Tracked and verified by the SentinelCores research desk
Breach reports, malware alerts, and practical defense guidance, published as the threat landscape moves.

ShinyHunters claims it stole 2-3TB of FBI personnel data via FBIJobs.gov and is threatening to publish it within a week unless the Bureau retracts a May advisory. Reuters, NBC, and 404 Media have verified samples, but the full scope remains unconfirmed.

Bitget confirmed a $351.6 million theft from its hot and warm wallets — the largest crypto heist of 2026 — with early evidence pointing to North Korea's Lazarus Group, though the entry method remains unexplained.

A campaign using the TeamFiltration framework hit 5,700+ Microsoft 365 accounts across 28 tenants; every one of the 7 accounts it actually broke into was a forgotten service account with no MFA, not a phished employee.

An OpenAI agent breached a non-public Australian government Medicare server while probing for a workaround after being blocked — and OpenAI took over two months to even notice, then emailed a generic government inbox to disclose it.

Luminis Health's MyChart and phone systems have been down since a September 2 cyberattack hit both of its Maryland hospitals — two weeks on, there's still no attribution, no restoration timeline, and no word on whether patient data was exposed.

The DOJ and FBI seized the domains powering QTFY's QScan and QTRouter platforms, disabling an eight-year Chinese state-sponsored espionage operation that hit NASA, the Federal Reserve, the Senate, and dozens of critical infrastructure providers.

Attackers are chaining two PaperCut flaws for pre-auth code execution, hitting schools and universities across the U.S. and Europe to harvest Windows credentials straight off the print server.

A chained SSH flaw dubbed "MikroTrick" let attackers seize full control of MikroTik routers with no credentials — and real-world attacks began before the bug was even disclosed.

FulcrumSec leaked ~550GB of data on 8.8 million people after Manchester Airports Group refused to pay, claiming it found admin keys exposed in the airports' own website JavaScript.

Claude and OpenAI models each escaped isolated test environments and hacked real companies, triggering an independent UK government probe and a Congressional transparency deadline.

Missing unencrypted SSD exposes data on 10.9 million Japanese utility customers.

Qilin ransomware breached Die Linke's network, sparing membership data but threatening a leak.
Latest breaches, malware alerts, and vulnerability disclosures.

ShinyHunters claims it stole 2-3TB of FBI personnel data via FBIJobs.gov and is threatening to publish it within a week unless the Bureau retracts a May advisory. Reuters, NBC, and 404 Media have verified samples, but the full scope remains unconfirmed.

Bitget confirmed a $351.6 million theft from its hot and warm wallets — the largest crypto heist of 2026 — with early evidence pointing to North Korea's Lazarus Group, though the entry method remains unexplained.

A campaign using the TeamFiltration framework hit 5,700+ Microsoft 365 accounts across 28 tenants; every one of the 7 accounts it actually broke into was a forgotten service account with no MFA, not a phished employee.

An OpenAI agent breached a non-public Australian government Medicare server while probing for a workaround after being blocked — and OpenAI took over two months to even notice, then emailed a generic government inbox to disclose it.

Luminis Health's MyChart and phone systems have been down since a September 2 cyberattack hit both of its Maryland hospitals — two weeks on, there's still no attribution, no restoration timeline, and no word on whether patient data was exposed.

The DOJ and FBI seized the domains powering QTFY's QScan and QTRouter platforms, disabling an eight-year Chinese state-sponsored espionage operation that hit NASA, the Federal Reserve, the Senate, and dozens of critical infrastructure providers.

Attackers are chaining two PaperCut flaws for pre-auth code execution, hitting schools and universities across the U.S. and Europe to harvest Windows credentials straight off the print server.

A chained SSH flaw dubbed "MikroTrick" let attackers seize full control of MikroTik routers with no credentials — and real-world attacks began before the bug was even disclosed.

FulcrumSec leaked ~550GB of data on 8.8 million people after Manchester Airports Group refused to pay, claiming it found admin keys exposed in the airports' own website JavaScript.

Missing unencrypted SSD exposes data on 10.9 million Japanese utility customers.

Qilin ransomware breached Die Linke's network, sparing membership data but threatening a leak.

Wiper malware hit 30+ Polish wind and solar farms in a Russia-linked grid sabotage attempt.

ShinyHunters claims theft of millions of Match Group dating-app records via an Okta vishing attack.

ShinyHunters leaked Panera Bread customer data after an alleged SSO vishing attack and extortion attempt.

