Data Breaches & Leaks
Cybersecurity news in this category

Metascan Confirms Limited Data Breach After Two-Minute Telegram Bot Compromise

Unauthorized Access to Japan's Government Solution Service (GSS) Exposes 246,000 Personal Records via VPN Flaw

South Korean Medical Beauty Platform Gangnam Unni Suffers API Breach Exposing 220,000 Users' Sensitive Photos and Medical Records
Dropbox Accounts Compromised Through Lenovo ID Authentication Flaw
Several thousand Dropbox accounts were breached between August 4 and 21 due to an authorization flaw involving Lenovo ID. The root cause was an error on Lenovo's side that permitted registration of accounts using arbitrary email addresses, which could then be used to access matching Dropbox accounts. Dropbox responded by forcing logouts for all users who had relied on Lenovo ID and by requiring direct password entry for Dropbox credentials. Approximately 5,000 accounts were affected, though only about one-third saw stored files accessed by attackers. Accounts protected by two-factor authentication remained unaffected. Additional reports from the same period covered Kaspersky analysis of ValleyRAT spyware using DLL sideloading, a critical SQL injection vulnerability in the All-in-One WP Migration WordPress plugin, and a Google Chrome update addressing CVE-2026-85046 in the V8 engine.
Detecting and Removing Secrets from Git History with Betterleaks and git-filter-repo
Developers often accidentally commit sensitive data such as API keys, passwords, database dumps, or private uploads to Git repositories. Even after removal in a later commit, these secrets remain accessible in the commit history and can be recovered by anyone with repository access. The recommended approach begins with scanning the entire history using specialized tools to identify leaked credentials across all branches and past commits. Once identified, the secrets must first be rotated or revoked before any history rewriting occurs. Tools like Betterleaks provide detection with keyword filtering, entropy analysis, and Base64 decoding, while git-filter-repo enables precise removal of files and replacement of secret strings throughout the repository timeline. The process requires careful backups, coordination with teams, and force-pushing rewritten history, followed by fresh clones for all contributors and CI/CD systems. Even after cleanup, organizations must assume that old secrets may persist in forks, backups, or caches and therefore treat rotation as mandatory.
Dropbox Lenovo ID Integration Flaw Exposes Thousands of Accounts Without Passwords
A flaw in the federated authentication process between Dropbox and Lenovo ID allowed attackers to compromise approximately 5,000 accounts between August 4 and August 21, 2026. Attackers registered a Lenovo ID using the email address tied to an existing Dropbox account due to missing email verification checks. They then logged in via the Lenovo ID option, and Dropbox automatically associated the identity with the existing account without requiring the original Dropbox password. Only accounts linked to the Lenovo ID integration and lacking two-factor authentication were affected. In fewer than one-third of the compromised accounts, attackers viewed or downloaded stored files. Dropbox responded by terminating all Lenovo ID sessions, removing existing associations, and updating the login flow to require the Dropbox password. Lenovo described the issue as stemming from a legacy integration and stated that its own customers were not directly impacted.
Yellow Hat Reports Breach in Web Work Reservation System, Possible Leak of 1.8 Million Member Records
Japanese automotive retailer Yellow Hat disclosed that its Web Work Reservation System was compromised, potentially exposing personal data of up to 1,801,499 members. The intrusion was detected on August 18, 2026, after which investigators confirmed that customer information stored on the company's member server may have been exfiltrated. Affected records include names, telephone numbers, email addresses, and member numbers. Yellow Hat has notified law enforcement and Japan's Personal Information Protection Commission while contacting impacted individuals through multiple channels. The company is advising members to remain vigilant against unsolicited communications that could indicate misuse of the stolen data.
Kaspersky MDR Adds Automatic Correlation with Leaked Credentials via Digital Footprint Intelligence
Kaspersky has updated its Managed Detection and Response service to automatically match security events against data from compromised logins and passwords. The enhancement integrates Kaspersky Digital Footprint Intelligence to provide analysts with additional context when suspicious activity coincides with known credential leaks. According to the company, a quarter of attacks investigated in 2025 began with the use of stolen credentials. The update also introduces notifications for asset protection status, allowing administrators to address connectivity or telemetry issues that could affect monitoring quality. Managed service providers can now configure per-client license usage limits, and the service adds support for Kaspersky Embedded Systems Security for Linux 4.0. The MDR platform continues to deliver 24/7 infrastructure monitoring, threat hunting, incident investigation, and response capabilities.
