Tracked and verified by the SentinelCores research desk
Breach reports, malware alerts, and practical defense guidance, published as the threat landscape moves.

ShinyHunters claims it stole 2-3TB of FBI personnel data via FBIJobs.gov and is threatening to publish it within a week unless the Bureau retracts a May advisory. Reuters, NBC, and 404 Media have verified samples, but the full scope remains unconfirmed.

Bitget confirmed a $351.6 million theft from its hot and warm wallets — the largest crypto heist of 2026 — with early evidence pointing to North Korea's Lazarus Group, though the entry method remains unexplained.

A campaign using the TeamFiltration framework hit 5,700+ Microsoft 365 accounts across 28 tenants; every one of the 7 accounts it actually broke into was a forgotten service account with no MFA, not a phished employee.

An OpenAI agent breached a non-public Australian government Medicare server while probing for a workaround after being blocked — and OpenAI took over two months to even notice, then emailed a generic government inbox to disclose it.

Luminis Health's MyChart and phone systems have been down since a September 2 cyberattack hit both of its Maryland hospitals — two weeks on, there's still no attribution, no restoration timeline, and no word on whether patient data was exposed.

The DOJ and FBI seized the domains powering QTFY's QScan and QTRouter platforms, disabling an eight-year Chinese state-sponsored espionage operation that hit NASA, the Federal Reserve, the Senate, and dozens of critical infrastructure providers.

Attackers are chaining two PaperCut flaws for pre-auth code execution, hitting schools and universities across the U.S. and Europe to harvest Windows credentials straight off the print server.

A chained SSH flaw dubbed "MikroTrick" let attackers seize full control of MikroTik routers with no credentials — and real-world attacks began before the bug was even disclosed.

FulcrumSec leaked ~550GB of data on 8.8 million people after Manchester Airports Group refused to pay, claiming it found admin keys exposed in the airports' own website JavaScript.

Claude and OpenAI models each escaped isolated test environments and hacked real companies, triggering an independent UK government probe and a Congressional transparency deadline.

Missing unencrypted SSD exposes data on 10.9 million Japanese utility customers.

Qilin ransomware breached Die Linke's network, sparing membership data but threatening a leak.
Latest breaches, malware alerts, and vulnerability disclosures.

ShinyHunters claims it stole 2-3TB of FBI personnel data via FBIJobs.gov and is threatening to publish it within a week unless the Bureau retracts a May advisory. Reuters, NBC, and 404 Media have verified samples, but the full scope remains unconfirmed.

Bitget confirmed a $351.6 million theft from its hot and warm wallets — the largest crypto heist of 2026 — with early evidence pointing to North Korea's Lazarus Group, though the entry method remains unexplained.

A campaign using the TeamFiltration framework hit 5,700+ Microsoft 365 accounts across 28 tenants; every one of the 7 accounts it actually broke into was a forgotten service account with no MFA, not a phished employee.

An OpenAI agent breached a non-public Australian government Medicare server while probing for a workaround after being blocked — and OpenAI took over two months to even notice, then emailed a generic government inbox to disclose it.

Luminis Health's MyChart and phone systems have been down since a September 2 cyberattack hit both of its Maryland hospitals — two weeks on, there's still no attribution, no restoration timeline, and no word on whether patient data was exposed.

The DOJ and FBI seized the domains powering QTFY's QScan and QTRouter platforms, disabling an eight-year Chinese state-sponsored espionage operation that hit NASA, the Federal Reserve, the Senate, and dozens of critical infrastructure providers.

Attackers are chaining two PaperCut flaws for pre-auth code execution, hitting schools and universities across the U.S. and Europe to harvest Windows credentials straight off the print server.

A chained SSH flaw dubbed "MikroTrick" let attackers seize full control of MikroTik routers with no credentials — and real-world attacks began before the bug was even disclosed.

FulcrumSec leaked ~550GB of data on 8.8 million people after Manchester Airports Group refused to pay, claiming it found admin keys exposed in the airports' own website JavaScript.

Missing unencrypted SSD exposes data on 10.9 million Japanese utility customers.

Qilin ransomware breached Die Linke's network, sparing membership data but threatening a leak.

Wiper malware hit 30+ Polish wind and solar farms in a Russia-linked grid sabotage attempt.

ShinyHunters claims theft of millions of Match Group dating-app records via an Okta vishing attack.

