Affected customers were notified directly by email, and anyone who did not receive communication was not impacted. The firm contained the issue within hours and launched a detailed investigation with external cybersecurity experts. The luxury retailer said the compromised information was obtained through a third-party provider and was limited to names, contact details, and marketing or loyalty card data. Harrods confirmed that hackers reached out to the company after stealing data linked to 430,000 customer records in September 2025. Investigators believe the attackers used stolen Salesforce credentials to gain temporary access to Kering’s systems—a tactic consistent with previous Shiny Hunters campaigns.
- The attackers – known as the Cl0p ransomware cartel – exploited a MOVEit zero-day vulnerability to gain access to the poker site’s systems.
- The investigation found that an unauthorized party may have acquired company files.
- Exposed data includes Social Security numbers, medical records, and special education information.
- This gives attackers the ability to skim card data while also controlling the infected phone remotely.
- Malicious activity reportedly began on 2 Jun, 2026, and customers submitted related bug bounty reports on 3 Jun and 4 Jun, 2026.
LexisNexis launched an investigation with external cybersecurity specialists, notified law https://darkside.ru/show/5499/ enforcement, and reviewed its security controls. LexisNexis said no financial or credit card information was affected and reported no evidence that the stolen data had been misused. The exposed information varied between affected individuals and may have included names, phone numbers, postal addresses, email addresses, Social Security numbers, driver’s license numbers, and dates of birth.
However, it http://www.angrybirds.su/gbook/guestbook.php?currpage=620 seems that the servers that were breached did not store any customer payment details. The information included files from big restaurant clients, promo codes, payment reports, and API keys. Our investigation also revealed that the threat actor downloaded private code repositories on December 27,” the company said. Even though the flaw that led to this leak was fixed in January 2022, the data is still being leaked by various threat actors.
ShinyHunters Adds EY, RingCentral, and Brinks Home to Data Leak Site
The exposed files contained AES-256-encrypted credentials and configuration data that could potentially be abused if decrypted. Attackers gained access to firewall configuration backup files stored in MySonicWall accounts, overturning earlier statements that suggested only part of the user base had been compromised. Sources familiar with the matter suggested that the attacks may be linked to Chinese threat actors, though the FBI has not yet confirmed attribution.
Commands are sent in JSON format, including recipient details, account numbers, and transfer amounts. This gives attackers the ability to skim card data while also controlling the infected phone remotely. It spreads through adult-themed websites https://falcoware.com/PrivacyPolicy.php disguised as app installers, mainly targeting users in the Czech Republic and Slovakia.
- The University of Nottingham confirmed a June 2026 data breach after ShinyHunters leaked files stolen from the university’s systems.
- The company declined to comment on the ransomware group itself or on whether other organizations were impacted.
- The extortion claim involved schematics, project details, and customer documents tied to major technology clients, including Apple, Dell, Google, and Nvidia.
- The exposed fields included names, email addresses, dates of birth, postal addresses, phone numbers, login IDs, and unique account identifiers.
- According to Orange, the attackers gained only limited access to internal systems and were able to exfiltrate outdated or low-sensitivity data.
- That’s why we want to spread the word and keep businesses in the know about what kind of companies are being hit with data breaches, so you can understand exactly how big the problem is and how you can keep your business safe in 2026.