Articles tagged "Data Breach"

Found 354 articles

Kraken, a cryptocurrency exchange, is facing a ransom demand after a data breach linked to an insider threat. The incident came to light in February 2025 when the company found a video on a criminal forum that traced back to one of its support staff members. This breach potentially compromises sensitive user data, raising concerns about the security of personal information held by the exchange. The situation is particularly concerning given the rise in cyberattacks targeting financial institutions. Users and stakeholders should be aware of the risks associated with such breaches and the importance of robust security measures.

Impact: User data at Kraken
Remediation: N/A
Read Original
ShinyHunters Leak Rockstar Games Data, No Player Records Impacted

Hackread – Cybersecurity News, Data Breaches, AI and More

The hacking group ShinyHunters has leaked 7.54 GB of data from Rockstar Games, specifically from their Snowflake analytics systems. Fortunately, Rockstar confirmed that no player records or personal information were compromised in this incident. This leak raises concerns about the security of game development companies and the potential for sensitive corporate information to be exposed. While player data remains safe, the breach could still impact Rockstar's reputation and business operations. Companies in the gaming industry need to be vigilant about their data security to prevent similar incidents in the future.

Impact: Rockstar Games, Snowflake analytics systems
Remediation: N/A
Read Original

Researchers at Barracuda have reported a significant increase in brute-force attacks originating from the Middle East, with a startling 88% of such attempts occurring in the region during the first quarter of the year. This surge raises concerns for organizations that may be targeted, especially those with weak password policies or inadequate security measures. Brute-force attacks involve systematically trying various password combinations to gain unauthorized access to accounts, which can lead to data breaches and financial losses. Companies in sectors like finance, healthcare, and e-commerce should take this trend seriously and reinforce their security protocols to protect sensitive information. Implementing stronger password requirements and two-factor authentication are crucial steps to mitigate these risks.

Impact: N/A
Remediation: Companies should implement stronger password policies and enable two-factor authentication.
Read Original
Actively Exploited

Mercor, an AI staffing company, is currently dealing with multiple class-action lawsuits stemming from a security breach linked to the LiteLLM open-source AI platform. The breach reportedly compromised Mercor’s systems, leading to allegations of damages against the company. At least four lawsuits have been filed, highlighting the potential legal and financial repercussions for Mercor as it navigates the fallout from this incident. This situation raises concerns not only about the security of AI platforms but also about how companies manage and protect sensitive information in the face of vulnerabilities. The outcome of these lawsuits could set important precedents for accountability in the tech industry.

Impact: Mercor systems, LiteLLM platform
Remediation: N/A
Read Original

Kraken, a major cryptocurrency exchange, is facing extortion threats from a cybercrime group that claims to have gained access to sensitive internal systems. The attackers are demanding ransom, threatening to release videos that allegedly demonstrate how they accessed client data. This incident raises serious concerns about the security of client information and the overall integrity of the exchange. Kraken has not disclosed the extent of the breach or how the hackers gained access, but the situation puts pressure on the company to bolster its security measures and protect its users. The threat of exposing internal operations is particularly alarming for any organization, especially in the cryptocurrency sector where trust is paramount.

Impact: Kraken cryptocurrency exchange, client data systems
Remediation: Strengthen internal security measures, conduct a thorough security audit, and educate staff on security protocols. Specific steps not provided.
Read Original
Booking.com Confirms Data Breach as Hackers Access Customer Details

Hackread – Cybersecurity News, Data Breaches, AI and More

Booking.com has confirmed that a data breach has occurred, compromising customer details. Although no payment information was accessed, the breach raises concerns about potential phishing scams targeting affected users. This incident puts customers at risk of receiving fraudulent communications that could lead to further data theft or financial loss. Booking.com has not specified how many users are impacted or the exact nature of the compromised data. Customers should remain vigilant and be cautious with any unsolicited emails or messages they receive following this breach.

Impact: Booking.com customer data
Remediation: Users are advised to be cautious of phishing attempts and to monitor their accounts for any suspicious activity.
Read Original

A significant data breach involving Rockstar Games has been reported, with a leak of 8.1GB of sensitive data attributed to the hacking group ShinyHunters. The leaked files include anti-cheat source code, player analytics, and game assets, along with Zendesk support tickets. This breach raises concerns about the security of user data and the integrity of the games produced by Rockstar. Game developers and players alike should be aware of the potential risks associated with such leaks, including the possibility of cheating and exploitation in online games. The data was reportedly obtained through a third-party service called Anodot, highlighting the vulnerabilities that can arise from third-party integrations.

Impact: Rockstar Games, including its online gaming platforms and related services.
Remediation: Companies should evaluate their data security measures, especially concerning third-party integrations and anti-cheat mechanisms.
Read Original

RCI Hospitality, a major player in the nightclub industry, has reported a data breach due to an IDOR (Insecure Direct Object Reference) vulnerability in RCI Internet Services. This security flaw exposed sensitive contractor data, potentially affecting individuals associated with the company. The breach was disclosed in a filing with the Securities and Exchange Commission (SEC), indicating that the company is taking the matter seriously. This incident raises concerns about data security in the hospitality sector, as breaches can lead to identity theft and other malicious activities. Stakeholders will need to monitor the situation closely as RCI investigates the extent of the exposure and implements necessary safeguards.

