← ALL ARTICLES
// DATA BREACHES

Data Breaches Intelligence

69 articles. Data breach intelligence and exposure analysis. PII theft, credential leaks, and unauthorized access incidents across MENA, EU, and US.

πŸ‡ΊπŸ‡Έ USA CRITICAL

Cisco Systems: ShinyHunters Claim 3M Salesforce Records, 300+ GitHub Repos, and AWS Data in Triple-Vector Extortion

ShinyHunters claims 3M Salesforce records, 300+ GitHub repos, and AWS data from three breach vectors in a triple-vector extortion against Cisco.

2026-03-31
🌍 GLOBAL CRITICAL

Oracle's Dual Breach: 6M Cloud SSO Records Stolen, 80 Hospitals Compromised - and a Denial That Collapsed Under Evidence

Passport scans of 700+ VIP attendees leaked - former UK PM David Cameron, Binance CEO, hedge fund billionaires. Open cloud storage, zero authentication.

2025-03-21
πŸ‡ΊπŸ‡Έ USA CRITICAL

TriZetto/Cognizant: 3.4M Patient Records Stolen in 11-Month Healthcare Supply Chain Breach

An unauthorized actor accessed TriZetto's eligibility verification portal for 11 months, stealing SSNs and medical data belonging to 3.4M patients.

2026-02-06
πŸ‡ΊπŸ‡Έ USA HIGH

Infinite Campus: ShinyHunters Breach K-12 Platform Serving 11M Students via 10-Minute Vishing Attack

ShinyHunters vished an Infinite Campus employee, bypassed MFA in real time, and exported Salesforce customer directory data in a 10-minute attack window.

2026-03-18
πŸ‡ΊπŸ‡Έ USA CRITICAL

Crunchyroll: 6.8M Users Exposed After Infostealer Malware Compromises TELUS Support Agent's Okta Credentials

A phishing email delivered infostealer malware to a TELUS Digital support agent in India, capturing Okta SSO credentials that unlocked Crunchyroll's.

2026-03-12
πŸ‡¬πŸ‡§ UK HIGH

Lloyds Banking Group: API Race Condition Exposes 447,936 Customers' NI Numbers, Account Data in 4-Hour Mobile App Failure

A software defect in an overnight API update broke transaction isolation across Lloyds, Halifax, and Bank of Scotland mobile apps for 4 hours and 40.

2026-03-12
πŸ‡¬πŸ‡§ UK HIGH

UK Companies House: Browser Back Button Exposes 5.43M Companies' Directors' Addresses and Dates of Birth for Five Months

A broken access control flaw in the Companies House WebFiling service - introduced during the October 2025 GOV.UK One Login migration.

2026-03-13
πŸ‡ΊπŸ‡Έ USA HIGH

Aura: The Identity Protection Company That Couldn't Protect Its Own Data - 903K Records Stolen by ShinyHunters

ShinyHunters vished an Aura employee, compromised their Okta SSO credentials, and exfiltrated 903,100 records from a legacy marketing platform inherited.

2026-03-11
πŸ‡ΊπŸ‡Έ USA HIGH

Intoxalock: Cyberattack Bricks 150,000 Court-Mandated DUI Devices Across 46 States for 8 Days

A cyberattack on Consumer Safety Technology disabled backend calibration systems for Intoxalock ignition interlock devices from March 14-22.

2026-03-14
πŸ‡ΊπŸ‡Έ USA CRITICAL

Woflow: One SaaS Vendor Breach Exposes Walmart, DoorDash, Uber, and Deliveroo - 326GB Archive Published by ShinyHunters

ShinyHunters breached Woflow, an AI merchant data platform serving as the data infrastructure layer for four major delivery/retail platforms.

2026-03-03
🌍 GLOBAL HIGH

VoidStealer v2.0: First Infostealer to Bypass Chrome ABE via Hardware Breakpoints - No Injection, No Escalation

VoidStealer is the first infostealer in the wild to bypass Chrome's Application-Bound Encryption without code injection or privilege escalation.

2026-03-29
πŸ‡ͺπŸ‡Ί EU CRITICAL

European Commission: ShinyHunters Claim 350GB AWS Cloud Breach - Second Hack in Under Two Months

Attackers compromised the Commission's AWS account hosting Europa.eu. ShinyHunters claim 350GB stolen including mail servers, databases, and contracts.

