stolen from at least 13 victim organizations. The group distributed the leaked datasets publicly through torrents rather than a traditional leak site. Independent verification of the stolen data lends credibility to the group's extortion claims against its victims.

Infosecurity Magazine · Aug 14, 2026Ransomware

E-Commerce Access, Vedicline Data, Langflow RCE, ASUS Claim, and Energy Shell Access

SOCRadar reports underground posts claiming a Bangladeshi e-commerce database, Vedicline data leak, Langflow RCE, ASUS breach, and energy-sector shell access.

SOCRadar's Dark Web Team identified several new underground posts, including an alleged Bangladeshi e-commerce customer database offered for sale. The roundup also covers a claimed Vedicline data leak, Langflow remote code execution, an ASUS breach claim, and energy-sector shell access sales. Details on record counts and victims were not provided in the excerpt.

SOCRadar · 9d agoData breach

Privacy Failure in Split-LLM Training, The Returned Gradient Nullifies the Decoys

Researchers show split-LLM training leaks privacy via zero-valued gradients on decoy rows, exposing which activations are real despite passing forward-channel checks.

A systems-security case study of a two-node split-LLM training setup found that the returned output gradient from an Untrusted Cloud Node is exactly zero for decoy rows, revealing which rows are real. Across nine seeds, zero patterns identified real rows in 4,096 of 4,096 frames per run, and an attack on frame contents recovered 0.65 to 1.50 percentage points of extra tokens over a baseline. Both datasets passed forward-channel privacy and quality checks but failed once the returned gradient was included. Row-wise gradient clipping and noise closed the leak for roughly 0.01 nats of held-out cross-entropy, though five unmeasured attack classes remain.

Exposed AWS Access Key Linked to Data Breach Affecting 1500+ UK Charities

CRM provider Beacon says a compromised AWS access key likely caused a data breach affecting more than 1,500 UK charities.

Beacon, a UK CRM provider serving the charity sector, disclosed that an exposed AWS access key was the likely root cause of a data breach. The incident affected data belonging to more than 1,500 UK charities. The company said the compromised cloud credential enabled the unauthorized access; specific record volumes and data types are not detailed in the report.

Infosecurity Magazine · Aug 13, 2026Data breach in the wild

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

Attackers exploit MLflow SSRF CVE-2026-64849 (CVSS 9.3) to steal cloud credentials; CISA added it to KEV; FUXA flaw CVE-2026-25895 is being scanned.

watchTowr observed exploitation of MLflow CVE-2026-64849, an unauthenticated SSRF (CVSS 9.3) affecting versions below 3.15.0, within hours of CVE assignment on August 17, 2026, with attackers abusing model-registry webhooks to reach cloud metadata endpoints and exfiltrate credentials and secrets. CISA added the flaw to its Known Exploited Vulnerabilities catalog on August 19, 2026, with a September 2 patch deadline for federal civilian agencies. VulnCheck reported scanning of FUXA CVE-2026-25895 (missing authentication plus path traversal, CVSS 9.5, versions through 1.2.9) beginning August 18; about 60 FUXA instances are exposed and no RCE payloads have been dropped yet.

The Hacker News · 27d agoExploit / PoC in the wildCVE-2026-64849CVE-2026-25895CVE-2026-25939+1 CVEs

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Malicious LiteLLM 1.82.7/1.82.8 PyPI releases tied to the Trivy TeamPCP campaign harvested cloud, SSH, and database credentials, potentially exposing 2,500+ organizations.

CloudSEK reported that two malicious LiteLLM releases on PyPI (versions 1.82.7 and 1.82.8, live about 40 minutes on March 24) harvested cloud keys, SSH keys, Kubernetes tokens, and database passwords, with captured loot files mapping potential exposure to more than 2,500 organizations including NVIDIA, Cisco, Deloitte, Volkswagen, FedEx, Siemens, and X Corp. The campaign is part of TeamPCP (tracked by Google as UNC6780), linked to the Aqua Security Trivy scanner compromise tracked as CVE-2026-33634 and added to CISA's Known Exploited Vulnerabilities catalog on March 26. The payload used a litellm_init.pth file executed at Python interpreter startup and exfiltrated secrets to models.litellm[.]cloud; the FBI's FLASH-20260702-01 advisory urged rotation of CI/CD, publishing, and cloud credentials.

