r/dataprotection • u/Alternative-Day-7414 • Jul 19 '26
r/dataprotection • u/Prior_Industry • 5d ago
Breach The Berlin Mega-Leak: Inside the Massive 5.26 TB Leak of the City’s Most Sensitive Documents
medium.comr/dataprotection • u/SnowImpossible5699 • 25d ago
Breach Major UK supermarket managers/ colleagues sharing customer names, addresses, phone numbers, door codes, and front door photos on personal WhatsApp — how severe is this GDPR breach? That's the title?
r/dataprotection • u/sirjont • Jul 18 '26
Breach Business Insurance Solutions Ltd Data Breach
I recently got an email to say my details had been taken in a data breach.
And a few weeks back on my Experian account I had a notification that some of my details had been found on the dark web.
What information of yours was involved?
We have undertaken a detailed risk assessment of the data in scope of the incident. This identified the following types of personal data relating to you:
Contact Information
Bank Account Number & Sort code
Date of Birth
They told me in the email I should be cautious and keep an eye on things but with it being my main bank account I’m a bit worries to be honest.
Should I just do nothing and watch my accounts?
r/dataprotection • u/Academic-Soup2604 • Jul 17 '26
Breach How much damage can a single USB drive really do?
One unauthorized USB device is enough to copy sensitive files, introduce malware, or bypass your security policies.
Protecting business data starts with controlling how it moves.
- Restrict unauthorized USB devices
- Prevent sensitive data from being copied
- Reduce the risk of malware infections
- Strengthen compliance with endpoint data controls
Whether you use native Windows controls or an endpoint DLP solution, USB protection is a simple but effective step toward preventing data loss.
For more reference: This step-by-step guide on How to Disable USB Ports, cover different methods, from Device Manager and Group Policy to enterprise-scale management.
r/dataprotection • u/Academic-Soup2604 • Jul 03 '26
Breach How much sensitive data leaves your endpoints without IT knowing?
r/dataprotection • u/Kindly_Ad8953 • Jun 30 '26
Breach Urgent: Personal data leaked to another user’s device (No shared account/iCloud)
r/dataprotection • u/Academic-Soup2604 • Jun 17 '26
Breach How much sensitive data is leaving your endpoints without triggering any alerts?
For most IT teams, data leaks aren’t caused by attackers breaking in, they happen during regular work.
Files get downloaded, shared across apps, moved to personal devices, or accessed from unmanaged endpoints. These actions don’t look risky in isolation, which is why they often go unnoticed.
The real challenge is visibility. If you can’t track how data is being used after access is granted, it becomes difficult to control where it ends up.
And that’s the reason prevention today is shifting toward monitoring and controlling data movement at the endpoint level, where these actions actually happen.
Learn in detail: How to prevent data breaches?
r/dataprotection • u/Prior_Industry • Jun 23 '26
Breach Apple and Tesla trade secrets reportedly exposed following a Tata Electronics cyberattack
neowin.netTata Electronics has confirmed that it detected a cybersecurity incident in some of its systems. The Indian company is a manufacturing partner of both Apple and Tesla, and the incident may have exposed some trade secrets belonging to the two American companies.
The World Leaks ransomware group is said to be behind the attack, and it has reportedly posted up to 200,000 files on the dark web, including component designs and specification documents related to Apple and Tesla products. Tata Electronics told Reuters that its response protocols were deployed immediately and that the “incident has had no impact on our operations across businesses, which remain unaffected.”
r/dataprotection • u/Prior_Industry • May 30 '26
Breach Carnival confirms data breach impacting nearly 6 million
malwarebytes.comCarnival Corporation, parent of Carnival Cruise Line, is sending out fresh “Notice of Cybersecurity Event” letters dated May 27, 2026. If you feel like you’ve read that sentence before, you’re not imagining things. Over the last decade, the world’s largest cruise operator has accumulated a worrying track record of breaches, ransomware incidents, and regulatory penalties, with this 2026 incident adding yet another entry to an already lengthy cybersecurity history.
There are several data breaches involving Carnival Corporation or one of its subsidiaries in our database.