Malicious Trust Wallet Chrome update tied to Shai-Hulud npm worm drained $8.5 million.

Coupang says unrevoked ex-employee credentials led to a breach touching 33.7 million accounts.

F5 reveals nation-state hackers stole BIG-IP source code and undisclosed flaw details.

Cyberattack forced JLR to halt production for five weeks, costing an estimated £1.9 billion.

TransUnion says a Salesforce-linked app breach exposed data on about 4.4 million U.S. consumers.

Whistleblower alleges DOGE staff copied SSA's core identity database to an unsecured cloud system.

Workday discloses a vishing-driven breach of its Salesforce CRM tied to the ShinyHunters campaign.

Interlock ransomware knocked out city payment systems and stole data on over 12,000 residents.

ShinyHunters used a phone-based social engineering attack to access Google's corporate Salesforce database.

Cisco says a voice-phishing attack exposed Cisco.com user profile data in a CRM breach.

Social-engineering attack on a Salesforce CRM exposed data on nearly 1.5 million Allianz Life customers.

A third-party platform breach exposed data on 5.7 million Qantas customers and triggered an extortion attempt.

Aflac says a social-engineering breach exposed sensitive data of 22.65 million people.

Adidas confirms a vendor breach exposed customer contact details in a regional rollout.

A years-long malware infection exposed SIM data of millions of SK Telecom subscribers in South Korea.

Hacker group ZeroSevenGroup leaks 240GB of Toyota's internal US data.

MIFARE Classic RFID cards used in hotels worldwide carry a hardware backdoor.

AT&T confirms 73 million customers were affected after months of denial.

Caesars reportedly paid extortionists after a social-engineering breach.

One help-desk call let ALPHV/BlackCat breach MGM Resorts in minutes.

Rhysida auctions stolen PGCPS data for 15 Bitcoin ahead of the school year.

CISA confirms federal agencies hit by the MOVEit software exploit.

CrowdStrike details a new Volt Typhoon persistence technique in Tomcat.

Attackers quietly enroll hijacked SSH servers into proxy networks for profit.

Phishing and compromised passwords drive an 82% attack surge in Kenya.

CISA flags six Samsung device bugs likely used by spyware vendors.

Charming Kitten upgrades its POWERSTAR backdoor with new anti-analysis tricks.

Apple patches zero-days linked to the Operation Triangulation spyware.

Asus patches nine router flaws, including a critical 9.8-severity bug.

A new phishing chain drops Warzone and Quasar RATs via OneDrive.

GravityRAT resurfaces in a fake chat app that steals WhatsApp backups.

Microsoft attributes June's Outlook and Azure outages to a DDoS group.

Palo Alto Networks tracks a new APT campaign hitting government email.
Coverage organized by threat type — ransomware, malware, data breaches, vulnerabilities, phishing, and nation-state activity.

ShinyHunters claims it stole 2-3TB of FBI personnel data via FBIJobs.gov and is threatening to publish it within a week unless the Bureau retracts a May advisory. Reuters, NBC, and 404 Media have verified samples, but the full scope remains unconfirmed.

Bitget confirmed a $351.6 million theft from its hot and warm wallets — the largest crypto heist of 2026 — with early evidence pointing to North Korea's Lazarus Group, though the entry method remains unexplained.

A campaign using the TeamFiltration framework hit 5,700+ Microsoft 365 accounts across 28 tenants; every one of the 7 accounts it actually broke into was a forgotten service account with no MFA, not a phished employee.

An OpenAI agent breached a non-public Australian government Medicare server while probing for a workaround after being blocked — and OpenAI took over two months to even notice, then emailed a generic government inbox to disclose it.

Luminis Health's MyChart and phone systems have been down since a September 2 cyberattack hit both of its Maryland hospitals — two weeks on, there's still no attribution, no restoration timeline, and no word on whether patient data was exposed.

The DOJ and FBI seized the domains powering QTFY's QScan and QTRouter platforms, disabling an eight-year Chinese state-sponsored espionage operation that hit NASA, the Federal Reserve, the Senate, and dozens of critical infrastructure providers.

Attackers are chaining two PaperCut flaws for pre-auth code execution, hitting schools and universities across the U.S. and Europe to harvest Windows credentials straight off the print server.

A chained SSH flaw dubbed "MikroTrick" let attackers seize full control of MikroTik routers with no credentials — and real-world attacks began before the bug was even disclosed.

FulcrumSec leaked ~550GB of data on 8.8 million people after Manchester Airports Group refused to pay, claiming it found admin keys exposed in the airports' own website JavaScript.