Hacktivist Group Cyberleek Leaks Alleged GTA VI Gameplay and Map Details in Protest Against Digital-Only Releases
A hacktivist collective calling itself Cyberleek has released two purported gameplay clips from GTA VI along with images that may depict the full map of Leonida state. The group claims the leak is a protest against Rockstar's decision to sell physical editions that contain only a download code rather than an actual disc. Cyberleek is also demanding an end to digital pre-orders, the practice of selling built-in content as DLC, and mandatory online connectivity for single-player modes. Rockstar and parent company Take-Two have already filed DMCA takedown requests, which some observers view as indirect confirmation of the material's authenticity. The footage reportedly shows basketball mechanics, vehicle customization, trunk-opening animations, a stamina meter, and an honor system reminiscent of Red Dead Redemption 2. The alleged map includes five counties, an extensive rail network, and numerous small islands. At the same time, Cyberleek is promoting a Solana-based token and soliciting donations, prompting several outlets to question whether the operation is partly a cryptocurrency marketing scheme.
Russian Medical Data Leaks Explode in July: 88 Million Records Exposed
In July 2026 more than 100 million records containing personal data of Russian citizens appeared in open access. Experts from Perspektivny Monitoring recorded 17 separate leaks originating from commercial organizations, online platforms, government bodies, e-commerce stores and medical institutions. The medical sector accounted for the overwhelming majority with 88.37 million records leaked, a sharp increase from 1.7 million in June. Two major incidents, one involving a large medical information system, drove the spike. Head of cyber threat research Nikolay Galkin stated that medical data has now leaked for four consecutive months and that attackers are deliberately targeting highly sensitive information. Other sectors also suffered losses, with 11.12 million records from commercial entities, 8.45 million from online platforms, 8.36 million from government organizations and 2.1 million from internet shops. Stolen databases are routinely traded in messenger channels and dark web marketplaces for use in fraud schemes.
SplitVPN Data Breach Exposes Personal Information of 865,000 Users
A data breach at the Russian VPN provider SplitVPN, formerly known as NotVPN, has exposed the personal details of approximately 865,000 users. The incident, which occurred in July 2026, involved a 17 GB SQL database containing emails, IP addresses, geolocation data, and partial payment card information. The stolen material was later distributed on a cybercrime forum, revealing 23.4 million user records, 13.6 million devices, and 2.6 million payment entries. Nearly 58 million connection logs spanning June 2025 to 21 July 2026 were also included, contradicting the companyโs previous no-logs policy. The exposure is particularly concerning for users relying on the service to evade censorship and surveillance.
Click to Pray App Exposed Personal Data of 719,000 Users Through Unprotected API Endpoint
Security researcher BobDaHacker discovered an IDOR vulnerability in the official Click to Pray application run by the Pope's Worldwide Prayer Network. The flaw allowed anyone to retrieve full user profiles, including names, emails, countries, and birth dates, by simply incrementing numeric user IDs in API requests. No authorization checks or rate limits were present on the endpoint despite the service holding data for over 719,000 registered accounts. The researcher reported the issue to nine contacts in January 2026 but received no response for seven months. Dark Reading independently verified the exposure before publication, after which the endpoint was quickly restricted. The same service had suffered similar authorization failures in 2019 involving PIN code exposure through its eRosary application. The case highlights persistent gaps in object-level authorization and responsible disclosure channels at the Vatican-backed platform.
Measuring Data Leak Risk by Days of Silence Rather Than Megabytes in Cloud Environments
A financial expert turned security specialist argues that the true cost of data leaks in cloud offices stems not from the volume of exposed files but from the duration they remain undetected. The article details how routine actions such as making documents public, forwarding emails externally, or changing passwords can silently expose sensitive information in platforms like Yandex 360 without triggering any alerts. It warns against blanket prohibitions that push risky behavior into unmonitored channels like personal email or messengers, reducing visibility to zero. Instead, the recommended approach focuses on real-time event-driven notifications combined with automated remediation to minimize the window of exposure. The piece provides a detailed checklist for evaluating monitoring tools, including immediate reaction capabilities, self-healing actions, regular overview reports, and proof of system health. Emphasis is placed on secure integration via OAuth, data residency compliance, and the importance of treating employees as hurried professionals rather than malicious actors.
