Coupang Data Breach Expands: 33.7 Million Accounts Compromised, 165,000 Additional Users Affected
South Korean e-commerce giant Coupang confirmed an additional 165,000 user accounts were exposed in the massive data breach affecting 33.7 million total accounts, triggered by a former employee using valid authentication keys.
ShinyHunters Publishes Harvard and UPenn Data: 2 Million Records Exposed
The ShinyHunters cybercriminal group published stolen data from Harvard University and the University of Pennsylvania after ransom demands went unpaid, exposing over 2 million alumni, donor, and student records.
NationStates Browser Game Confirms Data Breach After RCE Exploit
NationStates shut down its site after a vulnerability reporter chained input sanitization flaws to achieve remote code execution, copying user emails, password hashes, and IP addresses.
Qilin Ransomware Gang Claims Tulsa International Airport Breach
The Russian-speaking Qilin ransomware group listed Tulsa International Airport as a victim, leaking financial documents, employee IDs, and executive communications in the aviation sector's first reported attack of 2026.
Match Group Breach Exposes Data from Tinder, Hinge, and OkCupid
ShinyHunters stole 10 million records from Match Group dating platforms via a vishing attack that compromised Okta SSO credentials. The breach exposed user advertising IDs, IP addresses, and dating profile content.
Crunchbase Confirms Breach After ShinyHunters Publishes 2M+ Records
ShinyHunters breached Crunchbase via Okta voice phishing, exfiltrating over 2 million records. The attack was part of a broader campaign targeting approximately 100 organizations using real-time SSO phishing kits.
WorldLeaks Publishes 1.4TB of Nike Internal Data
The WorldLeaks extortion group published 1.4TB of Nike intellectual property including product designs, tech packs, and manufacturing documents spanning 2020-2026 after the company didn't pay.
8.73 Billion Chinese Records Exposed in Largest Known Single-Source Data Leak
Cybernews researchers discovered a massive Elasticsearch cluster containing national IDs, passwords, and personal data of hundreds of millions of Chinese citizens, hosted on bulletproof infrastructure and accessible for three weeks.
Under Armour Ransomware Breach Exposes 72 Million Customer Records
The Everest ransomware group leaked 72.7 million Under Armour customer records including emails, names, dates of birth, purchase history, and loyalty program details after the company didn't pay.
BreachForums Database Leaked — 324,000 Cybercriminal Accounts Exposed
A former ShinyHunters member leaked the BreachForums user database with 324,000 accounts, including usernames, emails, password hashes, and 70,000 IP addresses. Law enforcement interest is likely.
Disputifier Shopify App Hack Exposes 200,000+ Merchant Records
Exposed API tokens in Disputifier's frontend allowed attackers to process unauthorized refunds and exfiltrate data from Shopify merchants. The app was delisted after the company allegedly refused bug bounty negotiations.
European Space Agency Confirms Data Breach, Criminal Investigation Launched
A threat actor using the alias '888' exfiltrated 200GB+ from ESA systems including Bitbucket repositories, API tokens, and contractor data from SpaceX, Airbus, and Thales. Criminal probe initiated.
Blue Shield of California Notifies Members of Healthcare Data Breach
A record merge error during a system enhancement exposed member PHI through Blue Shield's member portal. The October 2025 incident was disclosed in January 2026 under HIPAA requirements.
Claims Management Giant Sedgwick Hit by TridentLocker Ransomware
TridentLocker claims to have stolen 3.4GB from Sedgwick Government Solutions, which provides claims services to DHS, ICE, CBP, DOL, and CISA. The attack targeted an isolated file transfer system.
Brightspeed Investigating Breach Claims After Crimson Collective Posts Customer Data
Extortion group Crimson Collective claims to have stolen data on over 1 million Brightspeed customers, including PII, billing details, and payment information. A class-action lawsuit has been filed.