Category: Data Breaches


  • Taco Bell Operator Discloses Employee Data Breach

    Pan American Group LLC has disclosed a data breach after an unknown attacker accessed company servers and obtained files containing employee information. The Taco Bell operator breach occurred in April 2026. Pan American Group says it found suspicious activity on April 9 and later confirmed that an attacker had accessed certain servers between April 8…

  • LACMA Data Breach Exposed Social Security and Medical Data

    The Los Angeles County Museum of Art has disclosed that a cyberattack exposed sensitive customer and employee information, including Social Security numbers and medical data. LACMA detected suspicious activity on July 11, 2025. The museum says the activity began four days earlier, and investigators confirmed that attackers had compromised its network in August 2025. The…

  • CyrusOne Data Breach Claim Raises Risks for Major Tech Tenants

    A claimed CyrusOne data breach has raised concerns about the possible exposure of sensitive data center documents, employee records and customer information. The ShinyHunters extortion group says it stole millions of records and is demanding $13 million. CyrusOne had not publicly confirmed the alleged incident at the time of reporting. The attackers had also not…

  • South Korean Startup Platform Breach Exposes Encryption Key Failure

    A South Korean startup platform breach has highlighted a serious weakness in how organisations protect encrypted information. Authorities said an encryption key was exposed through an application programming interface, or API, on Modu-ui Changup. The government-backed platform supports a nationwide startup audition programme overseen by South Korea’s Ministry of SMEs and Startups. The exposed key…

  • ReliaQuest Says Okta Session Was Exposed in Social Engineering Attack

    ReliaQuest has responded to claims of a data breach after ShinyHunters posted screenshots that appeared to show the cybersecurity firm’s Okta identity dashboard. The company confirmed that a social engineering attack on August 22 briefly gave a threat actor access to one employee’s identity dashboard session. However, ReliaQuest said its systems, applications and customer data…

  • Apollo Confirms Data Breach Exposing Social Security Numbers

    Apollo Global Management has confirmed a cyberattack that exposed sensitive personal information, including Social Security numbers. The Apollo data breach involved unauthorised access to some of the investment giant’s cloud platforms in July. Attackers accessed Apollo cloud platforms Apollo said a social-engineering attack gave intruders access to certain cloud systems between July 6 and July…

  • LockBit Posts US Bank Breach Claim on Dark Web

    LockBit has published a US Bank breach claim on its dark-web leak site and set a September 4 deadline. The ransomware group has not released a data sample, so the alleged incident remains unverified. The post includes a countdown clock, a tactic ransomware groups often use to pressure organisations into paying before they publish stolen…

  • ClarityCheck Facial Data Leak Exposes 9 Million Images

    The ClarityCheck facial data leak reportedly exposed a database containing more than nine million facial images. The collection allegedly included photographs of children and teenagers, raising serious privacy and surveillance concerns. Security researcher Jeremiah Fowler said the database held around 450GB of data. He found it online without password protection or encryption, according to his…

  • CEVA Logistics Data Breach Exposes Employee Information

    The CEVA Logistics data breach has exposed personal and employment information belonging to current and former workers, the company has confirmed. The incident had already affected several of the logistics group’s business partners and their customers. CEVA says the compromised data differs between individuals. However, the available information suggests that the attackers accessed a wide…

  • Philadelphia Casino Data Breach Claim Survives in Part

    The Philadelphia Casino Data Breach lawsuit has produced a split federal court decision. A judge allowed a negligence claim against Rivers Casino Philadelphia to continue, while dismissing several other legal theories. Current and former employees, along with casino patrons, filed the case after the casino allegedly discovered unauthorised access to its network. The attackers allegedly…