Tech News
← Home  ·  All topics

Data Breach

49 GoKawiil briefs on this topic

Hackers dump Flock Safety camera's internal data, exposing surveillance details

Hackers physically removed a Flock Safety license plate reader from a roadway, extracted an encryption key from its storage, and shared the recovered files with 404 Media and WIRED. The data showed the device's software identifies not just vehicles and plates but also people, bicycles, and even small details like bumper stickers, generating over a million images in just weeks of logs.

Spain's AEPD receives first reported AI-agent-driven data breach

Spain's Data Protection Agency (AEPD) has received its first notification of a breach allegedly executed by an autonomous AI agent built on a large language model. According to the report, the agent found system vulnerabilities, logged in, probed connected applications, then altered personal data and accessed financial records. The AEPD has not yet verified the claims but says the case demonstrates that AI-driven breaches have moved from theory to practice.

Hackers Extract and Publish Data From a Stolen Flock Safety Camera

A group of hackers physically removed a Flock Safety license-plate camera, copied its internal storage, and recovered an encryption key that unlocked thousands of stored vehicle images. They shared the extracted files with 404 Media and WIRED, and separately with the transparency group Distributed Denial of Secrets, along with details of how they pulled off the extraction so others could replicate it.

Ransomware's hidden costs dwarf ransom payments, new data shows

IBM's Cost of a Data Breach Report 2025 puts the average total cost of a ransomware incident at $5.08 million once downtime, remediation, legal work and business disruption are counted, while Verizon's 2026 DBIR pegs the median ransom payment at just $139,875. Datto's State of BCDR Report 2025 adds that while over 60% of organizations expect to recover within a day, only 35% actually do, and attackers increasingly target backup systems, forcing costly forensic and incident-response work when recovery options are compromised.

Revolut Mistakenly Shared Customer Data With Impersonator Posing as Regulator

Revolut, valued as Europe's most valuable startup, disclosed customer information to an individual who fraudulently claimed to represent a government agency. Hundreds of accounts were affected by the breach, which stemmed from the bank's own verification failure rather than a hack of its systems.

CenterPoint Energy confirms data breach after hacker leaks 7.49 million records

CenterPoint Energy has confirmed in an SEC filing that an unauthorized party accessed customer personal information through one of its external-facing systems. The disclosure follows claims from a hacker who says they exfiltrated 7.49 million records—including names, addresses, account numbers, billing details and partial Social Security numbers—by exploiting an unprotected public API lacking rate limiting or firewall defenses.

Revolut exposes customer passports and financial data via fake government request

Revolut disclosed that it inadvertently sent personal and financial data of some customers to a threat actor who impersonated a government agency using an authenticated domain. The leaked data reportedly includes identity documents, selfies, account statements, IBAN numbers, and transaction histories, including Bitcoin transactions. Revolut says the breach affects a limited but undisclosed number of accounts and that customer funds remain unaffected.

Misconfigured Vietnam-linked APIS database exposed 220 million traveler records

Security researchers at Kinryu Labs found an unsecured Elasticsearch cluster in Viettel-assigned IP space in Hanoi containing over 220 million passenger and crew records dating from 2017 to 2026. The exposed data included passport numbers, nationalities, dates of birth, flight details, seat assignments and baggage information, accessible due to a chain of misconfigurations and default credentials. The database was secured after being reported, though it remains unknown whether the data was accessed or copied before that point.

Revolut Exposes Customer Data After Fake Government Email Scam

Revolut confirmed it handed over sensitive customer information after receiving fraudulent data requests sent from what appeared to be a legitimate government agency email domain. The exposed data reportedly included names, birth dates, addresses, phone numbers, ID documents, and possibly verification selfies and transaction histories. The company says only a limited number of customers were affected and that it has since blocked the fraudulent email address and alerted authorities.

FLHSMV: DAVID driver database breached via stolen Plant City police credentials

Florida's Department of Highway Safety and Motor Vehicles confirmed the ShinyHunters extortion group breached its DAVID driver database on September 4, 2026, after the gang claimed to have stolen over 200,000 driver records. FLHSMV said the intruder used login credentials from a single Plant City Police Department account that had been improperly saved on the employee's personal device, contradicting ShinyHunters' claim that it exploited a password-reset flaw across multiple accounts.

Trezor customers hit by phishing wave after Brevo email vendor breach

Trezor disclosed that hackers who compromised 138 accounts at email marketing provider Brevo used the access to send roughly 347,000 phishing emails to its customers. The messages, disguised as security alerts, directed recipients to a fake app designed to steal their wallet backup passwords. Trezor says its own products and account systems were not breached, but the stolen credentials could let attackers drain victims' crypto holdings.

Trezor confirms 347,000 emails exposed via Brevo breach, 2,500 users phished

Trezor disclosed that a breach at its third-party email provider Brevo let attackers send fake security alerts to its opt-in newsletter subscribers, reaching roughly 347,000 email addresses. The fraudulent messages warned of a fake microcontroller vulnerability and pushed recipients to a malicious app requesting wallet backup phrases; Trezor says 2,500 people clicked the link before it disabled the domain within 20 minutes.