2026-03-29
🌍 GLOBAL HIGH

Infiniti Stealer: First macOS Infostealer Combining ClickFix Delivery with Nuitka-Compiled Python Payload

A new macOS stealer uses fake Cloudflare CAPTCHAs to trick users into pasting a curl command into Terminal. Steals Keychain, browser credentials.

2026-03-28
πŸ‡ΊπŸ‡Έ USA HIGH

Navia Benefit Solutions: 2.7M Records Exposed via BOLA API Flaw

A BOLA flaw in Navia Benefit Solutions' API exposed 2.7 million benefit plan participants including HackerOne employees. Seven years of records.

2026-03-26
🌍 THREAT BRIEF HIGH

149 Hacktivist DDoS Attacks Hit 110 Organizations Across 16 Countries

Coordinated hacktivist DDoS campaign triggered by US-Israeli strikes on Iran. 12 pro-Iranian and allied groups conducted 149 attacks against banks, airports.

2026-02-28
πŸ‡ΊπŸ‡Έ THREAT BRIEF HIGH

LexisNexis: 400K Users Exposed Including Federal Judges - Hardcoded Password

Threat actor FULCRUMSEC exploited CVE-2025-55182 to breach LexisNexis AWS infrastructure. 400K user profiles, 118 .gov accounts including 3 federal judges.

2026-02-24
πŸ‡«πŸ‡· THREAT BRIEF HIGH

French National Bank Registry (FICOBA): 1.2 Million Accounts Exposed

Attacker used stolen civil servant credentials to access France's centralized registry of all bank accounts. 1.2M accounts including IBANs and tax IDs exposed.

2026-02-18
πŸ‡ͺπŸ‡Ί THREAT BRIEF HIGH

European Commission MDM Breach - Staff Data Exposed via Ivanti Vulnerability

CERT-EU detected attack on the European Commission's MDM infrastructure. Staff names, phone numbers, emails exposed. Contained within 9 hours.

2026-01-30
πŸ‡ΊπŸ‡Έ THREAT BRIEF HIGH

Figure Technology: 967,000 Accounts Breached via Voice Phishing

ShinyHunters used real-time MFA relay vishing to breach Figure Technology, America's largest non-bank HELOC lender, exfiltrating 967,000 accounts in 90 minutes.

2026-01-28
πŸ‡ΊπŸ‡Έ THREAT BRIEF CRITICAL

Infutor: 676 Million Records Including SSNs Exposed via Misconfigured Elasticsearch

Elasticsearch 8.15.2 with security explicitly disabled exposed 676M consumer records including full SSNs Mar 8, 2026 Β· 676M records.

2026-03-08
πŸ‡¨πŸ‡¦ THREAT BRIEF CRITICAL

TELUS Digital: ShinyHunters Steal 1 Petabyte via Stolen GCP Credentials

ShinyHunters exfiltrated ~1PB from the US$2.7B Canadian BPO giant - FBI background checks, voice recordings, source code, AI training data.

2026-03-11
πŸ‡ͺπŸ‡Ί EU GDPR CRITICAL

Odido: 6.2 Million Dutch Customers Breached by ShinyHunters

ShinyHunters social-engineered Odido's Salesforce CRM via phishing + vishing, scraping 6.5M individuals + 600K companies over 48 hours.

2026-02-01
πŸ‡¦πŸ‡ͺ UAE PDPL HIGH

Abu Dhabi Finance Week: 700+ VIP Passports Exposed via Cloud Misconfiguration

Passport scans of 700+ VIP attendees including former UK PM David Cameron, Binance CEO, hedge fund billionaires Feb 1, 2026.

2026-02-01
πŸ‡§πŸ‡­ Bahrain PDPL HIGH

Bahrain National Security Agency: Claimed 200GB Email Server Exfiltration

Three threat actors claimed 200GB from Bahrain's NSA email infrastructure in 8 months. ESIX 7.13. US Fifth Fleet and UK intelligence-sharing implications.

2026-02-01
πŸ‡¦πŸ‡ͺ UAE PDPL MEDIUM

DU Emirates: 371K Customers Exposed in Telecom Breach

Threat actors exfiltrated 371,000 customer records from the UAE's second-largest telecom operator and set a ransom deadline. Emirates IDs and billing data.

