
Reported Condé Nast database sale creates phishing and account-abuse risk
A reported sale of Condé Nast account data may fuel targeted phishing, but the advertised size and exposed fields remain unconfirmed.
A breach matters because of what exposed data can enable next. Track verified disclosures, affected information, downstream identity and fraud risk, and the response decisions organizations should prioritize.

A reported sale of Condé Nast account data may fuel targeted phishing, but the advertised size and exposed fields remain unconfirmed.

A forum seller is marketing alleged festival-buyer records for fraud-related uses. The defensive priority is targeted validation and stronger identity controls, not treating the listing as proven.

McKesson confirms stolen customer data, while the attacker’s enormous record-count claim remains unverified and the company investigation continues across connected applications.

Segmentation limited the operational impact, but the breached standalone system still held sensitive information about targets of active federal investigations.

What a school app sends across the network may differ materially from what its contracts and privacy paperwork promise families.

Latvia’s CSDD has confirmed a breach affecting payment records, while the supplied facts do not show direct compromise of bank accounts, funds or payment systems.

Apollo Global Management has confirmed that attackers gained unauthorized access to some of its cloud platforms between July 6 and July 10. The private-equity company disclosed the incident…

The Hospital for Sick Children in Toronto has disclosed a cyber incident involving personal information connected to current and former employees, job applicants and people working with related…

Latvia’s road traffic agency confirmed a major cyberattack in which attackers stole data connected to about 1.2 million people. The incident triggered political consequences and demonstrated how compromise…

CareCloud confirmed that attackers accessed an electronic health-record environment and stole information affecting roughly 3.7 million people. Healthcare platforms concentrate highly sensitive identity and medical data and often…

A reverse-lookup service called ClarityCheck left more than nine million image files reachable without authentication, according to research independently reported by Wired. The exposed storage contained roughly 450…

A breach at France’s tax authority exposed data tied to 678,000 people, creating not only a privacy issue but a powerful new source of material for follow-on fraud.

Cybercriminals attempted to extort the UK Department for Education after compromising two online portals used for support and the Turing Scheme. The criminals claimed to hold more than…

Australia’s Origin Energy said personal information belonging to roughly 900,000 current and former customers was accessed in a July cyber incident.

Upbound Group said a breach involving customer and business documents contributed to roughly $13 million in fraudulent contract losses. The incident is notable because it demonstrates how data…

A database attributed to microtask platform Paidwork was published online with records reportedly covering more than 23 million users. Malwarebytes and The Register cited Have I Been Pwned…

Spain’s data-protection authority fined 23andMe €2.4 million over security and notification failures connected with its 2023 breach. The regulator said more than 2,600 people in Spain were affected…

Healthcare software company Craneware disclosed unauthorized access to part of its data environment and the theft of a significant volume of files. Its regulatory filing said the material…

Abbott disclosed unauthorized access to a limited number of internal systems in its cancer-diagnostics business. The affected environment included legacy Exact Sciences systems that remained separate from Abbott’s…

Lidl disclosed that attackers accessed a separately stored customer-data file at an external service provider. The breach affected online-shop customers in Germany, Belgium and the Netherlands and exposed…

AssuranceAmerica disclosed that attackers gained access to parts of its IT environment and copied files containing personal and insurance information for 6.9 million people. The exposed data included…

Medtronic notified customers after a breach exposed personal and medical information belonging to millions of people. The incident was linked to unauthorized access to corporate IT systems and…

The U.S. Department of Homeland Security investigated unauthorized access to the Homeland Security Information Network, a platform used to share sensitive information across federal, state, local and private-sector…

Aflac disclosed that a breach involving its Japanese subsidiary exposed information associated with approximately 4.38 million customers. BleepingComputer published the underlying report or notice on 2026-06-30, placing the…
Global breach costs reached a record $4.99M while AI-driven attacks rose 56%, changing the economics of cyber risk.
Software vulnerability exploitation now begins 31% of breaches, while ransomware appears in 48%, sharpening the need to reduce exposed attack paths.
Cyber crime affected 19% of businesses and 14% of charities, with phishing and repeat victimization shaping the practical risk.