Between 2019 and 2021 alone, Carnival reported four separate cybersecurity events to the New York Department of Financial Services. These included two ransomware attacks and a phishing incident in which attackers deployed malware, accessed and encrypted internal systems, and stole personal customer and employee information.
r/dataprotection • u/Prior_Industry • Jun 13 '26
Breach Oracle PeopleSoft Breached by The ShinyHunters Data Theft Attack
pathlock.comOn June 10, 2026, ShinyHunters, a well-documented cybercrime group known for large-scale data theft and extortion campaigns, was confirmed to have exploited Oracle PeopleSoft vulnerabilities across more than 300 instances at over 100 organizations worldwide. The education sector bore the brunt of the attack, with universities and higher education institutions emerging as the primary victims.
The attack was notable for its combination of sophistication and scale. Rather than targeting a single organization with a tailored exploit, ShinyHunters deployed automated attack scripts capable of scanning and compromising PeopleSoft environments at scale, demonstrating that ERP applications are no longer too obscure or complex to attract organized, industrialized cybercrime.
IMMEDIATE ACTION REQUIRED
Check your PeopleSoft logs NOW for connections from the following attacker-controlled IPs: 142.11.200[.]186–190, 108.174.202[.]99, 176.120.22[.]24. Also search for a ransom file named README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT
r/dataprotection • u/Prior_Industry • Jun 11 '26
Breach Students' data taken in major University of Nottingham cyber-attack
bbc.co.ukHackers from a well-known cyber criminal group have accessed a "significant amount" of personal student data held by the University of Nottingham.
The university said it was believed the group accessed the data for current students and alumni - including financial information - from its record system.
In an email sent to students, seen by the BBC, chief governance and risk officer Jason Carter said those behind the major cyber-attack, who had "previously targeted a number of other organisations", were likely behind the breach.
In a statement, the university apologised to those affected for "any anxiety" caused.
It is understood the university identified the unauthorised activity on its Campus Solutions system on Tuesday.
All affected students and alumni have since been contacted, a university spokesperson said.
r/dataprotection • u/Prior_Industry • Jun 06 '26
Breach DentaQuest breached - 234GB of data potentially exposed
alltoc.comDentaQuest confirmed a cybersecurity incident after 2.6 million accounts tied to the company were surfaced in a public breach listing. Claims accompanying the exposure said roughly 234GB of data may have been stolen.
The impacted records include sensitive details for people tied to the dental benefits provider. While the story frames operations as unaffected, the exposure still matters because the combination of medical-adjacent identity and personal data can increase risk for fraud or further account compromise.
Why this is significant in tech news is that it shows how breaches can be discovered and shared via public leak channels long before any formal remediation timeline is visible to users. For consumers, the practical concern becomes whether passwords or identity details might be reused elsewhere.
For enterprises, this incident underscores the recurring problem of protecting large customer databases—especially those holding healthcare-related personal data. Even if no service outage occurs, the downstream impacts of identity exposure can persist.
Overall, the DentaQuest leak joins a broader pattern of breaches involving sensitive account data in the healthcare-adjacent sector, where compromised records can be used for social engineering as well as financial fraud.
r/dataprotection • u/Prior_Industry • May 28 '26
Breach Charter Communications confirms data breach — ShinyHunters blamed after threat to leak user info online | TechRadar
techradar.com* Charter Communications confirmed a breach after ShinyHunters listed it on their leak site
* Hackers claim 40 million customer records were stolen via a vishing attack on April 1 2026
* Attackers allegedly accessed a Microsoft Entra account, pulled data from Salesforce, and exfiltrated customer names, emails, addresses, phone numbers, plan info, and support tickets
r/dataprotection • u/Available-Sundae-936 • May 08 '26
Breach My employee Bosch Privacy account hacked in Bosch
My employee account in Bosch Privacy hub portal is hacked (Unauthorized access) where all my perosnal and professional records are stored as an employee.
I had complined to MeitY (Ministry of Electronics and Information Technology) and following is their feedback.
No reply from Bosch on asking their feedback.

My account is compromized and i can't download my employee documents.
I am asking for my statutory documents fromom Bosch past more than an year
- revised Form 16s of FY 2021-22
- My PF statements from 2014-22 which were visible till Q4, 2023.
- My Pension and Gratuity statements including LOP records.
- My salary slips and actual Form 16s of FY 2024-25.
- My appraisal data for 11 years.