2025-11-01
πŸ‡ΊπŸ‡Έ USA CRITICAL

Prosper Marketplace: 17.6M Loan Applicants' Financial Data Exposed in Three-Month Breach

Attackers accessed Prosper databases for three months undetected via cloud misconfiguration, exfiltrating SSNs, bank accounts, and tax records of 17.6M.

2025-09-01
πŸ‡¦πŸ‡ͺ UAE PDPL MEDIUM

Society of Engineers UAE: 417K Files Including Emirates IDs and Passports Leaked

A threat actor exfiltrated 239GB containing 417,000 files from the UAE's mandatory engineering licensing body, including Emirates IDs, passports.

2025-09-01
πŸ‡¦πŸ‡ͺ UAE PDPL HIGH

Dubai PCFC: 1.94TB of Port Worker Data Exfiltrated and Sold for $50K

Threat actor Kazu exfiltrated 1.94TB containing 13M files from Dubai's Ports, Customs and Free Zone Corporation, selling passport scans and gate logs for $50K.

2025-09-01
πŸ‡¦πŸ‡ͺ UAE PDPL HIGH

Emirates NBD: 700K Credit Card Holder Records Sold for $430 on Dark Web

700,000 credit card holder records from the Middle East's largest bank sold for just $430 on a Chinese-language forum. Third Emirates NBD breach in 18 months.

2025-07-01
πŸ‡ΈπŸ‡¦ Saudi PDPL HIGH

Saudi Bank Accounts: 690,000 High-Value Records Sold for $420

A database of 690,000 Saudi bank account holders with full names, IBANs, and account balances was sold for $420 on a Chinese-language cybercrime forum.

2025-07-01
πŸ‡ΈπŸ‡¦ Saudi PDPL MEDIUM

Saudi Games 2024: Iran-Linked Cyber Fattah Leaks 6,000+ Participant Records

Pro-Iranian hacktivist group Cyber Fattah leaked passport scans, IBANs, and medical certificates of 6,000+ Saudi Games 2024 participants via unsecured.

2025-06-01
πŸ‡ΈπŸ‡¦ Saudi PDPL CRITICAL

Saudi Intelligence Agency: 11GB Classified Data Leak

11GB of classified data from Saudi Arabia's General Intelligence Presidency surfaced on dark web platforms, exposing personnel records and operational.

2025-03-01
πŸ‡ΊπŸ‡Έ USA CRITICAL

PowerSchool: 72M Student and Teacher Records Stolen in Largest Education Breach

A 19-year-old used stolen credentials on PowerSchool's MFA-less support portal, stealing 62.4M student and 9.5M teacher records including SSNs and medical.

2025-01-07
πŸ‡ΈπŸ‡¦ Saudi PDPL MEDIUM

NEOM Job Portal: 280,000 Applicants' Data Exposed in Recruitment Breach

NEOM's recruitment portal was compromised and 280,000 applicant records sold on BreachForums. Prior credential leaks dating to 2023 had gone unremediated.

2025-01-23
πŸ‡±πŸ‡§ Lebanon MEDIUM

Four Lebanese Hospitals: Patient Records with Cleartext Passwords on Dark Web

Patient records from four Lebanese hospitals spanning 2010-2021 posted to dark web with cleartext passwords, including medical records, passports.

2025-01-15
πŸ‡§πŸ‡­ Bahrain PDPL

Bahrain Government Portals: 15,500 Accounts Leaked on Dark Web

A politically motivated threat actor published 15,500 Bahraini government service portal credentials on a dark web forum. No acknowledgment from Bahraini.

2024-10-01
πŸ‡ΊπŸ‡Έ USA

T-Mobile: Four Breaches in Three Years - 76M+ Customers

Four separate breaches from 2021 to 2023 exposed SSNs and driver's licenses for 76M+ customers, resulting in a $350M class action settlement and $31.5M.

2024-09-01
πŸ‡ΊπŸ‡Έ USA

National Public Data: 272M Americans' SSNs Exposed - Company Files Bankruptcy

A data broker's 2.9B records including 272M Social Security numbers were posted for free on BreachForums. NPD filed bankruptcy shortly after.

2024-08-01
πŸ‡ΈπŸ‡¦ Saudi PDPL

Saudi Government Portal: Pryx Exploits IDOR to Leak 40GB of Citizen Data

Hellcat ransomware co-founder Pryx exploited an IDOR vulnerability in saudi.gov.sa to exfiltrate 40GB of citizen data including national IDs and driver's.

