Tech News
← Home  ·  All topics

Data Breach

49 GoKawiil briefs on this topic

IDScan suspected of massive breach exposing 150 million US and Canadian IDs

A dark web marketplace called Nexus emerged this week claiming to sell searchable access to over 150 million U.S. and Canadian driver's licenses and passports, with roughly half a million new records added daily. Security journalist Brian Krebs and researcher Zach Edwards traced the likely source to IDScan, a Louisiana-based identity verification firm used by major consumer brands to check tens of millions of IDs monthly. Both researchers confirmed their own personal documents appeared in the database, and Defense Secretary Pete Hegseth's photo was also reportedly found among the listings.

Hackers dump 8.7 million records stolen from Manchester Airports Group

A criminal hacking group has published personal data belonging to nearly 8.7 million customers of Manchester, London Stansted and East Midlands airports after breaching Manchester Airports Group's systems. The attackers had demanded a ransom, which MAG did not pay, and have now released roughly half a terabyte of stolen information—including contact details, vehicle registrations and postcodes—free of charge to other criminals via their own website.

Aesto Health breach exposes data of 9.5 million patients across 29 providers

Aesto LLC, which runs Aesto Health's data migration and archiving service for healthcare providers, revealed that an unauthorized actor accessed its AWS infrastructure between December 2 and 18, 2025. The breach, confirmed internally on May 26 after forensic review, exposed sensitive records for over 9.5 million people including Social Security numbers, driver's license numbers, and medical information tied to 29 healthcare clients such as VillageMD and Together Women's Health.

Dropbox accounts hijacked via flawed Lenovo single sign-on integration

Dropbox notified users that attackers gained unauthorized access to their accounts between August 4 and 21, 2026, though the company says no files were confirmed viewed or downloaded. The breach stemmed from a weakness in Lenovo's identity verification process, which let attackers register Lenovo IDs tied to victims' email addresses without owning those inboxes, then use those IDs to log into linked Dropbox accounts.

Novocure breach exposes data of 1,400+ cancer patients and staff

Novocure disclosed to the SEC that attackers gained unauthorized access to its systems in mid-August, exposing over 1,400 U.S. patient ID records without names attached. Fewer than 50 patients in the western U.S. had identifying information and healthcare provider contact details compromised, and an unspecified number of employees also had contact information exposed. The company says its treatment devices and operations remain unaffected and it is assessing notification obligations.

Brave adds email alias feature to mask users' real addresses at signup

Brave has rolled out a new 'email aliases' tool in its browser that lets users generate disposable email addresses which forward messages to their real inbox. Users can create up to five free aliases by verifying their main email through Brave's settings, then right-clicking any email field on a website to generate and insert an alias.

ShinyHunters claims theft of millions of patient records from McKesson's cloud systems

Pharmaceutical distributor McKesson confirmed hackers broke into several cloud-hosted accounts and stole data tied to its oncology and medical-surgical units. The ShinyHunters group told TechCrunch it used phishing and social engineering to trick employees into granting access, then pulled millions of rows of patient records from Snowflake and Salesforce environments, including names, Social Security numbers, diagnoses, medications, and employee home addresses.

FulcrumSec claims theft of 86GB from Manchester Airports Group in data breach

Extortion group FulcrumSec has claimed responsibility for a breach at Manchester Airports Group, saying it stole roughly 86GB of customer data across Manchester, London Stansted and East Midlands airports. BleepingComputer verified sample records against a real traveler's purchase history, finding detailed booking, payment and travel information beyond what MAG initially disclosed. The hackers allege they used exposed Iterable API credentials found in client-side JavaScript to access the data, including nearly 200,000 records tied to travel scheduled through 2026.

Hasbro confirms employee data breach affecting hundreds of workers

Hasbro has notified regulators that attackers gained unauthorized access to an employee account, exposing personal and financial details of staff. Massachusetts filings show at least 436 employees in that state had Social Security numbers, financial account data, card numbers, and driver's license information compromised. Hasbro says it disabled the compromised account, cut off unauthorized access, and added new safeguards, though it hasn't disclosed the full scope of the breach or when it was discovered.

ShinyHunters leaks data from 12.9 million Carhartt accounts after ransom refusal

ShinyHunters, an extortion group, published roughly 50GB of stolen Carhartt data on the dark web after the apparel maker declined to pay a $3.3 million ransom demand. Have I Been Pwned founder Troy Hunt confirmed the leak stems from a breach of Carhartt's Databricks analytics platform, exposing 12.9 million accounts containing names, emails, phone numbers, and addresses, alongside employee and corporate records.

LACMA confirms 2025 breach exposed Social Security numbers and medical records

The Los Angeles County Museum of Art disclosed that hackers accessed its network for four days before detection on July 11, 2025, compromising sensitive data belonging to customers and employees. Exposed information includes Social Security numbers, driver's license numbers, partial financial and payment card details, and health-related records such as diagnoses and treatment history. The museum only completed its investigation and began notifying affected individuals in late February 2026, more than a year after the intrusion was found.

Nutex Health discloses data breach in SEC filing

Nutex Health, a for-profit hospital operator with 28 facilities across 12 states, told the SEC that an unauthorized third party accessed and stole data from its servers, some of which may be private or confidential. The company has hired forensic investigators, notified law enforcement, and activated its incident response plan, but has not yet determined whose data—patients, employees, or partners—was affected.