Latvijas Valsts meži (LVM) disabled external systems including LVM GEO, its map service, and the “Mednis” hunting application after a cyber incident, while also restricting internal systems used to exchange data with suppliers and customers. LVM is working with Cert.lv and national security authorities, and the national police have opened an investigation to determine the circumstances and identify the attacker. #LatvijasValstsmeži #LVMGEO #Mednis #Certlv
Category: Cyber Attack
A taxpayer database reportedly scraped from the Coahuila state government portal in Mexico was allegedly leaked after the portal’s web vulnerabilities were exploited. The exposed data is said to include names, RFC details, home and work addresses, and phone numbers. #Coahuila #CoahuilaStateGovernment #Mexico…
A listing allegedly offers 347,178 Ecuadorian facial and biometric records for sale, including national IDs, names, dates of birth, birthplaces, and fingerprint codes. The exposure is especially serious because it reportedly includes minors’ records and could enable identity theft, biometric spoofing, and long-term impersonation. #Ecuador #Albertcamus…
A database allegedly containing full Texas Parks & Wildlife records was offered for sale after a confirmed breach affecting 3,087,721 records. The listing claimed extensive PII and financial data, while some sensitive fields such as SSNs, dates of birth, and card CVVs were disputed. #TexasParksWildlife #Shadowreaper…
Plitvice Lakes National Park in Croatia was hit by a cyberattack that severely disrupted ticketing and commerce systems, affecting electronic payments across the site. Some shops and facilities were forced to close or accept only cash while security protocols were activated and specialists worked to restore operations. #PlitviceLakesNationalPark #TotalCroatia #npplitvickajezera
Route Mobile’s Colombian subsidiary, Masivian S.A.S., was hit by a cyberattack, and the affected systems were isolated while an investigation is underway. The company said Route Mobile Limited and the rest of the group were not impacted. #RouteMobile #Masivian
Stadttheater Gießen was hit by a cyberattack carried out by a group described as highly professional and global, leaving all data and backups inaccessible. Despite the disruption, performances continue as scheduled while the theater works to restore its systems over the coming months. #StadttheaterGießen
The municipal administration of Nowa Ruda was hit by a ransomware attack on 2026-06-23, which encrypted data on servers and employee computers and created a crisis situation. Sensitive personal data may have been compromised, and the incident was reported to the relevant authorities, including CSIRT NASK and the Police. #NowaRuda #CSIRTNASK
A threat actor using the alias Kazu claims to have breached Colombian health-tech platform SaludTools and stolen about 2.3 TB of EMR/EHR and practice-management records. The actor is demanding $400,000 by July 7, 2026, threatening to leak or sell the alleged data if the ransom is not paid. #SaludTools #Kazu…
A threat actor known as Kazu allegedly breached ConsultorioMovil, an Argentine telemedicine platform owned by Grupo Cormos, and claims to have stolen 1.73 TB of data. The actor is demanding $200,000 by July 7, 2026, threatening to sell sensitive telemedicine and electronic medical record data if the ransom is not paid….
Magelang City government agencies in Indonesia were reportedly linked to four data exposures between May and June 2026, with more than 100,000 records allegedly affected. The disclosed data included personal, medical, employment, and NIK information, and the posts were presented as public-awareness disclosures rather than for sale. #MagelangCityGovernment #Indonesia #NIK…
A dataset allegedly linked to Région Occitanie in France is said to contain 318,751 student records, including minors’ personal information and facial photos. The exposure may put children and families at risk of identity theft, stalking, and targeted scams, though the authenticity and scope remain unverified. #RégionOccitanie #France #xMetah…
NightBroker allegedly posted a database claimed to belong to Deliware, an Indian food delivery app, after exploiting an exposed demo administration panel. The reported leak includes user data, authentication tokens, OTPs, password-reset keys, and Stripe API keys, though the dataset’s authenticity and scope remain unverified. #Deliware #NightBroker #StripeAPIkeys…
Chelan County Clerk’s Office is recovering after a malware attack disrupted county systems for three weeks, affecting phones, email, employee computers, and servers. The office is now restoring services and clearing a backlog of about 6,000 documents, with some delays and limited access still affecting electronic filings and passport applications. #ChelanCountyClerksOffice #ChelanCounty
LastPass confirmed that customer contact and support data was exposed in a supply chain breach involving Klue, after attackers stole OAuth tokens and used them to access Salesforce records. The company says its vaults and infrastructure were not affected, while the incident also impacted other Klue customers including Recorded Future, Tanium,…