Russian Interior Ministry Opens Five Criminal Cases Against 'Glaz Boga' Analog Platforms Selling Personal Data of Russian Citizens
The Russian Ministry of Internal Affairs (MVD) has initiated five criminal investigations following the discovery of online platforms that sold personal data of Russian citizens, operating on the same model as the notorious 'Glaz Boga' service. These platforms allowed users to pay for access to detailed biographies and confidential information compiled into multiple files, including passport details, bank account records, and other sensitive personal information. The cases are being investigated under Article 272.1 of the Russian Criminal Code, which addresses the illegal use, transfer, collection, and storage of computer information containing personal data. Authorities have seized the servers of the implicated services and are currently analyzing their contents to gather evidence, although the specific names of the platforms, the number of clients, and the volume of data sold remain undisclosed. The developments highlight how repeated data leaks have transformed personal information into a marketable commodity traded on underground marketplaces, prompting law enforcement action against the operators responsible for distributing such data.
Solar inRights 3.11 Automatically Blocks Corporate Accounts Whose Passwords Appear in Dark Web Leaks
GC Solar has released Solar inRights 3.11, a major update to its identity and access management platform that integrates directly with the Solar AURA threat monitoring service. The new version automatically detects corporate credentials exposed in open sources and dark web dumps, validates whether the same login-password pairs remain active inside the organization, and instantly revokes access while alerting the security team. The feature addresses the common scenario in which employees reuse work email addresses and passwords on third-party websites, allowing attackers to test stolen credentials against corporate systems in what appears to be legitimate login attempts. Research cited by Solar shows that a single large Russian company typically has more than 600 unique corporate accounts circulating in public and underground sources, although only about 4 percent directly indicate infrastructure compromise. Yandex Cloud data further reveals that valid account abuse featured in 54 percent of over 25,000 attacks on cloud and hybrid environments during the first half of 2025. In addition to the leak-response capability, version 3.11 introduces improved search, request filtering, and integration templates for Active Directory, Exchange, and 1C.
Hacker Leaks Suno Source Code Exposing Massive Scraping of 2 Million YouTube Music Tracks and Customer Data Breach
A hacker known as ellie.191 has leaked the internal source code of Suno, one of the largest AI music generation services, to 404 Media, revealing extensive unauthorized scraping of copyrighted material from YouTube Music, Deezer, Genius, and other platforms. The leaked files, believed to date from 2023 and 2024, detail how Suno collected over 2 million music tracks and hundreds of thousands of hours of audio, including 152,000 hours from YouTube Music alone, along with 420,000 podcasts totaling nearly 1 million hours. Additional datasets came from Pond5, Jamendo, Freesound, MuseScore, and other libraries, with the company using Bright Data proxies to bypass restrictions and tools to isolate vocals from instrumental tracks. The breach also exposed hundreds of thousands of customer records, including emails, phone numbers, and partial Stripe payment data, which multiple users have already confirmed as accurate. Suno claims the incident was limited, occurred in November 2025, and involved only outdated code, while denying any leak of sensitive payment information. The hacker gained access via an employee account compromised by the Shai-Hulud worm, which stole GitHub and cloud credentials, and stated the attack was driven purely by curiosity rather than a specific motive. This disclosure lends support to ongoing lawsuits from the Recording Industry Association of America alleging direct copyright infringement by Suno.
Over 600 Leaked Corporate Accounts Found Per Major Russian Company, with Half Exposing Plaintext Passwords
A study by Solar AURA examined nearly 19,300 records tied to the ten largest Russian companies from the RBC500 ranking and uncovered 6,194 unique corporate accounts. More than half of these credentials โ 3,739 โ were circulating on the dark web with passwords in plaintext. Only 4% of cases showed evidence of direct compromise of corporate infrastructure, indicating that the majority stemmed from employees reusing work emails and passwords on external platforms such as marketplaces, forums, and SaaS services. Researchers also identified over 12,600 additional records containing employee personal data that can be leveraged for targeted social-engineering attacks. The findings highlight how credential-stuffing, phishing, and password-reset abuse become trivial once external leaks occur, especially when short or reused passwords are involved. Experts recommend continuous leak monitoring, mandatory multi-factor authentication, and rapid blocking of exposed accounts to reduce risk.
