ZeroHour

Source: DataBreaches.net

13 stories in the last 3d

Revolut’s paperwork breach shows why insurers are rethinking what counts as a ‘cyber attack’

Revolut handed customer data to an attacker using a spoofed government email, prompting insurers to rethink cyber attack coverage definitions.

Revolut disclosed customer data after receiving a request from what appeared to be a genuine government email address; no servers were breached and no malware was involved. The social engineering incident has become a test case for how cyber insurers define a 'cyber attack'. The report is by Matthew Sellers. It highlights a growing gap between technical intrusions and data-loss incidents caused by impersonation.

DataBreaches.net · 10h agoData breach

Ransomware group claims attack on Missouri’s Cedar County Memorial Hospital after IT outage

Ransomware group claims attack on Cedar County Memorial Hospital in Missouri, forcing IT shutdown that disrupted EHRs and diverted emergency patients.

Cedar County Memorial Hospital in El Dorado Springs, Missouri shut down its IT networks on August 14 after a disruption left its electronic health record system, patient portal, and internet access unavailable. A ransomware group subsequently claimed responsibility for the attack. Diagnostic imaging was also disrupted, preventing transmission of images to radiologists, and the emergency department partially diverted trauma and critical patients.

DataBreaches.net · 10h agoRansomware

Hackers demand 10,000 Bitcoin from Revolut following data breach

Revolut breach via spoofed government-agency email requests; attackers posted stolen data samples on Telegram and demand 10,000 Bitcoin.

Revolut disclosed that an unauthorized third party obtained sensitive customer information by sending fraudulent requests from the email domain of a legitimate government agency. People claiming responsibility have posted samples of the allegedly stolen data across several Telegram groups. The perpetrators are demanding 10,000 Bitcoin from Revolut.

DataBreaches.net · 10h agoData breach

Members of ‘Black Axe’ cybercriminal group extradited from South Africa

Five alleged Black Axe members extradited from South Africa face US charges over romance scams defrauding more than 100 victims.

Five alleged members of the Black Axe cybercriminal organization were extradited from South Africa and will make their first US court appearance Monday. Prosecutors unsealed a 2021 indictment accusing them of running romance scams that stole thousands of dollars from more than 100 people. Named defendants include Perry Osagiede and Franklyn Edosa Osagiede.

Student photos, bank details stolen by hackers after St James Anglican School in Perth hit by cyber attack

St James Anglican School in Perth reports hackers stole student photos and family bank details in a contained network breach.

St James Anglican School in Perth's north identified unauthorized access to its computer systems in a cyber breach. Hackers stole students' and families' personal information, including photos and bank details. Parents were advised the school immediately contained the incident and secured its systems.

DataBreaches.net · 10h agoData breach

Possible cyber incident disrupts Monroe schools in Wisconsin

Possible cyber incident forced the School District of Monroe in Wisconsin to cut internet access, knocking out phones and canceling an ACT testing session.

The School District of Monroe in Wisconsin disconnected its network after a possible network security issue. Students powered down computers, school phone service failed, and a scheduled ACT testing session was canceled. Classes continued while the district investigates the incident. No data theft or attacker claims have been confirmed so far.

DataBreaches.net · 1d agoData breach

Silent Ransom Group Hacked Greenberg Traurig; Who notifies the 126k Affected?

Silent Ransom Group listed law firm Greenberg Traurig on its leak site, with roughly 126,000 individuals affected by the breach.

Silent Ransom Group (SRG) added prominent law firm Greenberg Traurig to its leak site of attacked and leaked victims. DataBreaches.net reports exclusive details indicating approximately 126,000 people were affected and raises questions over who is notifying them. SRG's leak site previously carried 64 law firm listings, including Troutman Pepper Locke, reported breached on August 21.

DataBreaches.net · 1d agoRansomware

Six in 10 Cyberattacks in Colombia Target Hospitals

A Biofile report based on IBM X-Force data finds 60% of cyberattacks in Colombia target healthcare institutions, making medical data a prime target.

A Biofile report drawing on IBM's X-Force Index found that six out of ten cyberattacks recorded in Colombia target health sector institutions. The finding highlights the growing exposure of hospitals and clinics to digital threats. Medical information has become one of the main targets for attackers in the country.

DataBreaches.net · 1d agoResearch

Delaware Consumer Privacy and Data-Breach Law Updates

Delaware's governor signed HB 380 and HB 381 amending the state privacy act and breach notification law.

On September 2, 2026, Delaware's Governor signed House Bill 380 and HB 381. HB 380 amends the Delaware Personal Data Privacy Act (DPDPA), enacted in 2023 and effective January 1, 2025. HB 381 separately amends Delaware's computer security breach notification law. Joseph J. Lazzarotti of JacksonLewis summarizes the changes.

DataBreaches.net · 2d agoPolicy & legal

AT&T store worker gets 16 months inside for SIM-swap side hustle

Former AT&T store worker Kenneth Carter sentenced to 16 months for SIM-swapping customers for cybercriminals.

Kenneth Carter, 44, a former AT&T retail employee in Portland, Oregon, used his internal system access to perform SIM swaps on customers' phone numbers for cybercriminals. The swaps allowed criminals to intercept authentication codes and raid victims' bank accounts. Carter was sentenced to 16 months in federal prison.

DataBreaches.net · 2d agoPolicy & legal1· 1 read

HHS Releases Updated Security Risk Assessment Tool

HHS OCR and ONC released version 3.7 of the Security Risk Assessment Tool for healthcare organizations.

The U.S. Department of Health and Human Services Office for Civil Rights (OCR) and the Office of the National Coordinator for Health IT (ONC) released version 3.7 of the Security Risk Assessment (SRA) Tool. The tool helps covered entities conduct HIPAA security risk assessments. ONC and OCR provided guidance on the updates.

DataBreaches.net · 2d agoTools

Not just Korea: Google leaked identifying info for sex crime victims across the world

Google exposed identifying information of sex crime victims who filed image-removal requests worldwide, not only in Korea, the Hankyoreh confirmed.

The Hankyoreh, reporting by Shin Da-eun and Park Kang-su, confirmed that Korea was not the only country where victims who sent Google removal requests about illegally obtained sexual images had their private information exposed online. The leak affected victims across the world, compounding harm to a highly vulnerable population. One quoted victim described photos taken when they were a minor being distributed without consent.

DataBreaches.net · 2d agoData breach

NYS DFS Issues New Cybersecurity Guidance on Risk Assessments for Financial Services Entities

New York DFS issued cybersecurity guidance defining expectations for risk assessments that regulated financial services entities must conduct.

On September 10, 2026, NYS DFS Acting Superintendent Kaitlin Asrow issued new cybersecurity guidance on conducting risk assessments sufficient to inform cybersecurity programs. The guidance covers scope, frequency, and the role of assessments for DFS-regulated financial services entities. It does not describe any incident or vulnerability, but sets regulatory compliance expectations under DFS cybersecurity rules.

DataBreaches.net · 2d agoPolicy & legal