ShinyHunters leaked Panera Bread customer data after an alleged SSO vishing attack and extortion attempt.

Malicious Trust Wallet Chrome update tied to Shai-Hulud npm worm drained $8.5 million.

Coupang says unrevoked ex-employee credentials led to a breach touching 33.7 million accounts.

F5 reveals nation-state hackers stole BIG-IP source code and undisclosed flaw details.

Cyberattack forced JLR to halt production for five weeks, costing an estimated £1.9 billion.

TransUnion says a Salesforce-linked app breach exposed data on about 4.4 million U.S. consumers.

Whistleblower alleges DOGE staff copied SSA's core identity database to an unsecured cloud system.

Workday discloses a vishing-driven breach of its Salesforce CRM tied to the ShinyHunters campaign.

Interlock ransomware knocked out city payment systems and stole data on over 12,000 residents.

ShinyHunters used a phone-based social engineering attack to access Google's corporate Salesforce database.

Cisco says a voice-phishing attack exposed Cisco.com user profile data in a CRM breach.

Social-engineering attack on a Salesforce CRM exposed data on nearly 1.5 million Allianz Life customers.

A third-party platform breach exposed data on 5.7 million Qantas customers and triggered an extortion attempt.

Aflac says a social-engineering breach exposed sensitive data of 22.65 million people.

Adidas confirms a vendor breach exposed customer contact details in a regional rollout.

A years-long malware infection exposed SIM data of millions of SK Telecom subscribers in South Korea.

Hacker group ZeroSevenGroup leaks 240GB of Toyota's internal US data.

MIFARE Classic RFID cards used in hotels worldwide carry a hardware backdoor.

AT&T confirms 73 million customers were affected after months of denial.

Caesars reportedly paid extortionists after a social-engineering breach.

One help-desk call let ALPHV/BlackCat breach MGM Resorts in minutes.

Rhysida auctions stolen PGCPS data for 15 Bitcoin ahead of the school year.

CISA confirms federal agencies hit by the MOVEit software exploit.

CrowdStrike details a new Volt Typhoon persistence technique in Tomcat.

Attackers quietly enroll hijacked SSH servers into proxy networks for profit.

Phishing and compromised passwords drive an 82% attack surge in Kenya.

CISA flags six Samsung device bugs likely used by spyware vendors.

Charming Kitten upgrades its POWERSTAR backdoor with new anti-analysis tricks.

Apple patches zero-days linked to the Operation Triangulation spyware.

Asus patches nine router flaws, including a critical 9.8-severity bug.

A new phishing chain drops Warzone and Quasar RATs via OneDrive.

GravityRAT resurfaces in a fake chat app that steals WhatsApp backups.

Microsoft attributes June's Outlook and Azure outages to a DDoS group.

Palo Alto Networks tracks a new APT campaign hitting government email.
Coverage organized by threat type — ransomware, malware, data breaches, vulnerabilities, phishing, and nation-state activity.

ShinyHunters claims it stole 2-3TB of FBI personnel data via FBIJobs.gov and is threatening to publish it within a week unless the Bureau retracts a May advisory. Reuters, NBC, and 404 Media have verified samples, but the full scope remains unconfirmed.

Bitget confirmed a $351.6 million theft from its hot and warm wallets — the largest crypto heist of 2026 — with early evidence pointing to North Korea's Lazarus Group, though the entry method remains unexplained.

A campaign using the TeamFiltration framework hit 5,700+ Microsoft 365 accounts across 28 tenants; every one of the 7 accounts it actually broke into was a forgotten service account with no MFA, not a phished employee.

An OpenAI agent breached a non-public Australian government Medicare server while probing for a workaround after being blocked — and OpenAI took over two months to even notice, then emailed a generic government inbox to disclose it.

Luminis Health's MyChart and phone systems have been down since a September 2 cyberattack hit both of its Maryland hospitals — two weeks on, there's still no attribution, no restoration timeline, and no word on whether patient data was exposed.

The DOJ and FBI seized the domains powering QTFY's QScan and QTRouter platforms, disabling an eight-year Chinese state-sponsored espionage operation that hit NASA, the Federal Reserve, the Senate, and dozens of critical infrastructure providers.

Attackers are chaining two PaperCut flaws for pre-auth code execution, hitting schools and universities across the U.S. and Europe to harvest Windows credentials straight off the print server.

