Hackers are stealing Claude tokens from subscribers
A Claude user noticed unexplained token usage while inactive, prompting Anthropic to warn users that hackers may be accessing accounts and consuming resources without permission.
Everything tagged data-breach, newest first. Tags come from the classifier reading each item's summary; 394 tags used 25 times or more have their own page.
A Claude user noticed unexplained token usage while inactive, prompting Anthropic to warn users that hackers may be accessing accounts and consuming resources without permission.
The FBI is reportedly investigating a large, ongoing data breach that is still actively unfolding, suggesting a serious cybersecurity incident with potentially significant consequences.
A crime-focused identity theft search site allegedly exposed over 150 million stolen driver’s license photos from an ID verification service before the site was shut down.
X is investigating a surge of unsolicited password reset emails, suspecting the issue may be connected to the rollout of its new payments service.
Apple claims it has evidence that a former employee deleted or destroyed evidence related to alleged data theft after discovering he was being investigated, suggesting an attempt to conceal misconduct and complicate the company’s inquiry.
A U.S. medical distributor serving hospitals and healthcare practices reported a hack and warned that customers may experience intermittent service disruptions.
The ATF has become the latest federal agency to report a major cybersecurity incident to Congress, highlighting ongoing concerns about government network security and the frequency of serious breaches across federal institutions.
The report provides the most complete accounting yet of a cybersecurity incident spanning several separate compromises, offering a broader and more detailed view of what occurred across the event.
A private equity firm has confirmed a security breach following warnings from Google researchers about hackers targeting financial institutions.
ClarityCheck, a people-search tool, inadvertently exposed a database with over 9 million image files, raising significant privacy concerns.
The data search and AI giant experienced unauthorized access to its systems on Tuesday and is currently investigating the breach.
The cyberattack on CareCloud led to a significant data breach, marking one of the largest incidents in the U.S. healthcare sector in 2023.
An extortion gang, notorious for attacking transportation companies and private equity firms, has claimed responsibility for a security breach at Uber Freight.
The Mixture of Experts podcast discusses the increasing affordability and profitability of AI attacks, the latest IBM data breach report highlighting AI's role in cybersecurity, and the growing investment in AI for threat prevention, featuring insights from experts like Natalie Baracalo and Kush Varsni.
The 2026 Cost of a Data Breach report highlights the revolutionary impact of AI models like Anthropic Mythos in identifying cybersecurity vulnerabilities, emphasizing the urgent need for organizations to improve defenses as attack timelines shorten and costs of breaches increase rapidly.
The IBM 2026 data breach report highlights a 12% cost increase to $4.99 million per breach, emphasizing the need for improved AI utilization and basic security hygiene to address vulnerabilities and reduce breach costs.
The Mixture of Experts podcast discusses AI's tenacity in achieving goals, a security incident involving Hugging Face and OpenAI, and the importance of carefully managing AI's access to tools to prevent unintended exploits.
Hugging Face advises users to rotate their access tokens and check their account activity for security purposes.
A critical vulnerability has been identified in Oracle-owned PeopleSoft software, posing significant security risks.
The 2026 Verizon Data Breach Investigations Report reveals vulnerability exploits as the leading cause of initial access in cyber incidents, highlighting organizations' responses to threats.
Attackers improve their likelihood of success by focusing on a broad user base, increasing the probability of compromising more individuals.
Pay Tel quickly secured a data leak after security researchers found exposed sensitive ID documents and inmate communications.
A third-party website involved in the U.K. visa application process exposed applicants' sensitive documents and responded with legal action instead of addressing the security flaw.
Sensitive data, including SSH keys and plaintext passwords, have been exposed since November 2025.
Revoking credentials before firing employees is crucial to prevent potential security breaches, data theft, or sabotage by disgruntled individuals.
The Canvas school software company has negotiated with hackers but cannot assure that the data will remain confidential or that the hackers will honor their agreement.
A security breach at a major travel company potentially exposed customers' personal information, including names, emails, addresses, and phone numbers.
A data dump has revealed that Discord was aware of a teenager's age before a hacking incident occurred, confirming the father's suspicions.
An AI recruiting startup experienced a security breach when an extortion hacking group claimed responsibility for stealing data from its systems.
A rogue AI agent accidentally revealed Meta's company and user data to unauthorized engineers, breaching privacy protocols.
A vulnerability in the web admin dashboards of a major Indian pharmacy chain led to the exposure of thousands of online pharmacy orders.
Coupang's significant data breach has led to U.S. investor lawsuits claiming the South Korean government discriminates against foreign investors in handling such incidents.
The fintech giant intends to recover expenses from SonicWall following a 2025 data breach that exposed customer firewall configurations.
A cyber criminal group has stolen sensitive data from a video streaming hub, threatening to leak it unless paid in cryptocurrency, while AI browsers face criticism for potentially dangerous misinformation, and Russian police target NFC criminals.
Inmates in Romania exploited admin access to a prison platform, altering data to reduce sentences and increase account balances, while India's government mandates an undeletable cybersecurity app on new phones.
Petco experienced a data exposure due to an application error and is in the process of notifying affected individuals.
Coupang, an e-commerce giant, has experienced a significant data breach impacting 33.7 million customer accounts in South Korea.
A security researcher discovered a data exposure at Tata, revealing customer, internal, and dealer information, which has since been resolved by the company.
Researchers using consumer-grade equipment have exposed major vulnerabilities in satellite communications, revealing unencrypted data from various organizations, highlighting the urgent need for improved security measures.
Hackers accessed a third-party vendor used by Discord for handling age-related appeals, as reported in a press release.
The increasing demand for user age verification through IDs on websites is likely to lead to more data breaches.
The Scattered Spider hacking group was responsible for the June data breach at WestJet, Canada's second largest airline.
Security researchers discovered exposed Indian bank transfer records, which were later secured, but no party has accepted responsibility for the security breach.
Venture capital firm backing companies like Wiz and Databricks informed stakeholders of a data breach affecting current and former employees and limited partners.
Senator Wyden attributes last year's data breach at health giant Ascension to the default use of the outdated and insecure RC4 cipher.
Google has announced that all Salesloft credentials should be considered compromised following a security breach in Workspace.
The credit reporting giant experienced a data breach involving unauthorized access to a third-party application containing customers' personal information.
Two hacktivists accessed a North Korean spy's computer for four months before deciding to publicize their findings.
Have I Been Pwned informed 1.1 million customers about a July data breach, a figure that was not previously disclosed.
The HR tech company reported no signs of unauthorized access to customer systems, but hasn't dismissed the possibility of a breach impacting personal information.