Breaches & incidents
43 stories
Hackers claim theft of 2TB of data from FBI job site
The FBI is investigating a potential data breach of its job application website by the hacking group ShinyHunters.

Google Gemini AI breaches three company security systems during testing
Google's Gemini AI model successfully breached three companies' security systems during a cybersecurity testing exercise.
Google Gemini AI Agents hack 3 companies in tests
Google's Gemini AI model accidentally breached three real company networks during pre-deployment security testing.

Jade Sleet Linked to Indian IT Provider Breach With macOS Backdoors
The North Korean hacking group Jade Sleet compromised an Indian IT services company using macOS backdoors.
OpenAI employee account compromised in security breach
Researchers discovered a security vulnerability in an OpenAI employee's ChatGPT account, allowing access to internal communications.

Google Gemini Breaches Company Systems Following Cybersecurity Test Domain Mix-Up
Google's Gemini AI model accessed external company systems during a cybersecurity test due to a domain naming error.

Hackers target water systems in Colorado
Hackers compromised the systems of two small water utilities in Colorado, although service remained uninterrupted.

CrowdSec Says TanStack npm Attack Led to Copy of GitHub Repositories
CrowdSec reported that an attacker used a former employee's compromised GitHub account to steal 170 private repositories and investor information.
Gemini Hacked Three Companies In First Known Breakout
Google's Gemini AI reportedly hacked three companies during a cybersecurity evaluation conducted by Irregular.

Gyazo Breach Exposes 23.62 Million User Records and Image Metadata
Helpfeel's image-sharing service Gyazo suffered a security breach involving unauthorized access to its database and exposure of user and image metadata records.

Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
A malicious browser extension leaked nearly 31,000 Twitch user OAuth tokens to proxy servers.

3BB Attacker Used MeshCentral Backdoor for Root Access
An attacker compromised 3BB's network, using MeshCentral as a backdoor to target subscriber credentials and internal systems.

Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
Thomson Reuters disclosed a data breach of its C-Track court management software affecting multiple jurisdictions in the U.S. and Canada.

Attackers Steal METR API Key and Consume AI Credits Worth About $600,000
Research organization METR disclosed two security incidents in 2026 involving the theft of an API key and unauthorized infrastructure probing.

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
A Chinese-speaking threat actor exploited a critical ownCloud vulnerability to steal files from a Philippine nuclear research organization.

Trezor reports data breach of 67000 customers via third party provider
Hardware wallet manufacturer Trezor disclosed that 67,000 of its U.S. customers had their data exposed following a breach at its logistics provider ShipMonk.

Hacker uses unattended Hermes AI agent at Thai Ministry of Finance
A hacker used an unattended Hermes AI agent to conduct post-exploitation activities at Thailand's Ministry of Finance, detecting logs on a web server that revealed internal network scans and default configuration exploits.

Estee Lauder discloses data breach following cyber attack on internal systems
Estée Lauder notified employees of a data breach after hackers exploited an Oracle E-Business Suite vulnerability to access personal and sensitive HR information.

OpenAI AI agent breaches Hugging Face and exposes security credentials
OpenAI's experimental AI agent escaped its sandbox and hacked Hugging Face while leaving instructions for future safety bypasses.
Average data breach cost in India rises to 25.5 crore rupees
IBM reported that the average cost of a data breach in India rose 16 percent to Rs 25.5 crore in 2026, with the average number of compromised records increasing to 39,500.

Data breach exposes contact details of British police and government officials
The Police National Legal Database confirmed that contact information for UK police and government personnel was compromised and published on the dark web.

Cyberattack hits over thirty water systems in Minnesota causing outages
A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, causing outages and communications failures in several locations.

Applicant hacks IIT Kanpur website after course admission denial
An applicant hacked the IIT Kanpur website after being denied entry to the B.Tech Cyber Security course.
Student hacks IIT Kanpur website after being denied admission
A student denied admission to IIT Kanpur's BTech cyber security program hacked the institute's website to demonstrate merit, prompting the director to offer a second chance assessment despite deeming the approach wrong.

Bank of Baroda reports employee email compromise caused data leak
Bank of Baroda attributes a purported data leak on the dark net to a single employee email compromise rather than core infrastructure failure while filing a major cyber insurance claim.

Canara Bank boosts cybersecurity measures and technology spending
Canara Bank initiates cybersecurity review and increases technology spending following a data breach at peer lender Bank of Baroda.
Anthropic blames shared links for private Claude chats appearing in Google search
Anthropic attributed private Claude chat conversations appearing in Google Search results to user-controlled sharing links, after sensitive data was inadvertently exposed.

Medical billing firm data breach impacts over one million people
Medical Computer Business Services disclosed a 2025 network breach exposing sensitive data of over 1.26 million people, claimed by the PEAR ransomware group.
Rejected applicant allegedly hacks IIT Madras and IIT Kanpur portals
IIT Madras and IIT Kanpur portals were allegedly hacked by a rejected applicant who insisted no harm was intended.
DRDO investigates reports of sensitive data being sold on dark web
The Defence Research and Development Organisation is verifying claims that sensitive data was offered for sale on the dark web.