breach

Trust Wallet Confirms Extension Hack Led to $7 Million Crypto Theft

Trust Wallet's Chrome extension was hacked on December 24, leading to $7 million in stolen cryptocurrency. Users reported wallet drain incidents post-update. Trust Wallet confirmed the issue and released a security patch (version 2.69) to resolve it, advising users to update immediately. A phishing campaign targeting affected users also emerged, prompting Trust Wallet to warn about compromised domains. Users should refrain from using version 2.68 and secure their funds by moving them to new wallets.

https://www.bleepingcomputer.com/news/security/trust-wallet-confirms-extension-hack-led-to-7-million-crypto-theft/

LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Finds

LastPass's 2022 data breach allowed hackers to exploit weak master passwords, facilitating cryptocurrency thefts lasting into late 2025. TRM Labs linked these activities to Russian cybercriminals using their exchanges to launder over $35 million in stolen assets. Despite attempts to mask transactions with CoinJoin techniques, evidence revealed operational patterns leading to identifications. The breach highlights the lasting vulnerabilities of poor password security, with the U.K. fining LastPass $1.6 million for inadequate protections.

https://thehackernews.com/2025/12/lastpass-2022-breach-led-to-years-long.html

Backing up Spotify

Anna's Archive has backed up Spotify, creating the largest public music preservation archive with 300TB of data. This includes metadata for 256 million tracks and 86 million music files, covering 99.6% of listens. The archive aims to preserve lesser-known music often overlooked by enthusiasts. While Spotify has a wealth of music, the focus is on retaining and making accessible all types of music, including popular and obscure tracks. The backup will be released through torrents, and the project seeks community support for seeding and donations to protect music heritage.

https://annas-archive.li/blog/backing-up-spotify.html

Major Leak Reveals One of the Largest Lead-gen Databases Ever Exposed

A major data leak exposed 4.3 billion records, including LinkedIn-derived personal information, due to an unprotected MongoDB database. Researchers discovered 16TB of data, with details like emails, employment histories, and personal profiles. The leak poses significant security risks, enabling targeted phishing and social engineering attacks, as attackers can exploit this structured and current data. The incident underscores vulnerabilities in data management practices and highlights growing threats from extensive data leaks.

https://cybernews.com/security/database-exposes-billions-records-linkedin-data/

UK Fines LastPass £1.2 Million for Data Breach Affecting 1.6 Million People

UK fines LastPass £1.2 million for 2022 data breach affecting 1.6 million users. Two attacks compromised employee data, leading to access of encrypted user information. ICO criticized LastPass for inadequate security measures. No evidence passwords unencrypted but concerns remain about hackers cracking vaults. LastPass acknowledges shortcomings, focusing on enhancing data security.

https://therecord.media/uk-fines-lastpass-over-1-million-data-breach

New ConsentFix Attack Hijacks Microsoft Accounts Via Azure CLI

ConsentFix attack hijacks Microsoft accounts via Azure CLI without passwords or MFA. It tricks users into submitting OAuth codes through a fake CAPTCHA on compromised sites, giving attackers full access to accounts using Azure authentication. Monitoring for unusual Azure CLI activity is recommended to detect this threat.

https://www.bleepingcomputer.com/news/security/new-consentfix-attack-hijacks-microsoft-accounts-via-azure-cli/

The Hidden Cascade: Why Law Firm Breaches Destroy More Than Data

Law firms face significant cyberattack risks, with 20% targeted in the past year and average breach costs exceeding $5 million. Attackers are increasingly sophisticated, using tactics that can undermine client privilege and expose sensitive data, especially relating to M&A deals. Current security assessments overlook law firms, leaving businesses vulnerable. The article advocates treating these firms like high-risk technology vendors, proposing specific security measures to mitigate risks associated with data breaches in professional services.

https://www.recordedfuture.com/blog/the-hidden-cascade

OpenAI Discloses API Customer Data Breach Via Mixpanel Vendor Hack

OpenAI reported a data breach affecting some API customers due to a Mixpanel hack, disclosing limited identifying information such as names and email addresses. No sensitive data like passwords or payment details were compromised. OpenAI has removed Mixpanel from its services and is investigating the incident, advising affected users to be cautious of potential phishing attempts.

https://www.bleepingcomputer.com/news/security/openai-discloses-api-customer-data-breach-via-mixpanel-vendor-hack/

Logitech Data Breach — What We Know As 0-Day Hack Attack Confirmed

Logitech experienced a data breach after a Clop ransomware group attack that used a zero-day flaw in a third-party platform. The attack did not directly affect Logitech’s products or business operations, but it may have exposed limited employee, consumer, and supplier data. Logitech believes sensitive personal data was not compromised and has since patched the vulnerability. The firm is working with cybersecurity experts and believes that this incident won’t materially affect its finances due to insurance coverage. Experts stress that the incident highlights the risks associated with zero-day exploits and underscores the need for stronger security measures.

https://www.forbes.com/sites/daveywinder/2025/11/15/logitech-data-breach—what-we-know-as-0-day-hack-attack-confirmed/

How Massive Data Breaches Flood Illicit Markets While Personal Information Fuels Cybercrime Economy

Massive data breaches expose sensitive personal information, fueling a cybercrime economy where stolen data is sold for illicit purposes. Criminals exploit breaches from various targets, leading to identity theft and fraud. The sheer volume of stolen data creates a market for scammers, with various vendors and platforms facilitating sales, often using cryptocurrencies for transactions. As demand grows, so do data breaches, making the issue persistent and profitable for cybercriminals.

https://www.milwaukeeindependent.com/syndicated/massive-data-breaches-flood-illicit-markets-personal-information-fuels-cybercrime-economy/

Databroker Files: Targeting the EU

Mobile phone location data of millions in the EU is being sold for advertising, posing serious privacy and security risks, including potential espionage. This data can reveal sensitive patterns of movement for EU officials, despite GDPR regulations meant to protect personal information. Investigations show that data brokers can easily target political figures, with significant implications for national security amid rising geopolitical tensions. EU leaders and NATO express concern over the situation but effective protective measures remain inadequate. Comprehensive regulation to curb data trading and enhance privacy rights is urgently needed, with calls for a ban on advertising tracking.

https://netzpolitik.org/2025/databroker-files-targeting-the-eu/

Google Disputes False Claims of Massive Gmail Data Breach

Google denies recent claims of a massive Gmail data breach affecting 183 million accounts, clarifying that compromised credentials result from various past attacks, not a new breach. The misinformation originated from misinterpretations of credential databases compiled over years. Google emphasizes strong defenses and offers advice for users concerned about past credential exposure.

https://www.bleepingcomputer.com/news/security/google-disputes-false-claims-of-massive-gmail-data-breach/

Oracle Says “obsolete Servers” Hacked, Denies Cloud Breach

Oracle confirmed hacking of “obsolete servers,” denying any impact on its cloud services or customer data. Hackers accessed and leaked user credentials from outdated infrastructure, asserting no usability of exposed passwords. Cybersecurity experts question Oracle's terminology, suggesting the breach pertains to legacy systems still managed by the company, which has not clarified server specifics. Recent breaches include compromised patient data from Oracle Health.

https://www.bleepingcomputer.com/news/security/oracle-says-obsolete-servers-hacked-denies-cloud-breach/

Scroll to Top