Tech News
← Home  ·  All topics

Data Breach

49 GoKawiil briefs on this topic

FBI investigates ShinyHunters' claim of stealing employee data via jobs site bug

Hacker group ShinyHunters claims to have exploited an unknown vulnerability on FBIJobs.gov, taking the site offline and posting a banner declaring it 'seized.' The group told The New York Times it stole two to three terabytes of data including names, addresses, phone numbers, spouse names and medical information of current and former FBI employees and applicants, though none has been leaked yet.

ShinyHunters claims theft of 2-3TB of FBI employee data via Oracle zero-day

Hacking group ShinyHunters says it stole terabytes of sensitive data on FBI employees and job applicants, exploiting a zero-day flaw in Oracle's PeopleSoft software to breach Amazon Web Services' GovCloud. A sample reviewed by Reuters and 404 Media reportedly includes names, addresses, birthdates and Social Security numbers for about 5,000 employees, and the group also claimed responsibility for briefly hijacking the FBI's website. The FBI confirmed it is investigating a claimed compromise of the FBIJobs.gov portal and possible exposure of employee personal information.

Discord launches revamped age-verification system with more privacy options

Discord began rolling out a new age-verification system today, sorting users into adult, teen, and unconfirmed groups and restricting teens' access to sensitive content and message requests from strangers. The system replaces a February plan that required ID scans or facial recognition, which Discord dropped after user backlash and a 2025 breach exposed government IDs of 70,000 users verified through a third-party service.

Hackers deface FBI jobs website, claim access to agents' home addresses

A hacking group calling itself ShinyHunters defaced the FBI's jobs recruitment website and claims to possess home addresses of FBI agents. The group has demanded that the bureau retract a warning it issued in May about ShinyHunters, giving the FBI a one-week deadline.

Discord launches automated age-estimation system worldwide, excluding UK and Australia

Discord has begun automatically sorting users into age groups using account signals like account age, activity patterns, and connected servers, rather than requiring ID or selfie verification. Users estimated to be 13-17 will get added safety restrictions, while those judged 18+ see no account changes; anyone misclassified can manually verify age through account settings. The rollout follows a February pause of Discord's prior ID-based verification system after a third-party vendor breach exposed users' scanned identification documents.

Discord begins global age verification rollout for all users

Discord started rolling out age verification to its entire user base this week, months after pausing the plan in February amid privacy concerns over biometric scans and ID checks. CTO Stanislav Vishnevskiy said over 90% of users won't need to submit ID, as the platform will instead rely on existing account signals like tenure and activity patterns to estimate age.

ShinyHunters claims theft of FBI employee data, defaces bureau jobs site

Hacking group ShinyHunters told 404 Media it breached FBI-related systems and obtained personal data on all FBI employees and applicants, including names, home addresses, phone numbers, birthdates and spouse details. The group provided a sample of roughly 5,000 records, and 404 Media verified some phone numbers matched named individuals and linked others to Justice Department personnel. ShinyHunters also defaced the FBI's jobs website on Tuesday.

Sweden fines Miljödata $183,000 over 2025 breach exposing 2.2 million people

Sweden's data protection authority IMY has fined IT provider Miljödata SEK 1.8 million ($183,000) following a GDPR investigation into an August 2025 ransomware attack. The breach hit systems used by 80% of Swedish municipalities, exposing personal ID numbers, health data, and records involving minors after attackers published stolen data on the dark web under the name 'Datacarry'.

BigCommerce merchants hit after attackers hijack Ribon app credentials

BigCommerce confirmed that credentials for third-party Ribon and Ribon 1.5 apps, made by Fastr's Be A Part Of, were stolen and used to inject malicious scripts into a small number of merchant storefronts between September 13 and 17. UK retailer Master of Malt was among those affected, with attackers accessing customer names, emails, phone numbers, and shipping addresses, though passwords and payment data were not exposed. BigCommerce says its core platform and systems remained secure, and it disabled the compromised apps upon discovery.

South Korea triples maximum data-breach fine to 10% of company revenue

South Korea's Personal Information Protection Commission has enacted rules allowing fines of up to 10% of a company's annual revenue for major data leaks caused by intent or gross negligence, up from the previous 3% cap. The new rules, effective Friday, apply when 10 million or more people's data is exposed, and also require firms to notify users within 72 hours even if a breach is only suspected. The heightened penalty targets repeat offenders within three years or firms that ignore corrective orders and are subsequently breached.

Gyazo breach exposes 23.6 million user records via server vulnerability

Helpfeel-operated screenshot service Gyazo confirmed that attackers exploited a server flaw on September 11, 2026 to access its database and steal roughly 23.62 million user records. The company detected the intrusion the following day, patched the vulnerability, and has taken the platform offline for maintenance while investigating. Exposed data varies by account but can include names, emails, password hashes, session and device IDs, SSO tokens, billing details, and usage statistics, alongside 490 million image metadata records.

Spanish Regulator Confirms AI Agent Used to Breach Corporate Data, Alter Records

Spain's Data Protection Agency (AEPD) disclosed that an organization reported a breach in which an attacker used a mainstream language model to locate weak credentials and exploit an application flaw. The AI agent reportedly enabled the attacker to access corporate invoices and modify personal data records, though the organization and hacker remain unnamed.