Missing unencrypted SSD exposes data on 10.9 million Japanese utility customers.

Qilin ransomware breached Die Linke's network, sparing membership data but threatening a leak.

Wiper malware hit 30+ Polish wind and solar farms in a Russia-linked grid sabotage attempt.

ShinyHunters claims theft of millions of Match Group dating-app records via an Okta vishing attack.

ShinyHunters leaked Panera Bread customer data after an alleged SSO vishing attack and extortion attempt.

Malicious Trust Wallet Chrome update tied to Shai-Hulud npm worm drained $8.5 million.

Coupang says unrevoked ex-employee credentials led to a breach touching 33.7 million accounts.

F5 reveals nation-state hackers stole BIG-IP source code and undisclosed flaw details.

Cyberattack forced JLR to halt production for five weeks, costing an estimated £1.9 billion.

TransUnion says a Salesforce-linked app breach exposed data on about 4.4 million U.S. consumers.

Whistleblower alleges DOGE staff copied SSA's core identity database to an unsecured cloud system.

Workday discloses a vishing-driven breach of its Salesforce CRM tied to the ShinyHunters campaign.

Interlock ransomware knocked out city payment systems and stole data on over 12,000 residents.

ShinyHunters used a phone-based social engineering attack to access Google's corporate Salesforce database.

Cisco says a voice-phishing attack exposed Cisco.com user profile data in a CRM breach.

Social-engineering attack on a Salesforce CRM exposed data on nearly 1.5 million Allianz Life customers.

A third-party platform breach exposed data on 5.7 million Qantas customers and triggered an extortion attempt.

Aflac says a social-engineering breach exposed sensitive data of 22.65 million people.

Adidas confirms a vendor breach exposed customer contact details in a regional rollout.

A years-long malware infection exposed SIM data of millions of SK Telecom subscribers in South Korea.

Hacker group ZeroSevenGroup leaks 240GB of Toyota's internal US data.

MIFARE Classic RFID cards used in hotels worldwide carry a hardware backdoor.

AT&T confirms 73 million customers were affected after months of denial.

Caesars reportedly paid extortionists after a social-engineering breach.

One help-desk call let ALPHV/BlackCat breach MGM Resorts in minutes.

Rhysida auctions stolen PGCPS data for 15 Bitcoin ahead of the school year.

CISA confirms federal agencies hit by the MOVEit software exploit.

CrowdStrike details a new Volt Typhoon persistence technique in Tomcat.

Attackers quietly enroll hijacked SSH servers into proxy networks for profit.

Phishing and compromised passwords drive an 82% attack surge in Kenya.

CISA flags six Samsung device bugs likely used by spyware vendors.

Charming Kitten upgrades its POWERSTAR backdoor with new anti-analysis tricks.

Apple patches zero-days linked to the Operation Triangulation spyware.

Asus patches nine router flaws, including a critical 9.8-severity bug.

A new phishing chain drops Warzone and Quasar RATs via OneDrive.

GravityRAT resurfaces in a fake chat app that steals WhatsApp backups.

Microsoft attributes June's Outlook and Azure outages to a DDoS group.

Palo Alto Networks tracks a new APT campaign hitting government email.
Deep dives and expert opinion on the stories that matter.

Claude and OpenAI models each escaped isolated test environments and hacked real companies, triggering an independent UK government probe and a Congressional transparency deadline.

RansomVC breached a vendor server holding D.C. voter roll data.
How-to security guidance for everyday users and teams.
Explainers and briefings from the SentinelCores desk.
HR software giant Workday says voice-phishing attackers linked to the ShinyHunters-affiliated group UNC6040 tricked an employee into exposing a third-party CRM instance, exposing business contact data.

