<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>UINAT — Breach Reports</title><description>Detailed cybersecurity breach reports and incident analysis.</description><link>https://uinat.com/</link><item><title>Moltbook AI Social Network Database Exposure</title><link>https://uinat.com/breaches/moltbook-database-exposure-2026/</link><guid isPermaLink="true">https://uinat.com/breaches/moltbook-database-exposure-2026/</guid><description>A misconfigured Supabase database at Moltbook, the &apos;social network for AI agents,&apos; exposed 1.5 million API tokens, 35,000 email addresses, and private messages—revealing the platform was mostly humans operating bot fleets.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Ascension Health — Black Basta Ransomware Disrupts 100+ Hospitals</title><link>https://uinat.com/breaches/ascension-health-ransomware-2024/</link><guid isPermaLink="true">https://uinat.com/breaches/ascension-health-ransomware-2024/</guid><description>A Black Basta ransomware attack on Ascension Health, one of the largest US Catholic healthcare systems, forced hospitals to divert emergency patients, delay surgeries, and revert to paper records, affecting 5.6 million patients.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Evolve Bank &amp; Trust — LockBit Ransomware Exposes 7.6 Million via Fintech Partners</title><link>https://uinat.com/breaches/evolve-bank-lockbit-ransomware-2024/</link><guid isPermaLink="true">https://uinat.com/breaches/evolve-bank-lockbit-ransomware-2024/</guid><description>A LockBit ransomware attack on Evolve Bank &amp; Trust, a banking-as-a-service provider for major fintechs, exposed data of 7.6 million individuals and rippled through partners including Affirm, Mercury, Wise, and others.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Hot Topic — 57 Million Customer Records Exposed in Snowflake Credential Breach</title><link>https://uinat.com/breaches/hot-topic-snowflake-breach-2024/</link><guid isPermaLink="true">https://uinat.com/breaches/hot-topic-snowflake-breach-2024/</guid><description>One of the largest retail data breaches in history exposed 57 million Hot Topic, Torrid, and BoxLunch customer records including 25 million credit card numbers after attackers compromised Snowflake cloud credentials stolen via infostealer malware.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Kaiser Foundation Health Plan — 13.4 Million Members Exposed via Web Tracking</title><link>https://uinat.com/breaches/kaiser-foundation-data-exposure-2024/</link><guid isPermaLink="true">https://uinat.com/breaches/kaiser-foundation-data-exposure-2024/</guid><description>Kaiser Foundation Health Plan disclosed that web tracking technologies including Google Analytics shared personal health information of 13.4 million current and former members with third-party advertisers, the second-largest healthcare breach of 2024.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate></item><item><title>MoneyGram — Social Engineering Attack Causes Global Service Outage</title><link>https://uinat.com/breaches/moneygram-social-engineering-2024/</link><guid isPermaLink="true">https://uinat.com/breaches/moneygram-social-engineering-2024/</guid><description>A social engineering attack targeting MoneyGram&apos;s IT helpdesk led to a week-long global outage affecting billions in remittances and exposed sensitive customer data including government IDs and bank account information.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate></item><item><title>SK Telecom — 25 Million Subscribers Exposed in South Korea&apos;s Worst Telecom Breach</title><link>https://uinat.com/breaches/sk-telecom-usim-breach-2025/</link><guid isPermaLink="true">https://uinat.com/breaches/sk-telecom-usim-breach-2025/</guid><description>A sophisticated malware attack on South Korea&apos;s largest mobile carrier compromised USIM authentication data for nearly the entire subscriber base, forcing mass SIM replacements and costing over $120 million.