Ukraine's largest grocery chain ATB confirms cyberattack as extortionists demand $400,000
The DataSuckers group posted a ransom note on ATB's own website and claims to hold data on 7.9 million customers. ATB says customer data was not compromised.
The latest cybersecurity news in Data Breaches.
The DataSuckers group posted a ransom note on ATB's own website and claims to hold data on 7.9 million customers. ATB says customer data was not compromised.
Japan's Nikkei disclosed that an attacker took over an employee's Microsoft 365 account and used it to send roughly 9,000 malicious emails. The Record reports a separate Google Workspace intrusion affected 1,646 people.
Danish authorities said unauthorized parties misused a private company's legitimate access to the Central Person Register to pull names, addresses and CPR numbers for about 8.8 million people.
Fakturownia, a Polish e-invoicing service with more than 600,000 customers, says an attacker exploited a vulnerability and copied account data, password hashes, API tokens and bank details.
Edtech provider Frontline Education is notifying school districts that attackers exploited a third-party software flaw and stole employee data, including Social Security numbers.
MetaMask says a security incident hit part of its infrastructure and is exiting affected Ethereum validators in its non-custodial staking operations, while stating wallets face no immediate threat.
President Lee Jae Myung ordered a thorough investigation after a string of intrusions exposed data of more than 60,000 customers at South Korean banks and lenders.
Attackers used compromised accounts to access DTU's identity management system and download records going back to 2003, affecting up to 200,000 current and former users.
Turkey's data protection authority KVKK says malware delivered through a third-party application hit Akkoyunlar, exposing employee identity, contact and audiovisual records.
Turkey's data protection authority KVKK says a security incident at Walke's e-commerce infrastructure provider exposed customer names, emails, addresses and transaction data.
Turkey's data protection authority says a flaw in third-party software libraries let attackers reach Unigen servers holding customer data, including stored password values.
KVKK says an unauthorized party used automated requests against unauthenticated URLs to download application documents, including passport details and criminal records, of 7,591 people.