Argentina Football Association Admits Hack After Victory Over Egypt: Fake Email Questions Referee Integrity in World Cup Match
Following Argentina's 1/8 finals victory over Egypt at the FIFA World Cup, the Argentine Football Association (AFA) suffered a significant cyber intrusion that allowed hackers to send a forged email from an official AFA Medios account to accredited journalists. The message accused French referee Francois Letexier of biased officiating in favor of Argentina, lavishly praised the Egyptian team's performance, and included threatening language tied to the Middle East conflict. AFA quickly denied authorizing the message and confirmed unauthorized access to internal systems, including parts of its database containing emails, passwords, and IP addresses that may now be sold on dark web forums. The fabricated claims closely mirrored public criticisms voiced by Egyptian coach Hossam Hassan and player Mostafa Zico after their elimination. AFA has launched a full investigation to assess the breach's scope and improve security, while advising affected users to change passwords immediately. Argentina, meanwhile, continues preparations for its quarterfinal clash against Switzerland.
630GB of Apple Secrets Leaked on Dark Web: WorldLeaks Breach Shatters Tata Electronics Supply Chain Security
In June 2026, the ransomware group WorldLeaks infiltrated Tata Electronics, Apple's key manufacturing partner in India, and exfiltrated 630GB of highly sensitive data comprising over 200,000 files that were subsequently posted on the dark web. The stolen materials include unreleased iPhone 18 Pro motherboard schematics, A20 Pro chip technical manuals, complete supplier lists, Tesla component designs, and employee passport copies, exposing the vulnerabilities in Apple's two-decade supply chain secrecy system built at a cost of billions of dollars. WorldLeaks, formerly known as Hunters International, employed a 'steal-only' tactic without encryption, capitalizing on the growing trend of data extortion that has proven more profitable than traditional ransomware. The breach raises serious concerns about Apple's ambitious India manufacturing expansion, which aims to increase local component sourcing from 10% to 50% within three years, and highlights broader risks to global supply chains involving companies such as Tesla, TSMC, and Qualcomm. Apple responded swiftly by deploying DMCA takedowns across platforms like X within 24 hours, yet the irreversible nature of dark web leaks underscores the need for enhanced supplier security audits, data segmentation, and proactive data loss prevention measures.
Medtronic Cyberattack Exposes Patient Data: Six-Day Breach Puts Social Security Numbers and Health Records at Risk
In April 2026, medical device giant Medtronic suffered a cyber intrusion that lasted six days, allowing unauthorized access to backend IT systems containing sensitive patient information. The breach, discovered on April 19 after beginning on April 13, exposed names, contact details, birth dates, Social Security numbers, and health treatment data linked to devices such as pacemakers, insulin pumps, and neurostimulators. Although the medical devices themselves remain unaffected and show no signs of remote tampering, the leaked data poses severe risks of identity theft, financial fraud, and targeted scams that could persist for years. Medtronic has initiated emergency response measures, engaged external experts, and notified law enforcement and regulators, while offering 24 months of free identity monitoring to affected users. The incident highlights how even large enterprises struggle with securing ordinary office IT systems that store critical patient records, underscoring the need for individuals to monitor accounts and adopt stronger security habits.
15-Year-Old Saitama Student Uses ChatGPT to Mass-Cancel 46,812 Bandai Channel Subscriptions, Triggering Service Outage and Data Breach Concerns
A 15-year-old boy from Saitama Prefecture has been arrested for developing and deploying a program that canceled 46,812 user subscriptions on the Bandai Channel anime streaming service owned by Bandai Namco Filmworks. The teenager initially wrote the code himself while in middle school but turned to ChatGPT to rewrite it in a faster programming language after the original version proved too slow. On November 4, 2025, he sent thousands of fake account-deletion requests that forced the company to temporarily shut down the platform. When the company attempted to block his access, the student changed his IP address more than 30 times to continue the attack. He had previously been detained in June for other computer-related offenses and later admitted he simply wanted access to numerous accounts without holding any grudge against the company. The incident prompted Bandai Namco Filmworks to report the matter to Tokyo police and later disclose a potential leak of personal data belonging to up to 1.36 million users, although no evidence of data publication has been found.