Thousands of Active Leaked AWS Keys Expose Corporate Accounts
Over 9,300 AWS access keys leaked between 2022 and 2026 remain active, exposing corporate accounts to unauthorized access risks.
Category
18 published analyses.
Over 9,300 AWS access keys leaked between 2022 and 2026 remain active, exposing corporate accounts to unauthorized access risks.
Healthtech firm CareCloud disclosed a data breach impacting over 3.7 million patients, exposing sensitive healthcare information.
A threat actor is selling employee databases stolen from Microsoft Azure infrastructure of multiple Fortune 500 companies using compromised credentials, exposing sensitive account records and presenting an enterprise security risk.
The ShinyHunters group breached RingCentral in July, compromising personal data of 1.6 million user accounts.
Trezor disclosed a data breach affecting nearly 14,000 customers after a logistics partner was hacked, exposing customer information but no wallet security or funds were compromised.
LexisNexis took down several services after detecting unusual activity on servers managed by a third-party vendor, raising concerns about potential data breaches.
The North Carolina Ports Authority confirmed a cyberattack on IT systems at multiple ports causing operational delays and highlighting risks to critical infrastructure.
Healthcare software provider Unlimited Technology Systems disclosed an October 2025 breach impacting over 3.8 million individuals and sensitive healthcare data.
A Canadian individual admitted guilt in a data theft scheme targeting Snowflake cloud accounts, compromising sensitive data from at least 165 organizations and pursuing extortion.
A flaw in the COLDCARD hardware wallet's random number generator enabled theft of $88.6 million in Bitcoin, compromising wallet seed security for thousands of users.
Amgen reported a cloud data breach involving unauthorized access to patient health data and proprietary corporate information via third-party cloud systems.
The ShinyHunters extortion gang claimed responsibility for a data breach at Ernst & Young obtained through a supply-chain attack involving stolen system credentials.
Upbound Group disclosed that threat actors exploited stolen data to create $13 million in fraudulent leases on Acima's platform, illustrating data theft risks in fintech.
Abbott Laboratories is investigating unauthorized access incidents affecting Exact Sciences legacy systems and its LabCentral portal, with allegations of stolen company data linked to extortion.
Two hackers were sentenced for their 2024 attack on Transport for London, which disrupted 148 systems and forced a password reset for 27,000 employees, causing significant operational and financial impact.
Japanese telecom giant KDDI suffered a data breach affecting over 12 million people, with attackers accessing email addresses and passwords through a compromised platform used by multiple ISPs. The breach highlights significant risks in telecom infrastructure security.
Japanese ISP KDDI Corporation disclosed a data breach compromising up to 14.2 million email logins from one of its systems shared with five other ISPs. Threat actors gained unauthorized access, impacting multiple large providers.
Tata Electronics has confirmed a cyberattack impacting parts of its IT infrastructure, with hackers leaking some data. The incident highlights the ongoing risks to enterprise security from targeted attacks.