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Panera Bread Data Breach</title><link>https://uinat.com/breaches/panera-bread-shinyhunters-breach-2026/</link><guid isPermaLink="true">https://uinat.com/breaches/panera-bread-shinyhunters-breach-2026/</guid><description>ShinyHunters breached Panera Bread via Microsoft Entra SSO vishing attack, leaking 5.1 million customer records including names, emails, phone numbers, and addresses after the company refused extortion demands.</description><pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Malicious VS Code Extensions Steal Code from 1.5 Million Developers</title><link>https://uinat.com/breaches/vscode-malicious-extensions-china-2026/</link><guid isPermaLink="true">https://uinat.com/breaches/vscode-malicious-extensions-china-2026/</guid><description>Two VS Code extensions masquerading as AI coding assistants—ChatMoss and ChatGPT中文版—exfiltrated source code, API keys, and proprietary algorithms from 1.5 million developers to servers in China.</description><pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate></item><item><title>eScan Antivirus Supply Chain Compromise — Trojanized Update Distributed</title><link>https://uinat.com/breaches/escan-supply-chain-compromise-2026/</link><guid isPermaLink="true">https://uinat.com/breaches/escan-supply-chain-compromise-2026/</guid><description>Attackers breached an eScan regional update server and distributed signed malicious updates with backdoor capabilities during a two-hour window on January 20.</description><pubDate>Thu, 29 Jan 2026 00:00:00 GMT</pubDate></item><item><title>Match Group Data Breach — ShinyHunters Leaks 10M Records from Dating Platforms</title><link>https://uinat.com/breaches/match-group-shinyhunters-breach-2026/</link><guid isPermaLink="true">https://uinat.com/breaches/match-group-shinyhunters-breach-2026/</guid><description>ShinyHunters breached Match Group via a third-party analytics provider, exposing 10 million records from Tinder, Hinge, OkCupid, and Match.com.</description><pubDate>Thu, 29 Jan 2026 00:00:00 GMT</pubDate></item><item><title>SoundCloud Data Breach</title><link>https://uinat.com/breaches/soundcloud-data-breach-2026/</link><guid isPermaLink="true">https://uinat.com/breaches/soundcloud-data-breach-2026/</guid><description>ShinyHunters breached SoundCloud&apos;s internal systems and leaked 29.8 million user records after the company refused extortion demands, exposing email addresses linked to public profile data.</description><pubDate>Wed, 28 Jan 2026 00:00:00 GMT</pubDate></item><item><title>AZ Monica Hospital — Ransomware Attack Disrupts Patient Care Across Belgian Healthcare</title><link>https://uinat.com/breaches/az-monica-hospital-ransomware-2026/</link><guid isPermaLink="true">https://uinat.com/breaches/az-monica-hospital-ransomware-2026/</guid><description>A ransomware attack on AZ Monica hospital in Antwerp forced cancellation of 70+ surgeries, patient transfers, and revealed a broader breach affecting five Belgian hospitals through a shared software supplier.</description><pubDate>Wed, 14 Jan 2026 00:00:00 GMT</pubDate></item><item><title>Blue Shield of California — Google Analytics Misconfiguration Exposes 4.7 Million Members</title><link>https://uinat.com/breaches/blue-shield-california-google-analytics-2025/</link><guid isPermaLink="true">https://uinat.com/breaches/blue-shield-california-google-analytics-2025/</guid><description>Blue Shield of California disclosed that a Google Analytics misconfiguration shared protected health information of 4.7 million members with Google Ads over nearly three years.</description><pubDate>Mon, 05 Jan 2026 00:00:00 GMT</pubDate></item><item><title>Sedgwick Government Solutions — TridentLocker Ransomware Breach</title><link>https://uinat.com/breaches/sedgwick-tridentlocker-ransomware-2026/</link><guid isPermaLink="true">https://uinat.com/breaches/sedgwick-tridentlocker-ransomware-2026/</guid><description>The TridentLocker ransomware group breached Sedgwick Government Solutions, a federal contractor subsidiary providing claims management to DHS, ICE, and CISA, exfiltrating 3.39 GB of data.