Data Breach News, Commentaries and Analyses, News
January 27, 2026
251 views 44 secs 0

SLSH Malicious “Supergroup” Targeting 100+ Organizations via Live Phishing Panels

Silent Push reports: A massive identity-theft campaign is currently active, targeting Okta Single Sign-On (SSO) and other SSO platform accounts across 100+ high-value enterprises. Silent Push has identified a surge in infrastructure deployment that mirrors the TTPs (Tactics, Techniques, and Procedures) of SLSH—a predatory alliance between Scattered Spider, LAPSUS$, and ShinyHunters. This isn’t a standard automated spray-and-pray attack; it is a […]

Data Breach News, News
January 26, 2026
262 views 4 mins 0

Double Trouble: Two Gangs Both Attack and Encrypt the Same Revenue Cycle Management Firm

SuspectFile reports that two well-known ransomware gangs independently attacked and encrypted files from Resource Corporation of America (RCA), a revenue cycle management business associate headquartered in Texas. What happened next is not totally clear because neither the Qilin gang nor the victim provided any details, but SuspectFile reports that the Medusa gang provided some information […]

News, Data Breach News, Vendor News
January 23, 2026
189 views 6 secs 0

ShinyHunters claim to be behind SSO-account data theft attacks

BleepingComputer reports: The ShinyHunters extortion gang claims it is behind a wave of ongoing voice phishing attacks targeting single sign-on (SSO) accounts at Okta, Microsoft, and Google, enabling threat actors to breach corporate SaaS platforms and steal company data for extortion. In these attacks, threat actors impersonate IT support and call employees, tricking them into […]

Data Breach News, Legal News, News
January 21, 2026
180 views 31 secs 0

DOGE improperly shared Social Security data: Filing

The Hill reports: Members of Elon Musk’s Department of Government Efficiency (DOGE) improperly shared Social Security data through a third-party server, according to a recent court filing from the Justice Department. The DOGE team embedded at the Social Security Administration (SSA) used Cloudflare, which was not approved for storing agency data, to share data during a 10-day period in March, the […]

Data Breach News, Education Sector, News
January 20, 2026
204 views 2 mins 0

Monroe University data breach affected 321,000

The Minnesota Department of Human Services’ vendor breach was not the only recent breach disclosed that affected more than 300,000 people. Monroe University in New York also disclosed a breach involving a lot of sensitive information. From their January 13 notification letter: We are posting this notice to inform our community of a data security […]

Vendor News, Data Breach News
January 20, 2026
203 views 28 secs 0

TriZetto Provider Solutions Issues Data Breach Notifications to HIPAA Covered Entities

The HIPAA Journal reports: TriZetto Provider Solutions, a Cognizant-owned provider of revenue management services to physicians, hospitals, and health systems, has started notifying certain healthcare clients about a recently identified cybersecurity incident. On October 2, 2025, suspicious activity was identified within a web portal used by some of its healthcare provider customers to access TriZetto […]

Data Breach News, Legal News, Malware Ransomware
January 20, 2026
172 views 14 secs 0

$2.75M American Addiction Centers data breach class action settlement

Top Class Actions reports: American Addiction Centers Inc. agreed to a $2.75 million class action lawsuit settlement to resolve claims it failed to adequately protect patients’ private information. The settlement benefits individuals whose personal information was potentially compromised in a data breach involving American Addiction Centers on or about Sept. 26, 2024, and who were […]