🚨 Chick-fil-A confirms credential-stuffing attack on Chick-fil-A One accounts
Unauthorized parties used stolen credentials from a third-party source to attack their website & mobile app between June 17–19, 2026.
On July 13 they confirmed accounts may have been accessed.
Exposed data can include:
• Name + email
• Membership & mobile pay numbers
• QR codes
• Chick-fil-A credit / gift card balances
• Last 4 digits of payment cards
• (if saved) birthday, phone number, address
Chick-fil-A forced logouts, removed saved payment methods, restored balances, and added rewards. They also reset passwords.
This is the same attack type that hit them in 2023.
Do not reuse passwords. Change yours now and use unique ones everywhere.
Full official notice: https://t.co/auJzvhW8Qu
Stay protected → https://t.co/LnGmfRWNPz
🚨Ransomware Alert: RansomHouse claims compromise of Fidelity Services Group (fidelity-services[.]com)
The threat actors uploaded proof and includes:
* Copies of South African IDs
* SARS Tax Compliance Pin (Visible Income Tax Numbers)
* And more
🚨Ransomware Alert: PEAR claims compromise of South Plains Rural Health Services (sprhs[.]org)
The ransomware group claims to have compromised 1.4Tb of data.
The data includes:
* Financials
* HR information
* Patient data
🚨Ransomware Alert: Arcus Media claims Be Travel (betravel[.].co[.]za)
South African executive travel company hit in a fresh attack.
Attacker is threatening to release files in 6 days.
NEW BREACHWATCHER MILESTONE: 625 MILLION Breached Records Now Monitored!
We just ingested +360 MILLION new logs into our database.
That’s 625,000,000 compromised credentials, actively indexed, scanned, and watched 24/7, so nothing slips past you or your team.
In a world where one leaked password can end careers and companies, BreachWatcher keeps you one step ahead of the breach.
Not sure if your credentials are already out there?
Subscribe today and find out before the bad guys do. 👇
https://t.co/56DMuTYoyE
🚨 INC Ransom Hits Three More Law Firms
The ransomware group INC Ransom just added three U.S. law firms to their data leak site (posted within the last few hours):
• Call Horton – Horton Personal Injury Lawyers
• The Swanson Law Group
• John Dufour Law
Law firms remain a prime target due to sensitive client data. If you're in the legal sector, review your defenses now.
Compromised credentials are a top initial access vector in ransomware attacks, often 20-30%+ of incidents (and up to 80%+ when combined with phishing/social engineering per Verizon DBIR reports). Attackers buy creds on the dark web, then move laterally to encrypt or exfiltrate data.
Know your exposure. Sign up to BreachWatcher today!
https://t.co/ZmWLkC2Sfp
💰 Alert: Root Access to Major Spanish ISP Up for Sale
A threat actor claims full root access to the central servers of a major Spanish Internet Service Provider.
They're actively marketing this privileged access specifically to Ransomware-as-a-Service (RaaS) operators.
This kind of initial access dramatically lowers the bar for devastating ransomware attacks on critical telecom infrastructure.
🚨 New Security Alert: Icarus and Klue-Salesforce Supply Chain Campaign
Icarus compromised Klue's integrations, stole OAuth tokens, and pulled CRM data from 15+ orgs including Huntress, Recorded Future, LastPass, BeyondTrust, and more.
More details + IOCs:
https://t.co/gPxHyG6BPe
You don't need to be hacked to be exposed.
Birthdays, pet names, your employer, location check-ins, attackers piece it all together from what you've already posted publicly.
It's called OSINT, and it's the foundation of every good spear phishing email.
Full Cyber Tip:
https://t.co/nN2Mugxv4N
💰 Tripadvisor Database for Sale
A threat actor is selling a database allegedly belonging to Tripadvisor.
The sample data contained:
* Email addresses
* Hashes passwords
💰Notion Database for Sale
A threat actor is selling a database with 110 million unique records allegedly containing details of Notion users.
The sample data contained:
Email addresses
Hashed passwords
etc.
🚨 LastPass hit by Klue supply chain attack
Read it here:
https://t.co/1FHXt4dpYE
Incidents like this show why continuous credential & breach monitoring matters.
Your data breach moves faster than your coffee order.
BreachWatcher watches the dark web 24/7 so you know the moment your info is exposed, not months later.
$5/month. Less than a coffee. More than peace of mind.
Sign up today!
https://t.co/bEoGm0n2RO
🚨 bet365 database for sale
A threat actor claims to have access to a database containing 120M+ records belonging to bet365 customers.
A review of the sample data reveals:
- Full name & surname
- Email address
- Cellphone number
- Nationality
- ID number
Social Security Numbers (SSNs) were also observed in the sample.
🚨 BlackX just listed the ANC as a ransomware victim. The group has published them on their data leak site.
The leaked data is currently being analyzed.
🚨 BlackX just listed the ANC as a ransomware victim. The group has published them on their data leak site.
The leaked data is currently being analyzed.
🚨 BlackX just listed the ANC as a ransomware victim. The group has published them on their data leak site.
The leaked data is currently being analyzed.
📣UPDATE:
A threat actor known as BlackX has leaked a database of 2M+ records on their dark web leak site.
BreachWatcher analyzed the dump and confirmed the ID numbers match the standard ZA ID format, meaning South African citizens are likely affected.