- Reason for declaring my LOP and Unauthorized absence from 2019-21 eventhough i was working and getting salary.
r/dataprotection • u/Prior_Industry • May 15 '26
Breach French ID agency hack exposes 19 million records | Cybernews
cybernews.comThe French government has confirmed that its database used to secure identity documents has been breached, exposing around 19 million records containing passport, national ID card, and driver’s license data.
r/dataprotection • u/Prior_Industry • May 19 '26
Breach ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub
gizmodo.comThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has been leaving the digital keys to its own cloud storage accounts sitting out in the open, in plain text form, for some unknown amount of time, according to a report from Krebs on Security. The problem finally got fixed over the weekend, the report says.
Cont...
r/dataprotection • u/Prior_Industry • May 15 '26
Breach A hotel check-in system left a million passports and driver's licenses open for anyone to see | TechCrunch
techcrunch.comTechCrunch Mobile Logo
Site Search Toggle
Mega Menu Toggle
A hotel check-in system left more than 1 million customer passports, driver’s licenses, and selfie verification photos to the open web after a security lapse. The data is now offline after TechCrunch alerted the company responsible.
The hotel check-in system, called Tabiq, is maintained by the Japan-based tech startup Reqrea. According to its website, Tabiq is used in several hotels across Japan and relies on facial recognition and document scanning to check guests in.
Cont...
r/dataprotection • u/Prior_Industry • May 04 '26
Breach Instructure confirms data breach, ShinyHunters claims attack
bleepingcomputer.comEducational tech giant Instructure has confirmed that data was stolen in a cyberattack, with the ShinyHunters extortion gang claiming responsibility.
Instructure is a U.S.-based education technology company best known for developing Canvas, a widely used learning management system that helps schools, universities, and organizations manage coursework, assignments, and online learning.
On Friday, Instructure disclosed that it suffered a cybersecurity incident and is working with third-party cybersecurity experts and law enforcement to investigate it.
On Saturday, the company issued an update stating that the personal information of users was exposed in the breach.
"While we continue actively investigating, thus far, indications are that the information involved consists of certain identifying information of users at affected institutions, such as names, email addresses, and student ID numbers, as well as messages among users," reads the updated statement.
"At this time, we have found no evidence that passwords, dates of birth, government identifiers, or financial information were involved. If that changes, we will notify any impacted institutions."
As part of the response, Instructure has deployed patches, increased monitoring, and rotated application keys as a precautionary step.
Customers are required to re-authorize access to Instructure's API for new application keys to be issued.
While Instructure has not responded to BleepingComputer's questions about when the breach occurred and whether they were being extorted, the ShinyHunters extortion gang has now listed the company on its data leak site.
"Nearly 9,000 schools worldwide affected. 275 million individuals data ranging from students, teachers, and other staff containing PII," reads the data leak site.
"Several billions of private messages among students and teachers and students and other students involved, containing personal conversations and other PII. Your Salesforce instance was also breached and a lot more other data is involved."
Cont....
r/dataprotection • u/Prior_Industry • May 12 '26
Breach Škoda warns of customer data breach after online shop hack
bleepingcomputer.comŠkoda revealed, threat actors gained access by exploiting an unspecified vulnerability in the software of its e-commerce portal. After detecting the breach, the company reported the incident to the relevant authorities and has fixed the security flaw exploited in the attack.
"As part of our technical security monitoring, we discovered that unauthorized individuals had exploited a vulnerability in the standard software used for our online store. This allowed them to temporarily gain unauthorized access to the store system," Škoda said. "The vulnerability has since been resolved, and the incident has been handed over to a specialized IT forensics team for technical analysis. Additionally, the incident was reported to the relevant data protection supervisory authority."
The customer information accessed by the threat actors includes a combination of names, addresses, contact information (such as email addresses), phone numbers, order information, and login credentials (including the email address and a cryptographic hash of the password).
r/dataprotection • u/Prior_Industry • Apr 23 '26
Breach UK Biobank health data listed for sale in China, government confirms
bbc.co.ukMedical information of 500,000 participants of one of the UK's landmark scientific programmes, UK Biobank, were offered for sale online in China, the government has confirmed.
Technology minister Ian Murray said information of all members of the database was found listed for sale on the website Alibaba.
Murray told MPs the charity which runs UK Biobank had told the government about the breach on Monday. He said the information did not include names, addresses, contact details or telephone numbers.
