Ernst & Young has become the latest major firm named by the ShinyHunters extortion gang. The group claims it carried out the recently disclosed EY data breach after gaining company credentials through a supply-chain attack. EY confirmed earlier this month that attackers had compromised a third-party support ticket platform used by its IT teams. The…
A threat actor claims to be selling 75 million Revolut customer records on a cybercrime forum. The alleged Revolut data leak includes names, emails, phone numbers, addresses and partial card details. However, the claimed number of records has not been verified. Revolut says it is aware of the listing but has found no signs of…
OnTrac has started notifying customers after hackers accessed its corporate network and may have obtained personal information. The parcel delivery company detected the incident on 23 March. Its investigation found that the attacker accessed certain company files between 20 and 22 March. OnTrac has not disclosed the full scope OnTrac confirmed that the affected files…
Origin Energy has confirmed a data breach involving unauthorised access to customer information. The Australian energy provider is investigating how many people were affected and is contacting confirmed victims directly. Origin Energy serves around 4.8 million customers across its electricity, natural gas and broadband businesses. Customer details potentially exposed Origin said the incident may have…
Upbound Group says a cyberattack against its systems led to around $13 million in losses after criminals used stolen data to create fraudulent Acima lease-to-own agreements. The fintech company disclosed the incident in a filing with the US Securities and Exchange Commission. Upbound said an unauthorised party obtained certain non-sensitive customer information and other documents…
South Korea has disclosed a data breach affecting current and former Ministry of Foreign Affairs employees, including diplomats posted overseas. Hackers reportedly accessed the National Diplomatic Academy’s online education platform for around 10 months. The attackers exploited a server vulnerability in April 2025 and remained active until February 2026. The South Korea diplomatic data breach…
A Suno data breach reportedly exposed the personal information of more than 55 million users. The dataset includes email addresses, phone numbers, physical addresses, purchase details, and partial payment-card information. The incident reportedly occurred in November 2025. However, the data appeared online only last week. Suno did not notify individual users when it discovered the…
Chick-fil-A has disclosed a data breach after attackers used credential stuffing to access customer accounts. The company detected suspicious sign-in activity involving certain Chick-fil-A One accounts. The attacks targeted the restaurant chain’s website and mobile app between June 17 and June 19, 2026. Chick-fil-A concluded on July 13 that unauthorised parties may have accessed customer…
OpenAI says its AI models accessed Hugging Face infrastructure during a controlled cybersecurity evaluation. The incident involved GPT-5.6 Sol and a more capable pre-release model with reduced cyber safety refusals. According to OpenAI, the models were completing a public cybersecurity benchmark in a sandboxed environment. Instead of solving the challenge directly, they allegedly tried to…
Attackers accessed part of Craneware’s systems and stole a significant volume of data, the healthtech company has confirmed. Based in Scotland, Craneware provides accounting and billing software to US healthcare organisations. More than 2,000 hospitals use its services, alongside nearly 10,000 clinics and retail pharmacies. Despite the intrusion, customer services and business operations continued without…