Skip to content
Tech News
clear
Topics: Today This Week This Month This Year

Dropbox accounts hijacked via flawed Lenovo single sign-on integration

Dropbox notified users that attackers gained unauthorized access to their accounts between August 4 and 21, 2026, though the company says no files were confirmed viewed or downloaded. The breach stemmed from a weakness in Lenovo's identity verification process, which let attackers register Lenovo IDs tied to victims' email addresses without owning those inboxes, then use those IDs to log into linked Dropbox accounts.

Novocure breach exposes data of 1,400+ cancer patients and staff

Novocure disclosed to the SEC that attackers gained unauthorized access to its systems in mid-August, exposing over 1,400 U.S. patient ID records without names attached. Fewer than 50 patients in the western U.S. had identifying information and healthcare provider contact details compromised, and an unspecified number of employees also had contact information exposed. The company says its treatment devices and operations remain unaffected and it is assessing notification obligations.

ShinyHunters claims theft of millions of patient records from McKesson's cloud systems

Pharmaceutical distributor McKesson confirmed hackers broke into several cloud-hosted accounts and stole data tied to its oncology and medical-surgical units. The ShinyHunters group told TechCrunch it used phishing and social engineering to trick employees into granting access, then pulled millions of rows of patient records from Snowflake and Salesforce environments, including names, Social Security numbers, diagnoses, medications, and employee home addresses.

FulcrumSec claims theft of 86GB from Manchester Airports Group in data breach

Extortion group FulcrumSec has claimed responsibility for a breach at Manchester Airports Group, saying it stole roughly 86GB of customer data across Manchester, London Stansted and East Midlands airports. BleepingComputer verified sample records against a real traveler's purchase history, finding detailed booking, payment and travel information beyond what MAG initially disclosed. The hackers allege they used exposed Iterable API credentials found in client-side JavaScript to access the data, including nearly 200,000 records tied to travel scheduled through 2026.

Hasbro confirms employee data breach affecting hundreds of workers

Hasbro has notified regulators that attackers gained unauthorized access to an employee account, exposing personal and financial details of staff. Massachusetts filings show at least 436 employees in that state had Social Security numbers, financial account data, card numbers, and driver's license information compromised. Hasbro says it disabled the compromised account, cut off unauthorized access, and added new safeguards, though it hasn't disclosed the full scope of the breach or when it was discovered.

ShinyHunters leaks data from 12.9 million Carhartt accounts after ransom refusal

ShinyHunters, an extortion group, published roughly 50GB of stolen Carhartt data on the dark web after the apparel maker declined to pay a $3.3 million ransom demand. Have I Been Pwned founder Troy Hunt confirmed the leak stems from a breach of Carhartt's Databricks analytics platform, exposing 12.9 million accounts containing names, emails, phone numbers, and addresses, alongside employee and corporate records.

LACMA confirms 2025 breach exposed Social Security numbers and medical records

The Los Angeles County Museum of Art disclosed that hackers accessed its network for four days before detection on July 11, 2025, compromising sensitive data belonging to customers and employees. Exposed information includes Social Security numbers, driver's license numbers, partial financial and payment card details, and health-related records such as diagnoses and treatment history. The museum only completed its investigation and began notifying affected individuals in late February 2026, more than a year after the intrusion was found.

Nutex Health discloses data breach in SEC filing

Nutex Health, a for-profit hospital operator with 28 facilities across 12 states, told the SEC that an unauthorized third party accessed and stole data from its servers, some of which may be private or confidential. The company has hired forensic investigators, notified law enforcement, and activated its incident response plan, but has not yet determined whose data—patients, employees, or partners—was affected.

Encryption key exposed in API led to breach of South Korea's Modu-ui Changup startup platform

South Korea's government-backed startup support platform, Modu-ui Changup, suffered a data breach that exposed personal information and startup idea summaries of roughly 5,000 successful applicants. Investigators from the Ministry of SMEs and Startups, National Intelligence Service, Cyber Security Center and National Police Agency traced the root cause to an encryption key that had been embedded in an API response, allowing an outside party to harvest it via web crawling and decrypt supposedly protected data.

Today's top topics: openai samsung smart glasses android authority gemini adobe premiere anthropic data centers galaxy s27 ultra battersea power station
View all today's topics →