ShinyHunters claims it stole 50GB of data from workwear company Carhartt, including records linked to millions of customers and employees. The group alleges that Carhartt ended extortion talks after receiving a $3.3 million ransom demand. ShinyHunters lists Carhartt on leak site The hacking group added Carhartt to its dark web leak site and posted a…
The Jewelbug hacker group has breached government webmail systems in the Middle East while operating a parallel cryptocurrency fraud network. Researchers found that the same infrastructure supported cyber espionage, credential theft and AI-generated scam sites. Jewelbug compromises shared government webmail Jewelbug, also tracked as Earth Alux and REF7707, targeted government, military and critical-sector organisations across…
Security researchers have obtained a 153GB archive containing credentials allegedly stolen during the March LiteLLM supply-chain attack. The data reportedly links to almost 2,500 organisations, including AWS, Cisco, Samsung, Salesforce and other major companies. The LiteLLM breach archive contains cloud credentials, access tokens, AI provider keys and other sensitive data. However, exposure in the dataset…
Hardware wallet maker Trezor has disclosed a data breach affecting almost 14,000 customers after attackers accessed systems belonging to its shipping and logistics provider, ShipMonk. The Trezor data breach exposed customer order information, including names, email addresses, phone numbers and shipping addresses. Trezor said its own systems were not compromised and that customers’ hardware wallets…
Valve is notifying European Steam hardware customers about a data breach at its shipping partner, CEVA Logistics. The breach exposed delivery-related customer data. However, it did not expose Steam passwords, payment card details or Steam Guard codes. The Valve data breach could still help criminals create convincing phishing scams. Affected customers should be cautious with…
The Unlimited Technology Systems breach has affected more than 3.8 million people after attackers accessed files in the healthcare software provider’s data centre in October 2025. The company says the intruders may have copied highly sensitive patient and personal information during a five-day period. It began notifying affected people in July 2026. Attackers Accessed Files…
Levi Strauss & Co. says attackers stole corporate information after they used social engineering to compromise the company-issued computers of three employees. The clothing company says it contained the Levi Strauss cyberattack quickly and found no evidence that attackers accessed consumer data. The incident also caused no disruption to normal business operations. Attackers Targeted Three…
Switzerland’s federal IT office says attackers breached its Microsoft SharePoint servers and compromised approximately 200 user accounts. The Federal Office for Information Technology and Telecommunication, known as BIT, detected unusual activity on its SharePoint environment on July 28. After confirming the incident, the agency cut off external internet access, patched suspected vulnerabilities and reset passwords…
Electric scooter company Ryde has confirmed that a data breach has affected all of its customer accounts, or roughly 4.5 million people across Norway and other European markets. The company said an unauthorised party accessed its systems on August 2 and copied customer information before Ryde blocked the intrusion. Ryde operates in Norway, Sweden, Finland,…
The UK Information Commissioner’s Office has reprimanded the Metropolitan Police Service after two separate incidents exposed highly sensitive personal information. The regulator said the Metropolitan Police data leaks were foreseeable and preventable. It has issued both a reprimand and an enforcement notice requiring the force to improve its data protection practices. The cases involved information…