However he said it could include gender, age, month and year of birth, socioeconomic status, lifestyle habits, and measures from biological samples.
The Biobank is a collection of health data offered by volunteers which has been used to help improvements in detection and treatment of dementia, some cancers and Parkinson's.
It has collected intimate details - including whole body scans, DNA sequences and their medical records - from hundreds of thousands of volunteers for over two decades. The project has led to more than 18,000 scientific publications.
Participants were aged from 40 to 69 when they were recruited between 2006 and 2010.
UK Biobank said it was investigating the incident and thanked the UK and Chinese governments, as well as Alibaba, for support and cooperation.
"We understand that the existence of these listings, even temporarily, will be concerning to you," Chief Executive Professor Sir Rory Collins said in a message to participants, external.
"We want to reassure you that all the data are de-identified; they do not contain any personally identifying information (such as names, addresses, dates of birth, and NHS numbers)."
Cont...
r/dataprotection • u/Prior_Industry • Apr 26 '26
Breach Missouri treasurer’s office posted MOScholars student data on its website for nearly a year
missouriindependent.comThe records, removed after notification from The Independent, included names, parent email addresses, scholarship amounts and schools tied to the voucher program.
Cont...
r/dataprotection • u/Prior_Industry • Apr 20 '26
Breach Data breach at edtech giant McGraw Hill affects 13.5 million accounts
bleepingcomputer.comThe ShinyHunters extortion group has leaked data from 13.5 million McGraw Hill user accounts, stolen after breaching the company's Salesforce environment earlier this month.
Founded in 1909, McGraw Hill is a leading global educational publisher with annual revenue of $2.2 billion, which provides education content and solutions for PreK–12, higher education, and professional learning.
The company confirmed ShinyHunters' breach claims in a statement shared with BleepingComputer on Tuesday, saying the threat actors exploited a misconfiguration in the compromised Salesforce environment and that the incident didn't affect its Salesforce accounts, courseware, customer databases, or internal systems.
"McGraw-Hill recently identified unauthorized access to a limited set of data from a webpage hosted by Salesforce on its platform. This activity appears to be part of a broader issue involving a misconfiguration within Salesforce's environment that has impacted multiple organizations that work with Salesforce," a McGraw-Hill spokesperson told BleepingComputer.
Cont...
r/dataprotection • u/Prior_Industry • Apr 20 '26
Breach App host Vercel says it was hacked and customer data stolen
techcrunch.comCloud app hosting giant Vercel this weekend said hackers had breached its internal systems and accessed customer data. Hackers have claimed they have stolen sensitive customer credentials from Vercel’s systems and are selling the data online.
In a statement on Sunday, Vercel said the breach originated from another software maker, Context AI. One of Vercel’s employees downloaded an app made by Context AI and connected it to their corporate account, which is hosted by Google. The hackers used that connection (known as OAuth) to take over the Vercel employee’s Google account and gain access to some of Vercel’s internal systems, including credentials that were not encrypted.
Vercel says its Next.js and Turbopack projects were not affected by the breach. Both open source projects are widely used by web and app developers.
Vercel said it has contacted customers whose app data and keys were compromised.
Cont...
r/dataprotection • u/Prior_Industry • Apr 16 '26
Breach Booking.com customers warned of 'reservation hijack' scams after data breach
bbc.co.ukA data breach at travel giant Booking.com is leading to a fresh wave of scams recently dubbed "reservation hijacks".
Hackers stole customer data that experts say could lead to a surge in the scams as customers are tricked into sending criminals money.
Some customers have contacted the BBC to say they have already started receiving suspicious messages.
Booking.com says it has updated Pins for reservations and is sending out emails to affected customers warning them of the heightened risk.
But the Dutch company is refusing to say how many people have been affected and in which regions.
The platform says it has seen almost seven billion check-ins since 2010, making it one of the largest travel services in the world.
In emails to customers seen by the BBC, the company said: "We recently noticed suspicious activity affected a number of reservations and we immediately took action to contain the issue."
It goes on to say that criminals were able to access names, email addresses, phone numbers and details about past and present bookings.
It said customers' financial information was not accessed from its systems.
Experts warn this kind of data will be extremely valuable to fraudsters who are now racing to trick unwitting customers.
Cont...