2024-08-01
πŸ‡¦πŸ‡ͺ UAE PDPL

Lulu Hypermarket: 196K Customer Records Stolen

Threat actor IntelBroker published 196,000 Lulu Hypermarket customer records on BreachForums, exposing names, emails, phone numbers, and loyalty card data.

2024-07-01
πŸ‡¦πŸ‡ͺ UAE PDPL

UAE Banking Sector: Coordinated DDoS Campaign

Coordinated DDoS attacks simultaneously hit ADCB, FAB, Mashreq, and RAKBANK, disrupting critical banking services and raising systemic risk concerns.

2024-01-01
πŸ‡¦πŸ‡ͺ UAE PDPL

UAE Government Portals Breached by Multiple Threat Actors

Multiple threat actors breached TDRA and uae.gov portals throughout 2024, listing citizen data, employee records, admin credentials.

2024-01-01
πŸ‡―πŸ‡΄ Jordan

r1z: Jordanian Initial Access Broker Behind 50+ Corporate Breaches

FBI arrested Jordanian national Feras Albashiti after an XSS forum undercover operation exposed him as a prolific initial access broker who sold RCE.

2024-01-01
πŸ‡ΈπŸ‡¦ Saudi PDPL

Saudi Pharma Health Platform: 7 Million Patient Records Sold on Dark Web

Threat actor 'sentap' listed 7M+ Saudi patient records on the Exploit forum, including blood types, pregnancy status, payment methods, and home addresses.

2024-05-01
πŸ‡ΈπŸ‡¦ Saudi PDPL

Riyadh Airports Company: 864 Employee Records Published on Cybercrime Forum

A threat actor published 864 employee records from Riyadh Airports Company, operator of King Khalid International Airport, on a cybercrime forum for $290.

2024-05-01
πŸ‡ͺπŸ‡¬ Egypt

85 Million Egyptians: Health Insurance Database on BreachForums

A health insurance database covering 85 million Egyptian citizens appeared for sale on BreachForums, containing national IDs, addresses.

2024-04-01
πŸ‡ΊπŸ‡Έ USA

AT&T: 73M Customer Records Including SSNs Published on Dark Web

73 million AT&T customer records with SSNs and trivially reversible passcodes were published on the dark web. A second breach of 110M call records.

2024-03-01
πŸ‡ΆπŸ‡¦ Qatar

QatarLiving.com: Expat Community Database Leaked on Dark Web

Qatar's largest expat community platform had its Elasticsearch database posted on BreachForums, exposing user IDs, names, emails, and phone numbers.

2024-03-01
πŸ‡ΊπŸ‡Έ USA

23andMe: 6.9M Users' Genetic Data Stolen - Company Bankrupted

Credential stuffing exposed immutable genetic ancestry data for 6.9M 23andMe users via the DNA Relatives feature, triggering a $50M settlement.

2023-10-01
πŸ‡ͺπŸ‡¬ Egypt

Egypt Ministry of Health: 2M Patient Records for Sale

A database of 2 million Egyptian patient records from the Ministry of Health appeared for sale on dark web markets, containing Arabic names, national IDs.

2023-07-01
πŸ‡ΈπŸ‡¦ Saudi PDPL

Saudi Ministry of Foreign Affairs: 1.4M Employee Records on Dark Web

600MB containing 1.4M employee records from Saudi Arabia's Ministry of Foreign Affairs surfaced on dark web forums, exposing diplomatic staff at embassies.

2023-01-01
πŸ‡ͺπŸ‡¬ Egypt

Egypt Leaks: Multi-Bank Financial Data Hacktivist Leak

Hacktivist group 'Egypt Leaks' published account records, transaction histories, and internal communications from multiple Egyptian banks online.

2022-10-01
πŸ‡§πŸ‡­ Bahrain PDPL

Bank of Bahrain & Kuwait: Server Breach and $739K Financial Fraud

A Nigerian cybercrime gang breached BBK's server infrastructure over two days and fraudulently transferred ~$739,000 from three customer accounts to 87.

2021-08-01
πŸ‡ΈπŸ‡¦ Saudi PDPL

Saudi Ministry of Health: Patient Data for Sale on Dark Web

A SQL database of Saudi MOH patient records appeared for sale on dark web forums, containing Arabic names, national IDs, medical diagnoses.