The Hacker News · Aug 12, 2026Data breach in the wildCVE-2026-33634

Electronic health record company CareCloud says 3.7 million people affected by breach

Healthcare software firm CareCloud reported a breach affecting 3,756,469 people after a hacker spent eight hours in an AWS EHR environment.

CareCloud disclosed to HHS that a hacker accessed one of its AWS environments from March 10 to March 16 and exfiltrated data within an eight-hour window in its electronic health record environment. Stolen data includes Social Security numbers, ID numbers, credit and debit card details, medical information, and insurance data. The company serves more than 45,000 providers and reported the incident to the SEC on March 24. No hacking group has claimed responsibility.

The Record · 27d agoData breach in the wild

Revolut discloses data breach exposing financial info, passports

Revolut disclosed a breach after a threat actor spoofing a government agency's email domain obtained customer passports, selfies, IBANs, and full transaction histories.

Revolut told affected customers that a threat actor sent a data request from an unauthorized email account on an official government agency's domain, carrying valid domain authentication credentials, and staff fulfilled it believing it legitimate. Exposed data includes identity details, contact information, passport and driver's license copies, KYC facial verification selfies, IBANs, withdrawal records, and full transaction histories including Bitcoin. Revolut calls the number of affected customers 'very limited' but refuses to give exact figures, while ZachXBT says high-net-worth users appear targeted. This follows a 2022 Revolut breach affecting 50,150 customers.

BleepingComputer · 2d agoData breach1· 1 read

88 ID Verification Breaches Show the Cost of Collecting Identity Data

A report catalogs 88 ID-verification breaches since 2011 exposing at least 2.15 billion records, with 41 incidents leaking irreplaceable biometric data and documents.

A Mysterium VPN report compiles 88 documented breaches since 2011 involving identity and age-verification data, with confirmed exposure of 2.15 billion records and claimed totals of 4.54 billion. In 41 of 88 incidents, ID scans, verification selfies, fingerprints, and biometric templates leaked, data that cannot be changed after exposure. Notable cases include the Tea app's exposed selfies, Discord's ~70,000 government IDs, vendor failures at AU10TIX, Sumsub, and Persona, and national registry breaches in Argentina (45 million records) and France (11.7 million people).

Security Affairs · 21d agoData breach

[webapps] Duplicati 2.2.0.3 - JWT Signing Key Leak

A public exploit exposes JWT signing key leakage in backup software Duplicati 2.2.0.3, risking session forgery.

Exploit-DB published exploit #52646 for Duplicati 2.2.0.3, a backup application. The issue leaks the JWT signing key, which could let an attacker forge authentication tokens. The disclosure does not report any exploitation in the wild.

Exploit-DB · Aug 17, 2026Exploit / PoC

Subgroup Membership Inference Audits of Differentially Private Synthetic Text

Audits of 32 differentially private synthetic-text releases show subgroup membership leakage is concentrated in few records and systematically underestimated by average-case attacks.

The paper defines a subgroup-targeted membership inference game in which the target pool is an explicit parameter, to audit residual leakage in differentially private synthetic text releases. The audit instantiates 32 proxies across four datasets, three generators (DP-SGD fine-tuning, API-based prompting, and activation steering), and five privacy budgets. DP substantially reduces average leakage at every budget, but remaining leakage is concentrated: roughly a tenth of records carries about 40% of it, and the noise removes more measured leakage from random records than from high-risk ones. Which records leak depends on the release mechanism, so record-level risk cannot be assessed independently of the release.

arXiv cs.CR · 7d agoResearch