PROBABLYPWNED
DBD

Data Breach Desk

Data Breaches

The Data Breach Desk reports corporate breaches, extortion campaigns, and the underground data economy, with attention to what data was exposed and what affected people should do.

breach disclosureextortion campaignsdark web monitoringidentity protection

Articles from the Data Breach Desk(113)

Novo Nordisk Discloses Breach Exposing Clinical Trial Patient Data
Data Breaches4 min read

Novo Nordisk Discloses Breach Exposing Clinical Trial Patient Data

Pharmaceutical giant Novo Nordisk confirmed attackers copied clinical trial patient data and healthcare professional information from internal systems. The company says affected data was pseudonymized and cannot identify patients by name.

Data Breach DeskJun 14, 2026
ServiceNow API Flaw Exposed Customer Data Before Patch
Data Breaches3 min read

ServiceNow API Flaw Exposed Customer Data Before Patch

Attackers exploited an unauthenticated API endpoint to query ServiceNow customer instances. The company received a bug report in April but didn't patch until June 5—after exploitation began.

Data Breach DeskJun 11, 2026
UN Food Agency Breach Exposes 600,000 Gaza Households
Data Breaches5 min read

UN Food Agency Breach Exposes 600,000 Gaza Households

A cyberattack on the World Food Programme exposed sensitive data of 600,000 Gaza households, potentially the largest humanitarian data breach on record. 17-day notification delay raises concerns.

Data Breach DeskJun 5, 2026
ShinyHunters Claims 275M Records in Instructure Canvas Breach
Data Breaches4 min read

ShinyHunters Claims 275M Records in Instructure Canvas Breach

Educational tech giant Instructure confirms data breach affecting Canvas LMS users. ShinyHunters claims 275 million student and teacher records stolen from 9,000 schools, with a May 6 leak deadline.

Data Breach DeskMay 4, 2026
Trellix Confirms Breach of Source Code Repository
Data Breaches4 min read

Trellix Confirms Breach of Source Code Repository

Trellix, formed from McAfee Enterprise and FireEye merger, disclosed unauthorized access to source code. Forensic investigation ongoing with no evidence of code exploitation.

Data Breach DeskMay 3, 2026
ShinyHunters Hits Canada Life With 5.6M Record Breach
Data Breaches4 min read

ShinyHunters Hits Canada Life With 5.6M Record Breach

ShinyHunters claims breach of Canada Life Assurance exposing 5.6 million Salesforce records with PII. Ransom deadline passed April 21, 2026—data leak threatened.

Data Breach DeskApr 21, 2026
Vercel Breach Traced to Compromised Third-Party OAuth App
Data Breaches4 min read

Vercel Breach Traced to Compromised Third-Party OAuth App

Compromised Google Workspace OAuth app 110671459871-30f1spbu0hptbs60cb4vsmv79i7bbvqj breached Vercel, exposing API keys and source code. Hackers demand $2M; audit Workspace apps and rotate credentials.

Data Breach DeskApr 19, 2026
Booking.com Breach Exposes Guest Reservation Data
Data Breaches4 min read

Booking.com Breach Exposes Guest Reservation Data

Booking.com confirms hackers accessed customer reservation data including names, emails, phone numbers, and booking details. Company resets PINs but won't disclose breach scope.

Data Breach DeskApr 16, 2026
North Korea Behind $285M Drift Protocol Heist
Data Breaches3 min read

North Korea Behind $285M Drift Protocol Heist

Solana's Drift Protocol lost $285 million in 2026's largest DeFi hack. TRM Labs attributes the attack to North Korean actors who exploited oracle manipulation and pre-signed transactions.

Data Breach DeskApr 4, 2026
European Commission Confirms AWS Cloud Breach
Data Breaches3 min read

European Commission Confirms AWS Cloud Breach

Hackers compromised the European Commission's Amazon cloud infrastructure, claiming to steal 350GB of data including employee databases. Investigation ongoing.

Data Breach DeskMar 28, 2026
ShinyHunters Extorts Infinite Campus After Salesforce Breach
Data Breaches4 min read

ShinyHunters Extorts Infinite Campus After Salesforce Breach

K-12 student information system provider Infinite Campus discloses breach affecting school staff data. ShinyHunters issued March 25 ransom deadline after claiming to steal Salesforce records.

Data Breach DeskMar 25, 2026
Navia Benefit Solutions Breach Exposes 2.7 Million SSNs
Data Breaches3 min read

Navia Benefit Solutions Breach Exposes 2.7 Million SSNs

Workplace benefits administrator Navia discloses data breach affecting 2.7 million individuals. Social Security numbers, health plan data, and personal information stolen during December-January intrusion.

Data Breach DeskMar 23, 2026
TriZetto Breach Exposes 3.4 Million Healthcare Records
Data Breaches4 min read

TriZetto Breach Exposes 3.4 Million Healthcare Records

Cognizant subsidiary TriZetto Provider Solutions confirms breach affecting 3.4 million patients. SSNs, Medicare IDs, and health data exposed after attackers went undetected for nearly a year.

Data Breach DeskMar 10, 2026
LexisNexis Breach Exposes Government and Law Firm Data
Data Breaches4 min read

LexisNexis Breach Exposes Government and Law Firm Data

FulcrumSec threat actor exploits React2Shell vulnerability to breach LexisNexis AWS infrastructure, leaking 2GB of customer data including .gov email addresses and federal employee records.

Data Breach DeskMar 3, 2026
BreachForums Database Leaked, Exposing 324K Users
Data Breaches3 min read

BreachForums Database Leaked, Exposing 324K Users

A backup misconfiguration led to the exposure of nearly 324,000 user records from the notorious hacking forum, including usernames, hashed passwords, and IP addresses.

Data Breach DeskJan 19, 2026
17.5 Million Instagram Accounts Leaked on BreachForums
Data Breaches4 min read

17.5 Million Instagram Accounts Leaked on BreachForums

A threat actor shared Instagram user data including emails and phone numbers for free. Users report receiving suspicious password reset emails within hours of the leak.

Data Breach DeskJan 10, 2026
Hacker Selling 139GB of US Utility Engineering Data
Data Breaches5 min read

Hacker Selling 139GB of US Utility Engineering Data

Pickett USA breach exposes LiDAR scans, transmission line surveys, and substation layouts for Tampa Electric, Duke Energy Florida, and American Electric Power. Asking price: 6.5 BTC.

Data Breach DeskJan 9, 2026
European Space Agency Confirms Data Breach
Data Breaches5 min read

European Space Agency Confirms Data Breach

Threat actor '888' claims 200GB of source code, API keys, and credentials from ESA's Bitbucket and JIRA servers. Agency says only unclassified scientific systems were affected.

Data Breach DeskJan 1, 2026