2021-01-01
πŸ‡ΈπŸ‡¦ Saudi PDPL

Virgin Mobile KSA: Employee and Customer Data Breach

Internal activation reports from Virgin Mobile KSA leaked on breach forums, exposing employee IDs, customer names, phone numbers, national IDs.

2020-01-01
πŸ‡°πŸ‡Ό Kuwait

KUNA: Kuwait News Agency Twitter Hijacked for Disinformation Attack

Attackers compromised Kuwait News Agency's official Twitter account and broadcast fabricated reports of a US military withdrawal, causing a diplomatic crisis.

2020-01-01
πŸ‡ΈπŸ‡¦ Saudi PDPL

Dalil App: 5 Million Users Exposed via Open MongoDB

585GB of data from 5M Saudi users including real names, phone numbers, and precise GPS locations was left on an unprotected MongoDB database with no.

2019-01-01
πŸ‡ΊπŸ‡Έ USA

Marriott/Starwood: 344M Guest Records Across Three Breaches

Attackers maintained access to Starwood's systems for four years undetected, compromising 339M guest records including 5.25M unencrypted passport numbers.

2018-11-01
πŸ‡¦πŸ‡ͺ UAE PDPL

Careem: 14.5 Million Users and Drivers Data Stolen

Trip histories, location data, and personal details of 14.5M Careem users and drivers across 14 MENA countries were stolen, helping catalyze the UAE data.

2018-01-01
πŸ‡ΊπŸ‡Έ USA

Uber: 57M Users Breached, CSO Convicted for Cover-Up

Uber paid hackers $100K in bitcoin to stay silent, then concealed a 57M-user breach from the FTC for over a year. CSO Joe Sullivan was later convicted.

2017-11-01
πŸ‡ΆπŸ‡¦ Qatar

Qatar News Agency: Hack Triggers Gulf Diplomatic Crisis

Attackers planted fake quotes attributed to the Emir on QNA's website, triggering the 3.5-year Saudi-led blockade of Qatar and a major Gulf diplomatic crisis.

2017-05-01
πŸ‡ΆπŸ‡¦ Qatar

Qatar National Bank: 1.4GB Data Leak Exposes 465K Accounts

The largest bank in the Middle East suffered a massive 1.4GB data exfiltration exposing 465,000 account numbers, credit card details.

2016-04-01
πŸ‡΄πŸ‡² Oman PDPL

Bank Muscat: $40M Global ATM Cash-Out Heist

Attackers breached two payment processors to remove withdrawal limits on 12 prepaid cards, enabling a $40M global ATM cash-out heist across 24 countries.

2013-02-01
πŸ‡§πŸ‡­ Bahrain PDPL

Al-Toufan: Multi-Wave Hacktivist Campaign Against Bahraini Government

Hacktivist group Al-Toufan launched multi-wave attacks on Bahrain's airport, news agency, and financial institutions timed to the 2011 Pearl Roundabout.

2023-01-01
πŸ‡ͺπŸ‡¬ Egypt

Egyptian Scholastic Test: 72K+ Children's PII on Open AWS S3

An unprotected AWS S3 bucket exposed data of 72,000+ Egyptian children including names, birth dates, national IDs, and test scores.

2022-01-01
πŸ‡―πŸ‡΄ Jordan

Orange Jordan: 92% Telecom Credential Leakage Rate Exposed

SMT Group found Jordan's telecom sector leaked 92% of all credentials between 2017-2019, with Orange Jordan responsible for more than half of telecom.

2017-01-01
πŸ‡°πŸ‡Ό Kuwait HIGH

Kuwait Smishing Triad: Rogue Cell Towers Target Banks and Telecoms

Two foreign cybercrime gangs arrested using rogue BTS/IMSI catchers in Kuwait to intercept SMS and inject fraudulent bank messages.

2025-02-01
πŸ‡±πŸ‡§ Lebanon

Lebanon Ministry of Education: 83,000 Student and Teacher Records Leaked

Lebanon's Education Ministry accidentally published 56,000 student exam results and 27,000 teacher bank account numbers on its website.

2022-01-01
πŸ‡«πŸ‡· EU GDPR HIGH

Lacoste: Lapsus$ Returns from Law Enforcement Dismantlement to Breach French Luxury Giant

Lapsus$ - the extortion group whose core members were arrested and convicted in 2022-2023 - claimed Lacoste as a victim, stealing source code.

2026-01-07