Suitable AI, an AI recruitment platform serving India and the USA, was allegedly breached through GraphQL API weaknesses, leading to a partial dump of 15,176 applicant records. The exposed data reportedly included names, contact details, resumes, and salary information from a pool of about 53,681 applicants. #SuitableAI #NightBroker #GraphQLAPI…
Category: Cyber Attack
Pushpanjali Hospital in Agra was hit by a ransomware attack that locked critical data, backup files, and the hospital’s phone software on its Windows server, disrupting operations. Authorities have registered a complaint and are investigating the incident to identify the cybercriminals behind the attack. #PushpanjaliHospital #Agra #DelhiGate
The City of Carros confirmed it was the victim of a cyberattack that caused its municipal website to become unavailable. Technical teams are working to restore services, while the exact nature of the attack and whether any data was leaked have not been confirmed yet. #VilledeCarros
The municipal websites of Baraolt and Ghidfalău have been offline for several days following a cyberattack, prompting local authorities to work with maintenance companies to restore the platforms. Officials are also seeking support from the National Cyber Security Directorate, while stressing that no sensitive data is stored on the Ghidfalău platform. #Baraolt #Ghidfalău #DirectionatNaționaldeSecuritateCibernetică
A threat actor using the alias 84City claimed to leak an SQL dump attributed to PPA Business School in France, containing 293,967 records tied to students, alumni, prospects, and applicants. The alleged exposure includes names, emails, phone numbers, home addresses, dates of birth, nationality, student IDs, and enrollment details, though the…
A threat actor using the alias ChimeraZ claims to have leaked an SQL dump from the Bebeboutik seller portal, with about 500,000 rows spread across 1,890 files and totaling 1.4GB. The alleged breach is unverified, but it could expose merchant, order, inventory, pricing, and sales data from the French baby-products marketplace….
Dutch police, led by the National Public Prosecution Service and Team High Tech Crime, have launched a major investigation into the Odido hack after more than six million customer records were stolen and later leaked. Investigators say they found strong signs that Dutch criminals were involved, and they are asking anyone with information to contact the police as the case continues for months. #Odido #TeamHighTechCrime #LandelijkParket
The City of Winkler in Manitoba was affected by a cybersecurity incident that forced officials to isolate impacted systems and take some municipal services offline as a precaution. Phone and payment systems are currently unavailable, and external experts have been brought in while police have been notified. #CityofWinkler #Manitoba
Thepha District Public Health Office in Thailand was reportedly breached, with the attacker claiming a full dump of databases, files, logs, and documents. The exposed data reportedly includes site accounts, hashes, and documents, and live server access was also offered. #ThephaDistrictPublicHealthOffice #Thailand #Monkeydance…
KDDI confirmed a major data breach affecting 12.23 million email users and 7.61 million stolen passwords after hackers exploited a software vulnerability in its foundational email system. The company has patched the flaw, urged mandatory password resets, and warned users about phishing and credential-stuffing risks. #KDDI…
The Community of Communes of Pays du Mont-Blanc (CCPMB) was indirectly affected by a major cyberattack that hit its internet operator, Phibee Telecom, causing outages to its website, email addresses, and phone services. Phibee reported malicious deletion of telecom system configurations and backups, while stating that no ransomware was used. #CCPMB #PhibeeTelecom
An investigation was launched after an internal application linked to the Kerala Police website, which manages internal files, experienced a malfunction that authorities suspect may be the result of a cyberattack. The police said no data breach has been detected, while the internal file system has been offline for four days and the public website remains operational. #KeralaPolice #Keralapolice.gov.in
Since April 2026, O-UNC-066, also known as Pink, has used a panel-controlled phishing kit and vishing scheme to target Microsoft 365 passkey enrollment and trick users into authorizing a fraudulent passkey. Okta observed the activity across multiple industries, with the attackers primarily seeking data extortion, though the kit does not handle third-party federation and no direct Microsoft account compromise was observed. #O-UNC-066 #Pink #Microsoft365 #Okta
A threat actor known as derm0nix, linked to Hackero$ Crew, claims to have breached the Portal de Salud de Culiacán in Mexico and leaked 4,045 patient records for free. The alleged data includes minors’ sensitive medical information, CURP national ID numbers, and detailed medical and reproductive histories, but the claim remains…
A threat actor known as 84City allegedly posted an SQL dump tied to ESGI, a French IT school, claiming it contains 26,451 student enrollment records. The exposed data may include names, contact details, addresses, class and program information, and school Active Directory logins, but the claim remains unverified. #ESGI #84City #ActiveDirectory…