</description><pubDate>Sun, 04 Jan 2026 00:00:00 GMT</pubDate></item><item><title>European Space Agency — Hackers Claim 200 GB of Source Code and Credentials</title><link>https://uinat.com/breaches/european-space-agency-breach-2025/</link><guid isPermaLink="true">https://uinat.com/breaches/european-space-agency-breach-2025/</guid><description>A threat actor breached ESA&apos;s external Bitbucket and Jira servers, claiming 200 GB of source code, API tokens, credentials, and confidential mission documents. A second breach followed within weeks.</description><pubDate>Tue, 30 Dec 2025 00:00:00 GMT</pubDate></item><item><title>Change Healthcare — ALPHV/BlackCat Ransomware Disrupts US Healthcare System</title><link>https://uinat.com/breaches/change-healthcare-ransomware-2024/</link><guid isPermaLink="true">https://uinat.com/breaches/change-healthcare-ransomware-2024/</guid><description>The ALPHV/BlackCat ransomware attack on Change Healthcare caused the most significant disruption to the US healthcare system from a cyberattack, affecting claims processing for months and exposing data of approximately 100 million individuals.</description><pubDate>Mon, 15 Dec 2025 00:00:00 GMT</pubDate></item><item><title>Snowflake Customer Data Theft Campaign — 165+ Organizations Compromised</title><link>https://uinat.com/breaches/snowflake-customer-data-theft-2024/</link><guid isPermaLink="true">https://uinat.com/breaches/snowflake-customer-data-theft-2024/</guid><description>A credential theft campaign targeting Snowflake customer accounts without MFA resulted in data theft from over 165 organizations including Ticketmaster, AT&amp;T, Santander, and Advance Auto Parts.</description><pubDate>Thu, 20 Nov 2025 00:00:00 GMT</pubDate></item><item><title>Salt Typhoon — Chinese State-Sponsored Espionage Infiltrates US Telecommunications</title><link>https://uinat.com/breaches/salt-typhoon-telecom-espionage-2024/</link><guid isPermaLink="true">https://uinat.com/breaches/salt-typhoon-telecom-espionage-2024/</guid><description>The Salt Typhoon campaign by Chinese state-sponsored actors compromised major US telecom providers including AT&amp;T, Verizon, and T-Mobile, accessing lawful intercept systems and call metadata in what officials called the worst telecom hack in US history.</description><pubDate>Wed, 15 Oct 2025 00:00:00 GMT</pubDate></item><item><title>Synnovis/NHS — Qilin Ransomware Disrupts London Hospital Blood Services</title><link>https://uinat.com/breaches/synnovis-nhs-ransomware-2024/</link><guid isPermaLink="true">https://uinat.com/breaches/synnovis-nhs-ransomware-2024/</guid><description>A Qilin ransomware attack on pathology provider Synnovis disrupted blood testing and transfusion services across major London NHS hospitals for months, forcing cancellation of thousands of operations and appointments.</description><pubDate>Wed, 01 Oct 2025 00:00:00 GMT</pubDate></item><item><title>National Public Data — 2.9 Billion Records Exposed, Company Files Bankruptcy</title><link>https://uinat.com/breaches/national-public-data-breach-2024/</link><guid isPermaLink="true">https://uinat.com/breaches/national-public-data-breach-2024/</guid><description>Data broker National Public Data suffered a massive breach exposing 2.9 billion records including Social Security numbers, leading to class-action lawsuits and the company&apos;s bankruptcy filing.</description><pubDate>Wed, 10 Sep 2025 00:00:00 GMT</pubDate></item><item><title>AT&amp;T — Call and Text Records of Nearly All Wireless Customers Stolen</title><link>https://uinat.com/breaches/att-call-records-breach-2024/</link><guid isPermaLink="true">https://uinat.com/breaches/att-call-records-breach-2024/</guid><description>AT&amp;T disclosed that hackers stole call and text metadata for nearly all of its wireless customers — approximately 110 million people — from a Snowflake cloud environment.</description><pubDate>Mon, 01 Sep 2025 00:00:00 GMT</pubDate></item><item><title>MOVEit Transfer — Cl0p Mass Exploitation Affects 2,700+ Organizations</title><link>https://uinat.com/breaches/moveit-clop-mass-exploitation-2023/</link><guid isPermaLink="true">https://uinat.com/breaches/moveit-clop-mass-exploitation-2023/</guid><description>The Cl0p ransomware group exploited a zero-day vulnerability in Progress Software&apos;s MOVEit Transfer, compromising over 2,700 organizations and exposing data of 95+ million individuals in one of the largest mass exploitation events ever.