Shell Global
89GB engineering and facility data exfiltrated by Cl0p
2026 continues the year-over-year growth trend in confirmed disclosures. The list below updates as new breaches are reported by Verizon DBIR partners and major security news outlets.
89GB engineering and facility data exfiltrated by Cl0p
Cyberattack exposed personal information of Xfinity customers; settled for $117.5 million
BlackNevas breach confirmed Aug 14
165 orgs breached, billions of records stolen
The root cause of the incident is believed to be a compromised AWS access key that was exposed in publicly available JavaScript build artifacts. The post Over 1,000 Charities Hit by Beacon CRM Data Breach appeared first
Hackers breached heat-and-power facility supplying 50,000 residents via private APN access point
Akira ransomware affiliates were seen using a new technique to evade endpoint detection and response (EDR), where they rebooted a compromised Windows system into Safe Mode with Networking enabled. According to Huntres
INC_RANSOM ransomware hit US IT firm
INC_RANSOM ransomware, firm data exfiltrated
AmnesiaStealer targets macOS users through fake GitHub pages, stealing passwords, cookies and data while giving attackers live control of the browser. Jamf Threat Labs researchers disclosed AmnesiaStealer, a new multi-st
Patient health information compromised in 2025 breach affecting hospital system
The exfiltrated data may be related to misconfiguration of Microsoft Power Page portals, according to a new report.
STILL, NHS? Martin Bagot reports: The NHS has admitted a data breach by sending patients’ personal information over pager devices. A BBC investigation found sensitive medical data of transplant patients was routinely sen
Data breach affected approximately 900,000 current and former customers; personal information exposed
Data storage platform hacked; 165 breaches affecting over 165 million records total across multiple organizations
Cyberattack exposed personal information of Xfinity customers; $117.5M settlement reached
24M customer breach due to lack of basic security controls; three major GDPR violations
Cyberattack exposed personal information of Xfinity customers; resulted in $117.5M settlement
US law and government relations firm breached by Storm
Cybersecurity teams should be responsible for risk oversight, rather than for executing every corrective action. Assigning security teams the tasks of finding, prioritizing, assigning, implementing, tracking and validati
100K+ officer and staff contacts leaked
7.3 million Chess.com profiles leaked online: the data is genuine, but evidence points to large-scale scraping, not a server breach. Free is a strange price for stolen data, and that’s exactly what makes this listi
Data breach disclosed in securities filing; type and scope of exposed data not yet determined
Over 95% of the affected companies were exposed before the malicious LiteLLM packages were published. The post Trivy, Not LiteLLM Behind the 2,500 Org Compromise appeared first on SecurityWeek.