SMSA Express is reportedly facing a data exposure claim involving 124.7 million shipment records, including sender and recipient details, commodity descriptions, and declared values. If true, the leaked data could enable highly convincing parcel delivery fraud and reveal private purchasing behavior and relationships between senders and recipients. #SMSAExpress #ShipmentRecords #ParcelFraud…
Category: Cyber Attack
Podomoro University Allegedly Breached, 75 Databases and Full Website Source Code Offered for $7,000
A seller using the name LordVoldemort claims to be offering a full compromise of Podomoro University in Indonesia, including 75 databases and the university’s website source code, for $7,000 in cryptocurrency. The alleged data spans academic, financial, HR, and IT systems, but the claim remains unverified. #PodomoroUniversity #LordVoldemort…
A forum post claims BENY New Energy suffered a breach that exposed user records and screenshots of a live database session. The more serious concern is possible visibility into EV charging management, firmware management, and device monitoring platforms tied to BENY’s grid-connected products. #BENYNewEnergy #OCPP…
IJsstadion Thialf in Heerenveen was targeted in a ransomware attack attributed to The Gentlemen, who claimed to have stolen internal documents, employee data, and financial contracts. The venue said the impact was minimal and that investigations confirmed its operations and data were not affected or put at risk. #TheGentlemen #IJsstadionThialf
Zoner, a Finnish web services provider, suffered a security breach that disrupted websites and email accounts for about 1,800 of its 58,000 customers. The company took affected servers offline, is restoring backups, and has found no signs of mass data copying or customer data loss. #Zoner #Finland
Brinks Home reported a cyberattack that led to unauthorized access to its systems and an implied extortion attempt, with attackers threatening to leak stolen information. The company activated its response plans, conducted a forensic investigation that did not confirm any compromise, and advised customers to remain vigilant. #BrinksHome
Kootenai County, Idaho disclosed a March data breach four months later, revealing that hackers accessed Social Security numbers, fingerprints, and private medical and financial information. The county says it shut down the intrusion quickly, refused to pay the ransom, and is offering affected residents one year of credit monitoring. #KootenaiCounty #BruceMattare
A forum user named riche allegedly posted a scraped B9/Bnine.com dataset containing about 36,000 records with sensitive personal and financial details, including partial SSNs and dates of birth. The claim is unverified, but the reported data could enable identity theft and targeted fraud against B9 customers. #B9 #Bnine.com #riche…
A threat actor using the alias konata_izumi_shell claims to have leaked Bolivia’s Ministry of Health and Sports SSSRO database, exposing 41,406 SQL records tied to rural health interns. The alleged dump includes highly sensitive personal, academic, and location data, but the claim remains unverified. #Bolivia #MinistryofHealthandSports #SSSRO #konata_izumi_shell…
A forum user known as 888 allegedly published a PokemonGym.nl database containing about 19,600 player accounts, with usernames, email addresses, IP data, and Argon2id password hashes. The post also claims to include full private messages from the Dutch online Pokémon RPG, but the breach remains unverified. #PokemonGymnl #888 #Argon2id…
Cisco Talos discovered msaRAT, a new Rust-based remote access trojan used by the Chaos ransomware group, which hides its command-and-control traffic by abusing Chrome DevTools Protocol and WebRTC through a browser process. The malware uses Cloudflare Workers for signaling and Twilio TURN for relayed communications, making its network activity difficult to trace and blending it into normal browser traffic. #msaRAT #Chaos #CloudflareWorkers #TwilioTURN #ChromeDevToolsProtocol
This advisory describes an active Cl0p ransomware affiliate campaign targeting internet-exposed PTC Windchill and FlexPLM systems by chaining a FlexPLM WSDL information disclosure flaw with a Windchill login servlet vulnerability to gain unauthenticated remote code execution. It also details post-exploitation webshell deployment, data theft, and extortion emails sent to affected organizations across Manufacturing, Automotive, Aerospace, and Retail/Apparel sectors. #Cl0p #PTCWindchill #FlexPLM #CVE-2026-12569
RevolutionParts.com was allegedly targeted in a data leak involving 5,147,231 unique customer records, with the listing posted for free. The exposed data reportedly includes customer PII and device identifiers, and the actor named in the post is kitta. #RevolutionParts #kitta…
A forum user named kitta allegedly leaked the Bebunk.com database, claiming it exposed 12,324 banking customers across France and New Caledonia. The sample reportedly includes IBANs, KYC records, account balances, and tokens, creating a high-risk exposure for potential fraud and account abuse. #Bebunk #kitta #IBAN #KYC #Bebunk.com…
Get Nice Holdings, a Hong Kong-listed financial services company, was hit by a cyberattack on July 19 that temporarily disrupted electronic trading systems and share withdrawal services. The securities unit resumed operations the same day, while the futures unit remained offline as the company investigated the incident with a cybersecurity firm and notified Hong Kong authorities. #GetNiceHoldings #HongKong