September 28, 2026 · KrebsOnSecurity
U.S. Army Soldier Sentenced to Nearly 6 Years for Hacking AT&T, Verizon in Extortion Scheme

Cameron Wagenius, known online as 'Kiberphant0m,' was sentenced for stealing call records from over 100 million AT&T customers and extorting telecom firms.

September 28, 2026 · The Hacker News
Microsoft Dismantles EvilTokens, an AI-Powered Phishing Service Tied to 12,000 Compromised Inboxes

A court-authorized takedown disrupted the EvilTokens device-code phishing platform, which used AI throughout its attack chain against organizations worldwide.

September 28, 2026 · The Hacker News
Bitget Says Suspected North Korean Hackers Stole Over $350 Million in Exchange Hack

Cryptocurrency exchange Bitget says attackers linked to North Korea's TraderTraitor group breached backend wallet infrastructure to steal hundreds of millions in crypto.

September 22, 2026 · BleepingComputer
Screenshot Service Gyazo Confirms Breach Exposing 23.6 Million User Records

Gyazo, a widely used screenshot-sharing platform, took its service offline after attackers exploited a server flaw to steal tens of millions of records.

September 22, 2026 · BleepingComputer
FBI Seizes NightmareStresser, One of the Longest-Running DDoS-for-Hire Platforms

US authorities took down the NightmareStresser booter service, used since 2022 to launch hundreds of thousands of DDoS attacks worldwide.

September 22, 2026 · BleepingComputer
Joint Advisory Ties North Korean 'WaterPlum' Group to 30,000 Infected Devices and $10.7M Crypto Theft

US, Japanese, Australian, and German authorities detail how North Korea's WaterPlum hackers used fake job interviews to steal cryptocurrency worldwide.

September 17, 2026 · BleepingComputer
CISA Warns Ransomware Gangs Are Now Exploiting Critical VMware vCenter Flaw

CISA updates its exploited-vulnerabilities catalog to flag a critical VMware vCenter bug, patched in July, as now abused in ransomware attacks.

September 17, 2026 · BleepingComputer
CenterPoint Energy Confirms Breach After Attacker Claims 7.49 Million Records Stolen

Texas utility CenterPoint Energy confirms customer data was stolen after a threat actor leaked records it says were pulled from an unprotected API.

September 17, 2026 · BleepingComputer
Five Alleged Black Axe Syndicate Leaders Extradited to US on Fraud Charges

US prosecutors charge five suspected Black Axe leaders extradited from South Africa over a decade-long romance scam and money-laundering scheme.

September 7, 2026 · BleepingComputer / Netskope
Cybercriminals Use Blockchain Smart Contracts to Run ClickFix Malware Campaign Across 5,400+ Hacked Websites

Researchers found over 5,400 compromised sites serving ClickFix malware payloads hidden in BNB Smart Chain smart contracts, resisting takedown efforts.

September 7, 2026 · The Hacker News
Thomson Reuters Discloses Breach of Court Case-Management Platform, Risking Exposure of SSNs and Sealed Records

A breach at Thomson Reuters' C-Track court software may have exposed Social Security numbers and sealed case data across 11 U.S. states and Canada.

September 7, 2026 · Krebs on Security / BleepingComputer
FBI Investigates Dark-Web Sale of 153 Million U.S. and Canadian Driver's Licenses Tied to IDScan Breach

A dark-web service called Nexus advertised scans of 153M+ driver's licenses traced to identity-verification firm IDScan, prompting an FBI probe and lawsuits.

August 31, 2026 · The Hacker News
Berlin State Government Refuses Ransom After Data Theft From Administrative Network

Berlin confirmed an extortion attempt tied to an August breach of its state administrative network and said it will not pay the attackers' demand.

August 31, 2026 · Krebs on Security
Australian Police Arrest Two Alleged Members of TeamPCP Hacking Group

The Australian Federal Police arrested two Perth men accused of running the TeamPCP software supply-chain extortion operation tied to the Shai-Hulud worm.

August 31, 2026 · BleepingComputer
McKesson Discloses Data Breach Amid ShinyHunters Extortion Claim

Healthcare distributor McKesson confirms a cybersecurity incident after the ShinyHunters group claimed to have stolen roughly 284 million patient-related data records.

