Breach tracker
The latest confirmed and reported data breaches
| Organisation | Records | Data exposed | Date | Status |
|---|---|---|---|---|
| Global retailer | 89M | Names, addresses, partial cards | Oct 1 | Confirmed |
| Health insurer | 4.2M | Claims, policy numbers | Sep 30 | Notifying |
| Telecom carrier | 12M | SIM & call records | Sep 29 | Investigating |
| Fintech app | 1.1M | Transaction histories | Sep 28 | Patched |
| Hotel chain | 640K | Passport scans | Sep 25 | Confirmed |
| University | 38K | Payroll, research files | Sep 29 | Contained |
Across the desk
Three leads, plus what else moved today
12,400+
Vulnerabilities disclosed this year
$4.9M
Average cost of a data breach
204 days
Average time to identify a breach
68%
Breaches involving human error
What it means
Longer reads and expert takes
Guides & explainers
Practical reads to keep you and your team safer

Old NFT approvals drained in Payment Processor exploit
Attackers abused a retired Limit Break contract once used by Magic Eden, stealing about $2.8M from wallets that approved it years ago.
Lena Hart · 4 min read

State-backed hackers used NetScaler zero-day for weeks
Mandiant says suspected state hackers exploited CVE-2026-88772 from early September, planting WHIPSHOT and SLAPSHOT web shells.
Sam Reyes · 4 min read

Fake iPhone Duo preorder sites steal Apple IDs
Scammers advertise preorders for a non-existent iPhone Duo, copying Apple's store to steal Apple ID logins and card details.
Lena Hart · 4 min read

Russia's Star Blizzard swaps ClickFix for RedFlick
Microsoft says Star Blizzard now uses a one-click technique called RedFlick to deploy its CosmicPulse backdoor against Ukraine-linked targets.
Priya Nair · 4 min read
Most read this week
- 1Crypto
NEAR Intents loses $3.8 million in cross-chain exploit
Priya Nair · Oct 1, 2026 · 4 min read
- 2Reviews
Is ProtectMyData legit? What we found in 2026
Lena Hart · Sep 30, 2026 · 7 min read
- 3Crypto
Old NFT approvals drained in Payment Processor exploit
Lena Hart · Sep 30, 2026 · 4 min read
- 4Data Breaches
BigCommerce app breach exposes Master of Malt shoppers
Lena Hart · Sep 30, 2026 · 4 min read
- 5Vulnerabilities
AI agent chains Zammad zero-days to breach DIVD
Mira Castell · Oct 1, 2026 · 4 min read

Amazon Prime phishing uses fake billing alert
Emails claiming your Prime membership is on hold lead to a multi-step fake Amazon site that steals logins and full card details.
Priya Nair · Sep 30, 2026 · 4 min read
In brief
Short takes from across the newsroom

China-linked hackers target Asian governments with Antino
Sep 30, 2026

Pennington County restores services after ransomware
Sep 29, 2026

Dutch police arrest suspected ShinyHunters member
Sep 29, 2026

China-linked NeedyMantis implant hid in telecoms for a year
Sep 29, 2026

Phishing campaigns install remote admin tools for access
Sep 29, 2026

Fake Zoom and Docusign emails target corporate inboxes
Sep 29, 2026

How to freeze your credit (and why you should)
Sep 29, 2026

OpenAI apologises after rogue AI agents hacked sites
Sep 29, 2026
Vulnerability watch
Critical flaws security teams should patch this week
Remote code execution in enterprise VPN gateways
Actively exploited. Patch or disable the web portal now.
Authentication bypass in a popular file-transfer server
Exploit code is public; data theft reported.
Browser extension autofill flaw exposes saved passwords
Fixed in the latest release — update automatically.
Privilege escalation in widely used router firmware
Vendor firmware update available for most models.
Ransomware desk
Attacks, takedowns and the gangs behind them

Teen suspected of leading KillSec ransomware arrested
Europol says three arrests and eight searches in four countries took down servers and the leak site of a group linked to about 1,000 attacks.
Dev Okafor · Oct 1, 2026 · 4 min read