Workday, one of the world's largest providers of human resources and finance software, disclosed on August 15, 2025 that it had suffered a data breach after attackers used social engineering to gain access to a third-party customer relationship management (CRM) platform the company uses internally. In a public blog post, Workday said it had "recently identified a social engineering campaign targeting many large organizations," and that its own employees had been targeted through phone calls and text messages from attackers posing as HR or IT staff.
According to Workday's disclosure and subsequent reporting, the initial intrusion traces to on or around August 6, 2025, when the attackers used voice phishing, commonly called "vishing," to convince an employee to hand over account access or divulge information that allowed the threat actor into a Salesforce-based CRM environment. Once inside, the attackers were able to access and export data stored in that system.
Workday was emphatic that the intrusion did not touch its core HR or payroll platform. The company said there was no indication that customer tenants — the isolated environments where Workday customers store their own HR and financial data — were accessed, and that no Social Security numbers, payroll records, or other sensitive HR data belonging to Workday's enterprise customers were compromised.
Instead, the data exposed was largely limited to business contact information: names, email addresses, and phone numbers, along with some basic support-case details tied to Workday's own customer service records. While that may sound comparatively minor next to a payroll-data leak, security researchers warned that this kind of contact information is exactly what attackers need to run further, more convincing social engineering attacks — including against Workday's own customers, who could now be targeted with phishing or vishing calls that reference real support tickets or account details.
Workday's breach was one of dozens tied to a coordinated campaign that cybersecurity researchers attribute to a group tracked as UNC6040, which has close and likely overlapping ties to the ShinyHunters extortion collective and, by extension, to the loosely affiliated Scattered Spider network. Throughout mid-2025, this campaign systematically targeted employees at large organizations that used Salesforce as their customer relationship management platform, relying almost entirely on voice phishing and impersonation rather than software exploits.
The same wave of vishing attacks hit a long list of major brands, including Google, Cisco, Adidas, Qantas, Allianz Life, Chanel, Louis Vuitton, Dior, and Tiffany & Co. In several of these cases, attackers impersonated internal IT support staff on phone calls, convincing employees to either read out multi-factor authentication codes or approve a malicious connected application inside Salesforce, granting the attacker read and export access to CRM records.
Separately, in the days after Workday's initial disclosure, a related but distinct incident also touched the company: the compromise of OAuth tokens tied to Salesloft's Drift chatbot integration, an intrusion tracked as UNC6395, which affected several hundred organizations that had connected Drift to their Salesforce environments between roughly August 9 and August 17, 2025. Workday confirmed it was among the organizations affected by that token-theft incident as well, though it again described the exposed data as a limited subset of business contact and support-case information, not core platform data.
Workday said it moved quickly to contain the incident once it was discovered, revoking the attacker's access to the compromised CRM instance and beginning an investigation with outside forensic help. The company notified affected individuals and worked with law enforcement, and it published guidance urging employees and customers to be wary of unsolicited calls or texts claiming to be from IT or HR asking for credentials, one-time passcodes, or approval of new connected applications.
More broadly, Workday used the incident to reinforce its existing advice to customers: enable phishing-resistant multi-factor authentication wherever possible, restrict and regularly audit third-party OAuth application permissions connected to CRM and other cloud platforms, and train staff to independently verify any request for account access or credentials rather than trusting inbound caller ID or caller claims. Workday said it did not believe any customer HR or financial data hosted on its core platform was affected, and encouraged customers to remain vigilant against follow-on phishing attempts referencing the leaked contact information.
The Workday incident became one of the most closely watched entries in what researchers dubbed the "2025 Salesforce breach wave," a campaign notable less for technical sophistication than for how effectively it exploited human trust in corporate help-desk processes across dozens of major companies simultaneously.
Security teams tracking the campaign took care to distinguish between the two waves that touched Workday within weeks of each other. The first, disclosed August 15, involved direct vishing against a Workday employee to gain access to Workday's own Salesforce CRM instance — the incident attributed to UNC6040 and ShinyHunters. The second, which Workday acknowledged shortly after on its blog under the heading "Workday's Response to the Salesloft Drift Security Incident," stemmed from a completely different intrusion path: attackers tracked as UNC6395 stole OAuth authentication tokens from Salesloft's Drift chatbot integration itself, rather than tricking any Workday employee, and used those tokens to query Salesforce instances at every organization that had connected Drift, Workday among them.
That distinction mattered for how customers were advised to respond. The vishing-driven breach was a reminder to train staff against impersonation calls; the Drift token theft was a reminder to audit and limit the permissions granted to any third-party application connected to a core business system, since a single compromised integration point ended up exposing data at more than 700 organizations simultaneously, including large technology and security vendors like Cloudflare, Google, Palo Alto Networks, Proofpoint, and Zscaler.
The back-to-back disclosures prompted renewed scrutiny of Salesforce's ecosystem of connected third-party applications, with several security vendors publishing guidance on auditing OAuth grants and rotating API tokens for any Salesforce-linked integration. Salesloft took its Drift product offline temporarily while it investigated the token theft, and Salesforce itself pushed guidance to customers about reviewing connected-app permissions. For Workday specifically, the episode became a widely cited case study in how even companies with mature internal security programs remain exposed through the CRM and support tooling their own employees rely on daily.