Data Breach News, News
September 18, 2025
754 views 3 secs 0

ShinyHunters claims 1.5 billion Salesforce records stolen in Drift hacks

Bleeping Computer reports: The ShinyHunters extortion group claims to have stolen over 1.5 billion Salesforce records from 760 companies using compromised Salesloft Drift OAuth tokens. For the past year, the threat actors have been targeting Salesforce customers in data theft attacks using social engineering and malicious OAuth applications to breach Salesforce instances and download data. The stolen data […]

Data Breach News
September 18, 2025
688 views 8 secs 0

JLR ‘cyber shockwave ripping through UK industry’ as supplier share price plummets by 55%

The Record reports: Shares in a British automaker supplier plummeted 55% Wednesday as it warned that a cyberattack on Jaguar Land Rover (JLR) was impacting its business, adding to concerns that the incident is sending a “shockwave” through the country’s industrial sector, according to a senior politician. Shares in Autins, a company providing specialist insulation components for Jaguar […]

Data Breach News
September 18, 2025
371 views 12 secs 0

Lotte Card hack exposes data of 3 million users

The Korea Herald reports that 2.97 million users, almost one third of the payment card’s 9.6 million customers, had their payment card data breached in an attack on Lotte Card’s online payments server: The stolen information comprises that which was generated and collected during online transactions processed through the compromised server between July 22 and […]

Commentaries and Analyses, Data Breach News, Vulnerabilities
September 17, 2025
793 views 23 secs 0

Self-Replicating Worm Hits 180+ Software Packages

KrebsOnSecurity.com reports: At least 187 code packages made available through the JavaScript repository NPM have been infected with a self-replicating worm that steals credentials from developers and publishes those secrets on GitHub, experts warn. The malware, which briefly infected multiple code packages from the security vendor CrowdStrike, steals and publishes even more credentials every time an infected package is installed. […]

Data Breach News
September 16, 2025
778 views 52 secs 0

JLR cyber attack: production won’t restart until 24 Sept at earliest

Autocar reports: JLR car production will not restart until 24 September at the earliest, the company has confirmed. The Jaguar and Land Rover maker was targeted by hackers on 1 September and is still in the process of rebuilding its computer systems. The group that hit Marks & Spencer earlier this year has claimed responsibility.  This has led to […]

Data Breach News
September 15, 2025
731 views 10 secs 0

Tiffany Korea acknowledges customer data leak, begins security overhaul

Chosun Biz reports an update to a previously disclosed breach affecting Tiffany Korea: Tiffany & Co., the luxury jewelry brand of LVMH (Louis Vuitton Moët Hennessy), announced that it became aware of a leak of key personal information, including customers’ names, postal and email addresses, and phone numbers. Through a notice on the 15th, Tiffany […]

Education Sector, Commentaries and Analyses, Data Breach News
September 15, 2025
840 views 21 secs 0

Watchdog warns of ‘insider threat’ of students launching cyberattacks on their schools

Public Technology reports: The UK’s data-protection watchdog has warned of a growing trend of cyberattacks on schools being perpetrated by pupils. The Information Commissioner’s Office recently analysed the details of 215 data breaches that took place across the education sector between January 2022 and August 2024 and were classified as “insider attacks”. Almost three in […]

Data Breach News, News
September 13, 2025
881 views 2 mins 0

Gucci, Balenciaga, Brioni, and Alexander McQueen allegedly hit by Salesforce attacks

More high-end retailers have reportedly fallen prey to Salesforce attacks. As first reported by DataBreaches.net, Gucci customer data was stolen last year. The data included more than 43 million records with customers’ names, age range, month and date of birth, email addresses, mobile phone numbers, addresses, total sales prices, and some additional information. The records […]

Data Breach News, Vendor News, Vulnerabilities
September 13, 2025
1213 views 45 secs 0

FBI FLASH: Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion

The FBI has issued an alert, FLASH-20250912-001. Summary The Federal Bureau of Investigation (FBI) is releasing this FLASH to disseminate Indicators of Compromise (IOCs) associated with recent malicious cyber activities by cyber criminal groups UNC6040 and UNC6395, responsible for a rising number of data theft and extortion intrusions. Both groups have recently been observed targeting […]