IBM’s “Cost of a Data Breach Report 2026” says AI is now a major force behind cyberattacks, with up to one-quarter of breaches linked to AI and average losses reaching $6 million per incident. The report also shows attackers using deepfakes, AI-capable malware, and reputational extortion while critical infrastructure, financial services,…
Category: Cyber Attack
Rapid City, South Dakota, reported a cyber intrusion attempt targeting a wastewater lift station, but its water and wastewater systems remained safe. The incident comes amid a national warning about attacks on internet-connected industrial controllers used by water utilities, while the city works with federal agencies. #RapidCity #PenningtonCounty
ExpoEmpleo Database Allegedly Leaked, 192,280 Uruguayan Job Seekers With National ID Numbers Exposed
A forum user named Sub21 allegedly leaked the ExpoEmpleo database, exposing 192,280 Uruguayan job seekers with DNI numbers, contact details, addresses, and social media handles. The claim is unverified, but the dataset appears to cover registrations since around 2015 and could enable identity theft and recruitment fraud. #ExpoEmpleo #Sub21 #Uruguay #DNI…
A broker is advertising access for sale to Golden Tulip Bahrain, with the listing tied to a FortiGate firewall environment and a price available on request. The post includes five interface screenshots as evidence and identifies the actor as Roiese. #GoldenTulipBahrain #FortiGate #Roiese…
Operation Cronos exposed that LockBit did not reliably delete stolen data after ransom payment, undermining the assumption that victims could buy data safety. The piece also shows how volatile outcomes, especially from groups like Icarus, Silent Ransom, and Dharma, are reshaping ransomware payments, tactics, and trust in extortion negotiations. #LockBit #OperationCronos #Icarus #SilentRansom #LunaMoth #Klue #Dharma
Mercor was reportedly breached, with biometric, PII, source code, and bucket data exposed in a one-time sale listing. The leak is said to include 211GB of database data and 939GB of code, with Resolute and Lapsus$ claiming attribution. #Mercor #Resolute #Lapsus$…
The University of Aveiro detected unauthorized access to its information systems, exposing personal and institutional data. The university is assessing the scope of the incident while urging the academic community to change passwords and strengthen security practices. #UniversityofAveiro
A forum user calling themselves cozypandas allegedly published an IPRO customer database containing 60,454 records, including names, addresses, NetSuite and Salesforce identifiers, and internal account data. The post also claimed DoJ agency accounts were included and advertised forged court orders and fraudulent emergency disclosure requests, but the leak remains unverified. #IPRO…
The Romanian National Administration of Penitentiaries (ANP) was hit by a ransomware attack on 2026-07-29, prompting an immediate response from the National Cyber Security Directorate (DNSC). Several ANP services remain temporarily offline while remediation and investigation continue, and a complaint will be filed with DIICOT. #ANP #DNSC #DIICOT
The Šumperk municipal office was the target of a cyberattack. The incident affected the city administration in Šumperk, Czech Republic. #Šumperk #MěstskýúřadŠumperk
Hiwin S.r.l. suffered a cyberattack that affected some of its information systems, prompting the company to activate its cybersecurity response procedures and bring in external experts. The impacted systems are being assessed for security before restoration from backups, and the preliminary operational impact is considered non-material.
A seller using the name 666op is allegedly offering a Shopee customer database with more than 300 million records, claiming coverage across Southeast Asia, Taiwan, and parts of Latin America. The listing is unverified, but it advertises detailed customer data that could enable highly targeted phishing and account abuse. #Shopee #666op…
A seller using the alias weykofa is allegedly offering a Planity database containing nearly 1 million French salon and spa customers, with sample records showing names, phone numbers, email addresses, and business identifiers. The claim is unverified, but the exposed data could help enable SMS-based fraud by tying each customer to…
A forum user known as 0xSec allegedly published a database linked to Lire Demain, the French education supply network of Auzou, exposing 5,974 institutional client records and 476 residential records. The leaked files could enable invoice fraud and business email compromise by revealing order references, invoice details, staff contacts, and delivery…
Krefeld Pinguine’s website was taken offline after a malware attack overnight on July 25–26, prompting the club to act quickly to prevent further damage and protect visitors. The club is now investigating the incident and working on a secure solution, while no data exfiltration has been confirmed so far. #KrefeldPinguine