A data breach is any incident where information is accessed, lost or exposed without authorisation. Here is what counts, how common they are in the UK, what they cost, and …
data breach
-
-
A maximum-severity Metabase SQL injection vulnerability was exploited in the wild before a fix existed, and Framework and Tally have both confirmed data loss.
-
A third party data breach at Thomson Reuters exposed sealed court records and Social Security numbers across 24+ courts, and the vendor took four months to disclose it.
-
Have I Been Pwned onboarded Sri Lanka CERT as its 48th free government subscriber. For UK businesses, the story is about who watches your exposed staff logins, and what they …
-
WilmerHale paid at least $18 million and Goodwin Procter around $10 million to the Luna Moth extortion group, which broke in using phone calls and fake IT visits rather than …
-
A single attacker has spent 17 months scraping Salesforce and ServiceNow customer portals worldwide, not by exploiting a flaw but by using guest user permissions exactly as they were configured.
-
Origin Energy confirmed a data breach affecting millions of customer records, but the company learned of it from a reporter’s call, not its own monitoring. Here’s what that gap means …
-
A contractor exposing CISA’s credentials on GitHub is the easy story. The nine ignored security alerts that followed reveal the failure worth fixing.
-
A US county paid roughly $1 million to a group that never encrypted a single file, exposing how far data-theft extortion has moved beyond classic ransomware.
-
ShinyHunters exploited CVE-2026-35273 for nearly two weeks before Oracle published any advisory. The flaw is serious — but the disclosure gap is the structural failure that put 100 organisations at …