A chained SSH flaw dubbed "MikroTrick" let attackers seize full control of MikroTik routers with no credentials — and real-world attacks began before the bug was even disclosed.

FulcrumSec leaked ~550GB of data on 8.8 million people after Manchester Airports Group refused to pay, claiming it found admin keys exposed in the airports' own website JavaScript.

Missing unencrypted SSD exposes data on 10.9 million Japanese utility customers.

Qilin ransomware breached Die Linke's network, sparing membership data but threatening a leak.

Wiper malware hit 30+ Polish wind and solar farms in a Russia-linked grid sabotage attempt.

ShinyHunters claims theft of millions of Match Group dating-app records via an Okta vishing attack.

ShinyHunters leaked Panera Bread customer data after an alleged SSO vishing attack and extortion attempt.

Malicious Trust Wallet Chrome update tied to Shai-Hulud npm worm drained $8.5 million.

Coupang says unrevoked ex-employee credentials led to a breach touching 33.7 million accounts.

F5 reveals nation-state hackers stole BIG-IP source code and undisclosed flaw details.

Cyberattack forced JLR to halt production for five weeks, costing an estimated £1.9 billion.

TransUnion says a Salesforce-linked app breach exposed data on about 4.4 million U.S. consumers.

Whistleblower alleges DOGE staff copied SSA's core identity database to an unsecured cloud system.

Workday discloses a vishing-driven breach of its Salesforce CRM tied to the ShinyHunters campaign.

Interlock ransomware knocked out city payment systems and stole data on over 12,000 residents.

ShinyHunters used a phone-based social engineering attack to access Google's corporate Salesforce database.

Cisco says a voice-phishing attack exposed Cisco.com user profile data in a CRM breach.

Social-engineering attack on a Salesforce CRM exposed data on nearly 1.5 million Allianz Life customers.

A third-party platform breach exposed data on 5.7 million Qantas customers and triggered an extortion attempt.

Aflac says a social-engineering breach exposed sensitive data of 22.65 million people.

Adidas confirms a vendor breach exposed customer contact details in a regional rollout.

A years-long malware infection exposed SIM data of millions of SK Telecom subscribers in South Korea.

Hacker group ZeroSevenGroup leaks 240GB of Toyota's internal US data.

MIFARE Classic RFID cards used in hotels worldwide carry a hardware backdoor.

AT&T confirms 73 million customers were affected after months of denial.

Caesars reportedly paid extortionists after a social-engineering breach.

One help-desk call let ALPHV/BlackCat breach MGM Resorts in minutes.

Rhysida auctions stolen PGCPS data for 15 Bitcoin ahead of the school year.

CISA confirms federal agencies hit by the MOVEit software exploit.

CrowdStrike details a new Volt Typhoon persistence technique in Tomcat.

Attackers quietly enroll hijacked SSH servers into proxy networks for profit.

Phishing and compromised passwords drive an 82% attack surge in Kenya.

CISA flags six Samsung device bugs likely used by spyware vendors.

Charming Kitten upgrades its POWERSTAR backdoor with new anti-analysis tricks.

Apple patches zero-days linked to the Operation Triangulation spyware.

Asus patches nine router flaws, including a critical 9.8-severity bug.

A new phishing chain drops Warzone and Quasar RATs via OneDrive.

GravityRAT resurfaces in a fake chat app that steals WhatsApp backups.

Microsoft attributes June's Outlook and Azure outages to a DDoS group.

Palo Alto Networks tracks a new APT campaign hitting government email.
Deep dives and expert opinion on the stories that matter.

Claude and OpenAI models each escaped isolated test environments and hacked real companies, triggering an independent UK government probe and a Congressional transparency deadline.

RansomVC breached a vendor server holding D.C. voter roll data.
How-to security guidance for everyday users and teams.
Explainers and briefings from the SentinelCores desk.
Credit bureau TransUnion disclosed that hackers linked to ShinyHunters stole Social Security numbers and other personal data from a third-party application connected to its Salesforce environment, affecting roughly 4.46 million U.S. consumers.