Japanese rail firm Keio hit by ransomware attack
Oct 1, 2026 · 4 min read

Pennington County restores services after ransomware
Sep 29, 2026 · 4 min read

Ransomware hits 2026 high in August as Qilin leads
Sep 28, 2026 · 4 min read

Ransomware halts US production at Coca-Cola's Fairlife
Jul 17, 2026 · 4 min read
Watch & listen
The Unlisted Report podcast and video briefings
Podcast · Ep. 42
Inside the 89-million-record retail breach
38 min
Video · Ep. 41
How ransomware gangs pick their victims
12 min
Podcast · Ep. 40
Passkeys, explained without the jargon
27 min
Privacy & scams
Protecting your data and spotting the latest tricks
Fake iPhone Duo preorder sites steal Apple IDs
Scammers advertise preorders for a non-existent iPhone Duo, copying Apple's store to steal Apple ID logins and card details.
Lena Hart · Sep 30, 2026 · 4 min read
PhishingAmazon Prime phishing uses fake billing alert
Emails claiming your Prime membership is on hold lead to a multi-step fake Amazon site that steals logins and full card details.
Priya Nair · Sep 30, 2026 · 4 min read
PhishingPhishing campaigns install remote admin tools for access
Microsoft says attackers disguise the MSP360 remote management installer as meeting invites and PDFs, then add ScreenConnect as a backup.
Sam Reyes · Sep 29, 2026 · 4 min read
Editor's picks
Stories our editors think you shouldn't miss

Ransomware hits 2026 high in August as Qilin leads
Mira Castell · Sep 28, 2026 · 4 min read

Hacked Ukrainian sites push Psychedelic Stealer
Mira Castell · Sep 28, 2026 · 4 min read

Simba breach exposes IC numbers of 23,549 customers
Priya Nair · Sep 28, 2026 · 4 min read

CISA warns of exploited Citrix NetScaler zero-days
Dev Okafor · Sep 27, 2026 · 4 min read
Threat intel briefing
Nation-state hacking, botnets and attacks on critical infrastructure

North Korea's 2026 crypto thefts pass $1 billion
Elliptic links the Bitget hack to North Korea-backed hackers, citing laundering patterns and wallets tied to the record $1.5 billion Bybit theft.
Dev Okafor · Sep 26, 2026 · 4 min read
Lunex stealer disables security tools before striking
Ontinue found a four-stage Lunex attack on Ukrainian speakers that uses fake CAPTCHAs and a vulnerable driver before stealing passwords and crypto.
Sam Reyes · Sep 24, 2026 · 4 min read
Microsoft takes down EvilTokens AI phishing service
The platform used an AI chatbot to plan fraud from 12,000+ hacked inboxes. Microsoft seized 50 sites and UK police arrested two men.
Sam Reyes · Sep 22, 2026 · 4 min read
Fake LastPass downloads spread stealer that kills 145 security tools
A kit impersonating 40+ brands on GitHub used a Microsoft-signed driver to disable security software before installing the Rapuncel infostealer.
Dev Okafor · Sep 21, 2026 · 4 min read
Russian spies used AI to rebuild malware after detection
Anthropic says a group linked to APT29 used Claude to automatically rebuild and redeploy its malware whenever security tools caught it.
Mira Castell · Sep 11, 2026 · 4 min read
Meet the newsroom
The reporters behind the stories
Dev Okafor
Vulnerabilities & Guides Editor
Dev tracks critical software flaws and writes practical security how-tos.
13 stories
Lena Hart
Privacy & Scams Correspondent
Lena reports on data privacy, regulation and the latest phishing tricks.
18 stories
Mira Castell
Senior Breach & Ransomware Reporter
Mira covers major data breaches and the criminal groups behind them.
15 stories
Priya Nair
Cloud & AI Security Correspondent
Priya covers cloud security, AI risks and how new technology changes the threat landscape.
17 stories
Sam Reyes
Threat Intelligence Reporter
Sam investigates nation-state hacking, espionage and attacks on critical infrastructure.
11 stories
Browse by topic
Data Breaches
News
Ransomware
Privacy
Phishing
Threat Intel
Guides
Crypto
AI Security
Vulnerabilities
Government
Reviews
Have a tip?
Seen a breach, leak or exposed database? Our newsroom reviews every confidential tip.





