Breach updates

Every breach report in the live feed, curated and classified by what actually happened, who was hit, and how many records the reporting says were exposed. Unclassified open source only.

Every figure below is counted directly from the cited reports in this list. Nothing is estimated, and record counts are only shown when the source itself states one.

Last 24h
0
0 in 7 days
Tracked
4
in current feed window
Critical
1
severity-rated critical
Records
-
no counts stated yet
Ransomware
PRIVSEC·Incidents & Breaches·criticalCONF 57

Google Threat Intelligence Group and Mandiant document Oracle E-Business Suite zero-day extortion

Bottom line: an extortion campaign linked to the CL0P ecosystem exploited an Oracle E-Business Suite zero-day for mass data theft across dozens of customers. Enterprise resource planning platforms are now a primary mass-exploitation target, not a back-office concern.

Automated analysis from cited open sources.

#CL0P#Oracle E-Business Suite#Extortion

Source: Google Threat Intelligence Group / Mandiant · published 2025-10-09 13:00Z[1]

IntrusionTelecom
CI-COMMS·Incidents & Breaches·highCONF 61
USlow · 11US (general)

Chinese operators breach additional United States telecom networks through unpatched Cisco routers

Bottom line: reporting on the Insikt Group findings identified further carrier compromises through Cisco devices left unpatched for over a year. Asset inventory gaps on network gear, not novel exploits, are carrying this campaign.

Automated analysis from cited open sources.

Critical Infra: CommunicationsFeb 14, 2025BleepingComputer (opens in new tab) Details
#Salt Typhoon#Cisco#Carriers

Source: BleepingComputer · published 2025-02-14 12:00Z[1]

Third partyGovernmentTelecom
ADV-CN·Cyber Diplomacy & Norms·highCONF 57
USmedium · 48Treasury / OFACUS (general)

Associated Press: Treasury sanctions follow the telecom hack and the breach of its own network

Bottom line: the designations covered both the carrier campaign and an intrusion into Treasury systems through a third-party support provider. Third-party remote support tooling remains an unresolved federal exposure.

Automated analysis from cited open sources.

Adversary: China (PRC)Jan 17, 2025Associated Press (opens in new tab) Details
#Treasury#Third party access#Sanctions

Source: Associated Press · published 2025-01-17 18:00Z[1]

Ransomware
CRIME·Incidents & Breaches·highCONF 57
USlow · 8US (general)

Operation Cronos seizes LockBit infrastructure and publishes affiliate detail

Bottom line: international law enforcement took the leak site, recovered decryption keys and exposed the affiliate structure of the most active ransomware brand. Infrastructure seizure combined with public exposure now precedes arrests in United States practice.

Automated analysis from cited open sources.

Cybercrime / RansomwareFeb 20, 2024US Department of Justice (opens in new tab) Details
#LockBit#Operation Cronos#Ransomware

Source: US Department of Justice · published 2024-02-20 13:00Z[1]