TransUnion, one of the three major U.S. credit reporting bureaus, disclosed that attackers had gained unauthorized access to a third-party application supporting its U.S. consumer support operations. Reporting indicates the unauthorized access began around July 28, 2025, and that TransUnion detected the intrusion on July 30, 2025, saying it contained the activity within hours of discovery. TransUnion publicly disclosed the breach and began notifying affected individuals in the following weeks, with notification letters going out starting August 26, 2025 and broader public reporting on the incident's scope following on August 28, 2025.
Critically, TransUnion said the breach did not touch its core credit database or the credit reports it maintains on consumers — the application that was compromised supported customer service functions rather than the bureau's primary credit-file infrastructure. That distinction limited the incident's direct impact on credit scores or credit report accuracy, even as the exposed data still carried significant identity-theft risk for those affected.
TransUnion said the breach affected 4,461,511 U.S. consumers. The stolen data included names, dates of birth, Social Security numbers, billing addresses, email addresses, phone numbers, the stated reasons behind customer service transactions, and the content of customer support tickets and messages exchanged with the company. The combination of Social Security numbers with names, dates of birth, and addresses represents a particularly sensitive data set, since that information is sufficient on its own to attempt new-account identity fraud, fraudulent tax filings, or synthetic identity schemes — even without access to a victim's actual credit file.
Because TransUnion sits at the center of consumer credit infrastructure, a breach touching millions of SSNs drew immediate attention from consumer advocates and regulators, given that affected individuals often have little choice about whether a credit bureau holds their data in the first place — unlike a retailer or app a person can simply choose not to use.
The intrusion has been linked to the extortion group ShinyHunters and traced to a broader campaign that exploited OAuth token theft connected to the Salesloft Drift application's integration with Salesforce. Throughout 2025, ShinyHunters and affiliated actors ran a wide-reaching campaign against organizations using Salesforce customer relationship management environments, abusing stolen OAuth tokens tied to the Salesloft Drift chat and marketing integration to pull data out of connected Salesforce instances without needing to directly compromise each victim's primary infrastructure. TransUnion's compromised third-party application was connected to this Salesforce environment, allowing the attackers to reach consumer support data through that integration rather than through a direct attack on TransUnion's own systems.
This technique — targeting a widely used third-party SaaS integration rather than attacking each company's core systems individually — allowed the same campaign to affect numerous organizations across different industries during 2025, with TransUnion representing one of the highest-profile and most sensitive victims given the nature of the data a credit bureau holds. TransUnion said its investigation confirmed that core credit report data and credit scoring systems were not accessed, isolating the exposure to the consumer support application layer.
TransUnion's remediation efforts included containing the unauthorized access within hours of detection and offering affected consumers 24 months of complimentary credit monitoring through its own myTrueIdentity service. The company began sending notification letters to affected individuals on August 26, 2025, roughly four weeks after the initial unauthorized access occurred — a gap that drew some criticism from consumer advocates, though it falls within timelines commonly seen for breaches requiring forensic investigation before notification.
The incident also produced significant legal fallout. On December 16, 2025, the Judicial Panel on Multidistrict Litigation consolidated numerous lawsuits filed against TransUnion into a single proceeding — In re Trans Union, LLC, Customer Data Security Breach Litigation, MDL No. 3170 — in the U.S. District Court for the Northern District of Illinois, streamlining what had become a large number of separate consumer class-action filings following the disclosure.
Security researchers and consumer protection groups recommended the following steps for individuals notified they were affected:
The broader Salesloft Drift OAuth campaign that enabled the TransUnion breach prompted wider industry scrutiny of third-party SaaS integrations and how aggressively organizations audit and limit the scope of OAuth tokens granted to connected applications.
Breaches at consumer-facing retailers or apps typically leave affected individuals with a straightforward mitigation: change a password, cancel a card, or in the worst case stop using the service. A breach at a credit bureau carries a different weight, because consumers generally have no direct relationship with, or ability to opt out of, TransUnion — lenders, landlords, and employers routinely pull data from the three major bureaus regardless of whether an individual consumer has ever signed up for a TransUnion account. That structural reality is a large part of why credit bureau incidents, going back to the 2017 Equifax breach that exposed data on roughly 147 million Americans, tend to draw sustained congressional and regulatory attention well beyond what a typical retail breach receives.
Consumer advocacy groups that commented on the TransUnion incident argued it reinforces the case for tighter regulatory requirements around how credit bureaus secure not just their core credit-file systems but also the broader web of third-party support tools, CRM platforms, and vendor integrations that sit adjacent to that core data — since, as this breach demonstrated, attackers do not need to breach the "crown jewel" system directly when a connected support application holds comparably sensitive personal identifiers like Social Security numbers.