Impact: Contractor data from RCI Internet Services
Remediation: N/A
Read Original

Basic-Fit, a popular fitness chain in Europe, has reported a significant data breach affecting approximately one million of its customers. Hackers managed to infiltrate the company's systems and accessed sensitive information. While Basic-Fit has not specified exactly what data was compromised, breaches of this nature often involve personal details such as names, email addresses, and possibly payment information. This incident raises concerns about the security of customer data in the fitness industry, especially as more people rely on online services for their health and fitness needs. Customers are advised to monitor their accounts for any unusual activity and consider changing their passwords to enhance their security.

Impact: Customer data including names, email addresses, and potentially payment information.
Remediation: Customers should monitor their accounts for unusual activity and change their passwords.
Read Original

Rockstar Games has recently experienced a data breach due to a security incident involving Anodot, a data analytics company. The ShinyHunters extortion group has leaked sensitive analytics data stolen from Rockstar on their data leak site. This incident raises concerns for the gaming community as it not only affects Rockstar but also puts user data at risk. The leaked information could potentially be used for further targeted attacks or to exploit vulnerabilities in Rockstar's systems. It underscores the importance for companies to bolster their security measures in the face of such threats.

Impact: Rockstar Games, Anodot
Remediation: Companies should enhance their security protocols and monitor for any suspicious activity related to the leaked data.
Read Original

Booking.com has reported a data breach involving unauthorized access to its systems, which has compromised sensitive reservation and user data. The company is urging affected users to reset their reservation PINs as a precautionary measure. This incident raises significant concerns for travelers who use the booking platform, as the exposed data could potentially be used for fraudulent activities. Booking.com has not disclosed the exact number of users affected or the specific data that was accessed, but the breach underscores the ongoing risks associated with online booking systems. Users are advised to monitor their accounts for any suspicious activity and to take steps to secure their information.

Impact: Booking.com user accounts and reservation data
Remediation: Users are advised to reset their reservation PINs.
Read Original

Booking.com has reported that hackers gained access to user information, although the company has not disclosed how many customers were affected. They have stated that the situation has been contained, but specifics about the type of data compromised remain unclear. This incident raises concerns for users who may have shared sensitive booking details on the platform. Protecting user data is crucial for maintaining trust in online services, especially in industries like travel where personal information is frequently exchanged. Booking.com will likely need to assess its security measures to prevent future breaches and reassure customers about their data safety.

Impact: Booking.com user accounts and associated booking information
Remediation: N/A
Read Original

A new infostealer called 'Storm' has emerged, capable of hijacking user sessions by decrypting data on the server side rather than locally. This technique allows attackers to bypass traditional security measures like passwords and multi-factor authentication (MFA). Researchers from Varonis have demonstrated how the infostealer sends sensitive browser data directly to the attackers' servers, raising significant concerns about user privacy and account security. The implications are serious, as organizations relying on standard security protocols may find themselves vulnerable to these sophisticated attacks. Companies should be vigilant and assess their security measures to protect against this evolving threat.

Impact: Web browsers and online accounts that rely on session management and MFA.
Remediation: Implement enhanced security measures such as stronger session management, continuous monitoring of user sessions, and consider additional layers of authentication beyond MFA.
Read Original
Hacker Used Claude Code, GPT-4.1 to Exfiltrate Hundreds of Millions of Mexican Records

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

A hacker has reportedly used advanced AI tools, Claude Code and GPT-4.1, to steal personal records of hundreds of millions of Mexican citizens from nine different government agencies. This breach raises serious concerns about data security and the potential misuse of sensitive information. The stolen records likely include personal identifiers, which could lead to identity theft or fraud. The incident highlights vulnerabilities in governmental data protection practices and the growing capabilities of cybercriminals using AI for malicious purposes. Authorities will need to investigate the breach thoroughly and implement stronger security measures to protect citizen data in the future.

Impact: Records of Mexican citizens from nine government agencies
Remediation: Authorities should enhance data security protocols and conduct a comprehensive review of existing safeguards in government systems.
Read Original
ShinyHunters Claims Rockstar Games Snowflake Breach via Anodot

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

ShinyHunters, a known hacking group, claims to have gained access to data from Rockstar Games' Snowflake platform due to a breach involving Anodot, a data analytics company. They have threatened to leak this data on April 14 unless their ransom demands are met. This incident raises concerns about the security of sensitive information related to Rockstar, a major player in the gaming industry. If the breach is legitimate, it could expose user data and proprietary information, impacting both the company and its customers. The situation is still developing, and Rockstar Games has not yet confirmed the breach or provided details on any potential data compromise.

Impact: Rockstar Games, Snowflake platform, Anodot
Remediation: N/A
Read Original
Page 1 of 24Next