
Data analyst sent to prison for stealing data, extorting employer
A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme.
Stories tagged “Data Breach.”
30 stories

A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme.

Trezor said nearly 14,000 customers had personal data exposed after its fulfillment partner ShipMonk suffered an unauthorized access to its systems, though its own infrastructure and wallets remain secure.
The best antivirus software to protect your computer in 2026
ZDNET experts put every product through rigorous testing and research to curate the best options for you. Our favorite antivirus software protects your PC, laptop, and mobile devices from malware without costing a fortune.

A maximum-severity zero-day vulnerability in Metabase's business intelligence software is being actively exploited, allowing unauthenticated remote attackers to gain administrator access.

Healthcare software company Unlimited Technology Systems reports a data breach impacting over 3.8 million individuals.

Levi Strauss & Co. says hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines. The company has disclosed the incident in a filing with the U.S. Securities and Exchange Commission (SEC), saying that it…

A hacker, Connor Riley Moucka, pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy over the 2024 breaches of Snowflake customer accounts. The intrusions reached at least 165 organizations and exposed records belonging to at le…

A cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals. The intrusion was detected on Sunday, July 26, and was later claimed by the ExfilSquad data extort…

The Police National Legal Database (PNLD) has confirmed that police, government, and customer contact information was compromised and published on the dark web. The data included names, organisations, and work email addresses belonging to police officers, police staff, cr…

Pharmaceutical company Amgen suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers.

Medical billing firm MCBS disclosed a 2025 network breach exposing sensitive information of over 1.2 million people. The company reported that 1,261,464 people have been impacted. Exposed data includes full name, physical address, social security number, date of birth, an…

Bank of Baroda has launched a forensic investigation after customer data and internal documents from the state-run lender surfaced on the dark web. The bank said the breach resulted in “unauthorised access to certain data” but that attackers did not access its core bankin…

Chick-fil-A has disclosed a data breach affecting an undisclosed number of customers, following credential stuffing attacks on its website and mobile app in June 2026.
Origin Energy, Australia's top electricity and gas retailer, is investigating a potential security incident that may involve unauthorised access to some customers' data.
70,000 customers' info leaked by Sagawa Express setup error
Sagawa Express Co., a major Japanese parcel delivery company, announced that personal information for approximately 70,000 users of its Smart Club service was leaked due to a system setup error.

Genetic testing company 23andMe has agreed to pay $18 million to settle claims from a coalition of 43 attorneys general that it failed to protect customers' genetic data. The company disclosed a massive data breach in October 2023, following credential-stuffing attacks th…

AssuranceAmerica, an American insurance company, has disclosed a data breach affecting nearly 7 million drivers after attackers accessed its systems in March 2026.

Personal data of Indian students from various government exams and private coaching institutes is being sold online across over 1,000 databases, with recent batches covering CUET-UG and other 2026 exams.

A U.S. government entity, strongly implied to be Union County, Ohio, paid approximately $1 million to the Kairos group to prevent the leak of 2 terabytes of stolen sensitive data. This incident highlights a growing trend of cyber extortion gangs foregoing encryption in fa…

Medtronic is notifying customers about a data breach by the ShinyHunters extortion group that exposed personal data, including names, contact info, dates of birth, Social Security numbers, and health-related information.

Insurance giant Aflac has disclosed a data breach affecting its Japan subsidiary, where unauthorized actors accessed systems and stole personal and bank account information.

Nissan suffered a data breach affecting current and former employees due to an Oracle PeopleSoft vulnerability. The breach is linked to the ShinyHunters extortion group.

The National Association of Insurance Commissioners (NAIC) says the ShinyHunters extortion group stole only publicly available data after breaching its systems. The breach was caused by a zero-day vulnerability in an Oracle PeopleSoft server.

Japanese telecommunications giant KDDI Corporation disclosed a data breach affecting up to 14.2 million email logins across six ISPs, stemming from a vulnerability in third-party software.

Healthtech company Xolis warns of a data breach affecting nearly 1.4 million individuals.

Dialog, a group cofounded by Peter Thiel, notified members of a data breach, but a WIRED analysis found the files were readable due to a website misconfiguration. The exposed data includes personal information of senior figures in national security and technology.

LastPass announced a data breach after hackers accessed customer data from its Salesforce environment. The breach occurred due to a supply chain attack on Klue, a third-party market intelligence platform.

A data breach at the Texas Parks and Wildlife Department's license system vendor exposed personal information for over 3 million individuals. The breach included driver's license information, passport numbers, email addresses, phone numbers, and residential addresses.

Salesforce has disabled the Klue Battlecards app integration due to a security incident involving OAuth token abuse. The incident exposed customer data, including business contacts and sales-related information.

Hackers are exploiting a critical security vulnerability in a widely used corporate VPN system from Palo Alto Networks to breach online company data in Pakistan. The vulnerability, tracked as CVE-2026-0257, affects the GlobalProtect VPN portal and gateway components runni…