August 24, 2026 · BleepingComputer
Over 9,300 Leaked AWS Access Keys Found Still Active, Giving Full Control of Corporate Accounts

Truffle Security found thousands of exposed AWS keys, many years old and never rotated, still granting administrator access to company cloud accounts.

August 24, 2026 · The Hacker News / CISA
US Agencies Warn of AI-Generated Exploit Scripts Targeting Siemens S7 PLCs in Critical Infrastructure

CISA, NSA, FBI and DOE warn of an active campaign using AI-generated scripts to probe and manipulate Siemens S7 industrial controllers.

August 24, 2026 · The Hacker News / U.S. Department of Justice
TikTok and ByteDance Agree to $400 Million Settlement Over Children's Privacy Violations

DOJ settlement resolves claims TikTok let millions of children under 13 use adult accounts and collected their data without parental consent.

August 17, 2026 · BleepingComputer
Cybercriminals Arrested Over €30 Million Commerzbank Fraud Scheme

Brazilian and German police arrested suspects behind a 2023 scheme that exploited a service-provider flaw to drain Commerzbank customer accounts.

August 17, 2026 · BleepingComputer
RingCentral Data Breach Exposes Personal Information of 1.6 Million Accounts

The ShinyHunters extortion group breached cloud communications provider RingCentral in July, exposing personal data tied to 1.6 million accounts.

August 17, 2026 · BleepingComputer
Ukrainian Police Shut Down 94 Fraudulent Call Centers in Nationwide Sweep

Ukraine's National Police dismantled 94 scam call centers running investment fraud and bank-impersonation schemes, seizing cash, crypto access and gear.

August 10, 2026 · BleepingComputer
Healthcare Software Firm Unlimited Technology Systems Discloses Breach Affecting 3.8 Million Patients

A months-delayed disclosure reveals hackers accessed patient records at a healthcare billing vendor for five days in October 2025, exposing data on 3.8 million people.

August 10, 2026 · BleepingComputer
Canadian Man Pleads Guilty in Snowflake Cloud Extortion Campaign Affecting 100+ Million People

Connor Riley Moucka admitted to hacking Snowflake customer accounts and extorting victims, in a scheme US officials say affected over 100 million individuals.

August 10, 2026 · BleepingComputer
Ransom Cartel Ransomware Creator Sentenced to 16 Years in US Prison

Belarusian national Maksim Silnikau was sentenced to 16 years for building and running Ransom Cartel, which extorted at least 18 companies worldwide.

August 3, 2026 · BleepingComputer
Amazon Ties Years of npm Supply-Chain Attacks to North Korean Hacking Group

Amazon attributed a string of npm package compromises, including the widely used debug and chalk libraries, to the North Korea-linked Sapphire Sleet group.

August 3, 2026 · BleepingComputer
Coordinated Cyberattack Disrupts 30+ Minnesota Water Utilities, CISA Warns of Wider Threat

Hackers targeted exposed industrial controllers at over 30 Minnesota water systems, prompting a CISA alert on internet-facing operational technology.

August 3, 2026 · BleepingComputer
COLDCARD Hardware Wallet Flaw Linked to $88 Million Bitcoin Theft

A firmware bug in COLDCARD hardware wallets let attackers predict private keys, draining an estimated $88.6 million in Bitcoin from thousands of addresses.

July 27, 2026 · BleepingComputer
Swiss Rail Giant Stadler Rejects $12.3 Million Ransom Demand After Cyberattack

Stadler Rail says the Everest ransomware gang demanded $12.3 million after breaching a data platform it shared with a supplier, but the company refused to pay.

July 27, 2026 · BleepingComputer
South Korea Discloses Data Breach Impacting Diplomats Worldwide

Hackers spent ten months inside a South Korean diplomatic training system, stealing personal data on current and former foreign ministry staff.

July 27, 2026 · The Hacker News
Police Dismantle Kratos Phishing Kit Used to Bypass Microsoft 365 MFA

German, US, and Indonesian authorities took down the infrastructure behind the Kratos phishing-as-a-service kit and arrested its alleged operator.