People trust us with some of their most sensitive personal data. Protecting it has to be more than a promise.
That’s why earning our SOC 2 Type II certification matters so much to us. Independent auditors tested our Security, Confidentiality, and Privacy controls over time to verify that the practices behind them consistently work as designed.
Read more: https://t.co/gihl3scZ9t
Hackers claim they stole FBI employee data, including information that could identify where agents and their families live.
ShinyHunters claims it breached FBI systems and obtained sensitive employee and applicant records. Nextgov was shown data appearing to contain names, home addresses, phone numbers and information about spouses and siblings for nearly 5,000 employees. The full dataset has not been verified.
Revolut disclosed customer data after scammers sent fake information requests from a legitimate government agency email domain. Exposed data included contact details, passports and driver’s licenses, and may have included selfies and transaction histories.
Revolut hasn't disclosed how many customers or which countries were affected.
Suno, the AI music platform, suffered a leak affecting the personal information of more than 55 million users, including email addresses, phone numbers, and tens of thousands of Stripe transaction records containing names, addresses, purchase amounts, and partial payment card details. The company has not publicly acknowledged the breach or disclosed how the attackers gained access.
If you've used Suno, be on the lookout for phishing emails or texts that reference your account or past purchases. Change your password if you've reused it elsewhere, and review your financial statements for any unfamiliar activity. Real purchase details can make scam messages far more convincing than generic phishing attempts.
Hugging Face is urging users to rotate any API keys stored on the platform after attackers compromised internal datasets and service credentials through a malicious dataset upload. It's still investigating whether customer or partner data was accessed.
A key Apple and Tesla supplier has confirmed a data breach after hackers allegedly stole more than 630GB of internal data.
According to reports, the exposed files may include Apple supplier specifications, Tesla manufacturing documents, internal emails, and SAP-related information. Apple is reportedly investigating the incident, and a ransom demand was made to Tata Electronics, the affected supplier.
Based on what's been reported so far, the exposed data appears to be company and operational information rather than customer account data. That means Apple and Tesla users aren't believed to be directly affected, though the incident highlights how much sensitive information can sit with third-party suppliers behind the scenes.
Hackers claim they leaked 26 million Madison Square Garden visitor records after an alleged ransom deadline passed.
The leak allegedly includes visitor information, security reports, and records tied to facial recognition systems used by the venue.
A night out at a concert isn't something most people associate with privacy risks. Yet as more venues adopt technologies like facial recognition, visitor data becomes part of the cybersecurity equation, making attendees more likely to be affected when breaches like this occur.
7-Eleven confirmed a data breach affecting more than 185,000 people after attackers gained access to an internal server containing franchisee records.
Exposed data reportedly includes names, addresses, phone numbers, dates of birth, and in some cases Social Security numbers and driver’s license details. ShinyHunters claimed responsibility for the attack.
Breaches like this create long-term exposure because personal details don’t lose value once they leak. Information tied to identity can continue circulating across phishing, fraud, and social engineering campaigns long after the original incident.
@AirCanada your website is not allowing me to cancel my booking within the 24 hour window. I sent you a DM too, but haven’t heard back. Been on hold on the phone for over an hour.
Microsoft uncovered a major cloud attack campaign targeting Microsoft 365 and Azure accounts.
The attackers impersonated IT support staff, tricked employees into approving fake MFA prompts, then used compromised Microsoft Entra ID accounts to access OneDrive, SharePoint, Azure databases, and internal systems.
Breaches are increasingly targeting cloud identities. Once attackers control the identity layer, they can move through entire environments using legitimate tools.
@vibeeval@Privacy_Hawk does this all in minutes and is much more comprehensive. If you’ve got the 7 hours and want to repeat that 7 hours every few months, sure. For those who want it handled every month automatically, @Privacy_Hawk is the way.
The biggest privacy risk isn’t hidden. It’s legal.
Data brokers are part of a multi-billion dollar industry that collects and sells personal information, like your name, address, phone number, location history, relatives, and even inferred interests.
You don’t have to sign up for it. You don’t have to interact with them. They build profiles about you anyway.
That’s why we built our data removal feature, to help you take that information back.
Not all data exposure starts with a hack.
A lot of it comes from data brokers, companies that collect, aggregate, and share personal information from apps, websites, and everyday activity.
No breach required.
The risk isn’t just when data is stolen.
It’s how widely it’s already been collected and shared.
“Free” apps aren’t actually free.
They just don’t charge you money upfront.
Most run on a different exchange: your data, your attention, and your behavior. Every click, scroll, and interaction adds value.
You’re not just using the product, you’re helping power it.
🔓Alleged ransomware attack on Apple supplier Luxshare may have exposed employee data: names, roles, emails, and project details.
Why this matters: This kind of breach fuels targeted phishing, attackers can impersonate real employees to gain deeper access to vendors, partners, and internal systems.
That’s often the first step in a wider scam wave. Even if consumers aren’t directly affected now, this is exactly how tomorrow’s threats begin.
#Cybersecurity #DataBreach
2025 had some of the biggest data breaches on record:
• PowerSchool (Education) — 62M records exposed after attackers used stolen credentials and remote access tools, escalating into extortion
• Salesforce ecosystem (SaaS) — 1B records affected across 40+ companies after phishing and voice scams abused third-party integrations
• Yale New Haven Health (Healthcare) — 5.5M patients impacted after unauthorized network access exposed sensitive medical data
• Prosper Marketplace (Finance) — 17.6M email addresses breached, with financial and identity data accessed from internal systems
• TransUnion (via third-party app) — 4.4M Americans affected after a connected external tool was compromised
Different industries. Same playbook: stolen passwords + third-party access + personal data that’s more valuable than ever.
Breaches are inevitable. Exposure isn’t. Shrink your digital footprint. 🔒
149M usernames + passwords exposed in an unsecured database. What was in the leak?
✅ Email logins (Gmail + more)
✅Social accounts (Facebook/Instagram)
✅ Banking logins
✅ Streaming + subscriptions (Netflix, etc.)
✅ Everyday accounts people reuse everywhere
Researchers suspect these were collected via infostealer malware (not a direct hack of major platforms).
Quick actions to protect yourself: Change your email password + turn on 2FA everywhere + replace reused passwords 🔒
Tax season is when scams surge.
As filing, payments, and document sharing move online, scammers use timing and stress to their advantage. That’s why phishing emails, fake refund notices, and IRS-themed texts show up every year.
What to know: the IRS only contacts you by email or text with permission, may call about account matters without sharing sensitive details, and directs payments or issues only to https://t.co/ecbrwhVifr.
When in doubt, ignore the message and verify directly through official IRS channels.