Data BreachThe Cyber Express·5 days ago

678,000 People Hit in French Tax Authority Data Breach

France's Directorate General of Public Finances confirmed a cyberattack in June and July 2026 where attackers used stolen credentials to access systems and extract sensitive data on 678,000 individuals and professionals, including tax information and cadastral records like addresses and property details. A separate claim by hacker ZeroBytes alleged additional access to a professional cadastral database affecting potentially millions, though these figures remain unconfirmed as investigations continue. DGFiP has implemented additional security measures and will notify affected parties while working with French authorities to determine the full scope of the breach.

Data BreachDark Reading·6 days ago

Hugging Face Breach Raises Big Questions About AI Security Controls

A breach at Hugging Face has prompted security experts to scrutinize AI platform security practices, with Adam Shostack expressing surprise at details revealed by OpenAI regarding the incident. The attack highlights potential gaps in security controls that protect machine learning platforms and raises broader concerns about how AI companies safeguard sensitive data and systems.

Data BreachThe Register·6 days ago

Crook hawks millions of records allegedly plundered from corporate Azure tenants

A threat actor is selling millions of records allegedly stolen from multiple corporate Azure tenants, with breaches affecting organizations including McDonald's, Vodafone, TCS, and Kyndryl. Researchers have identified compromised credentials as the likely attack vector enabling access to these cloud environments. The incident underscores ongoing risks to enterprises relying on cloud infrastructure when credential security practices are inadequate.

Data BreachInfosecurity Magazine·6 days ago

SafePal Data Breach Hits Tens of Thousands of Customers

Hardware wallet provider SafePal has suffered a data breach affecting nearly 40,000 customers. The incident represents a significant security incident for the cryptocurrency storage platform and its user base.

Data BreachInfosecurity Magazine·1 week ago

Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations

Researchers have confirmed that the extortion group ExfilSquad has successfully stolen and leaked sensitive data from at least 13 organizations, with the stolen datasets distributed through torrent channels. The verification of ExfilSquad's access to this data across multiple victims indicates an active and ongoing extortion campaign targeting a broad range of targets.

Data BreachThe Register·1 week ago

French tax authority admits data heist after crook touts 2M records

The French tax authority has acknowledged a data breach affecting approximately 2 million records after a threat actor publicly advertised the stolen information. While investigators assess the full scope of the incident, government officials have disputed claims that the attacker maintains ongoing access to their systems.

Data BreachInfosecurity Magazine·1 week ago

Exposed AWS Access Key Linked to Data Breach Affecting 1500+ UK Charities

A compromised AWS access key has been identified as the likely cause of a data breach affecting over 1500 UK charities using CRM provider Beacon's services. The exposure resulted in unauthorized access to sensitive charity data, highlighting the critical importance of securing cloud credentials and access keys across third-party platforms.

Data BreachHuntress Blog·1 week ago

Education Under Attack: The Pattern Behind Recent University Breaches

Four recent university breaches share a common root cause: misconfiguration, revealing a critical vulnerability pattern affecting the higher education sector in 2026. The article examines the specific misconfigurations enabling these attacks and outlines remediation strategies to address this widespread security gap.

Data BreachInfosecurity Magazine·1 week ago

ICO Reprimands Criminal Records Office After 2023 Breach

The Information Commissioner's Office has formally reprimanded ACRO (the criminal records office) following a 2023 breach that exposed inadequate security practices. The agency found that failures in both patching and security monitoring directly contributed to the incident. This enforcement action underscores the regulatory consequences of neglecting fundamental cybersecurity hygiene for organizations handling sensitive data.

Data BreachDark Reading·1 week ago

Long-running Data Theft Campaign Targeting Salesforce, ServiceNow

A sophisticated campaign tracked as "City-Forum" has been conducting data theft operations against Salesforce and ServiceNow users since at least March 2025, leveraging custom-developed tools to compromise targets across various industries. The long-running nature of the operation suggests a well-resourced threat actor with sustained capability against popular enterprise platforms.

Data BreachKrebs on Security·2 weeks ago

Canadian Man Pleads Guilty in Snowflake Extortions

A 26-year-old Canadian cybercriminal has pleaded guilty to hacking and extorting over 165 organizations using Snowflake's cloud platform, making him one of 2024's most significant threat actors. Connor Riley Moucka of Ontario also admitted to stealing call and text records from more than 100 million AT&T customers as part of the scheme. The case highlights both the targeting of cloud infrastructure providers and the scale of personal data compromise in recent extortion campaigns.

Load more