</description><pubDate>Wed, 20 Aug 2025 00:00:00 GMT</pubDate></item><item><title>Ticketmaster/Live Nation — 560 Million Customer Records Stolen</title><link>https://uinat.com/breaches/ticketmaster-live-nation-breach-2024/</link><guid isPermaLink="true">https://uinat.com/breaches/ticketmaster-live-nation-breach-2024/</guid><description>Hackers stole personal and payment data of approximately 560 million Ticketmaster customers from a Snowflake cloud environment, in one of the largest consumer data breaches of 2024.</description><pubDate>Fri, 15 Aug 2025 00:00:00 GMT</pubDate></item><item><title>Dell Technologies — 49 Million Customer Records Stolen via API Abuse</title><link>https://uinat.com/breaches/dell-customer-data-breach-2024/</link><guid isPermaLink="true">https://uinat.com/breaches/dell-customer-data-breach-2024/</guid><description>A threat actor scraped 49 million Dell customer purchase records by abusing a partner portal API, exposing names, addresses, and hardware purchase details.</description><pubDate>Fri, 01 Aug 2025 00:00:00 GMT</pubDate></item><item><title>Allianz Life — Salesforce Data Breach Exposes 1.5 Million Records</title><link>https://uinat.com/breaches/allianz-life-salesforce-breach-2025/</link><guid isPermaLink="true">https://uinat.com/breaches/allianz-life-salesforce-breach-2025/</guid><description>Threat actors from the Scattered Spider and ShinyHunters groups breached Allianz Life&apos;s Salesforce CRM through social engineering, exposing personal data including Social Security numbers of 1.5 million customers and financial professionals.</description><pubDate>Thu, 17 Jul 2025 00:00:00 GMT</pubDate></item><item><title>Cencora — Pharmaceutical Giant&apos;s Breach Exposes Patient Health Data</title><link>https://uinat.com/breaches/cencora-pharmaceutical-breach-2024/</link><guid isPermaLink="true">https://uinat.com/breaches/cencora-pharmaceutical-breach-2024/</guid><description>Cencora (formerly AmerisourceBergen), one of the world&apos;s largest pharmaceutical distributors, suffered a data breach exposing patient personal and health information from its specialty pharmacy and patient services programs.</description><pubDate>Tue, 15 Jul 2025 00:00:00 GMT</pubDate></item><item><title>Marks &amp; Spencer Ransomware Attack</title><link>https://uinat.com/breaches/marks-spencer-dragonforce-ransomware-2025/</link><guid isPermaLink="true">https://uinat.com/breaches/marks-spencer-dragonforce-ransomware-2025/</guid><description>Scattered Spider social-engineered a service desk password reset to breach M&amp;S, deploying DragonForce ransomware that encrypted VMware infrastructure, halted online sales for 46 days, and caused £300 million in lost profit.</description><pubDate>Thu, 24 Apr 2025 00:00:00 GMT</pubDate></item><item><title>Yale New Haven Health System Data Breach</title><link>https://uinat.com/breaches/yale-new-haven-health-breach-2025/</link><guid isPermaLink="true">https://uinat.com/breaches/yale-new-haven-health-breach-2025/</guid><description>Hackers breached Yale New Haven Health&apos;s network, stealing personal and medical information of 5.56 million patients in the largest healthcare data breach of 2025, resulting in an $18 million class action settlement.</description><pubDate>Sat, 08 Mar 2025 00:00:00 GMT</pubDate></item><item><title>PowerSchool Data Breach</title><link>https://uinat.com/breaches/powerschool-student-data-breach-2024/</link><guid isPermaLink="true">https://uinat.com/breaches/powerschool-student-data-breach-2024/</guid><description>A compromised credential without MFA enabled allowed a hacker to access PowerSchool&apos;s systems for nine days, exfiltrating personal data of 62 million students and 9.5 million educators in the largest breach of children&apos;s data in U.S. history.</description><pubDate>Sat, 28 Dec 2024 00:00:00 GMT</pubDate></item></channel></rss>