Visualização normal

Hoje — 9 de Setembro de 2026Cybersecurity News
  • ✇Security Affairs
  • Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data Pierluigi Paganini
    An exposed Vietnam-linked APIS database contained 220.8 million passenger and crew records, including passport and flight data. Researchers found an exposed Advance Passenger Information System (APIS) database containing 220.8 million passenger and crew records from January 2017 to April 2026. The data includes sensitive details such as passport numbers, identities and flight information, potentially affecting travelers of many nationalities who flew to, from or through Vietnam. Kinryū L
     

Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data

8 de Setembro de 2026, 08:01

An exposed Vietnam-linked APIS database contained 220.8 million passenger and crew records, including passport and flight data.

Researchers found an exposed Advance Passenger Information System (APIS) database containing 220.8 million passenger and crew records from January 2017 to April 2026.

The data includes sensitive details such as passport numbers, identities and flight information, potentially affecting travelers of many nationalities who flew to, from or through Vietnam. Kinryū Labs discovered the Elasticsearch cluster, named “pax-info,” while searching for exposed databases.

It contained 29 indices and about 107 GB of data. The researchers linked the server to IP space assigned to Viettel in Hanoi, but could not confirm which Vietnamese organization operated it.

Researchers found an exposed APIS database linked to Vietnam that contained more than 220 million passenger and crew records from 2017 to 2026. The data included passport numbers, identities and flight details. The Elasticsearch database, discovered by Kinryū Labs, held about 107 GB of data across 29 indices. It was hosted on IP addresses assigned to Viettel in Hanoi, although researchers could not confirm which Vietnamese organization operated the system.

The exposed database contained names, dates of birth, sex, nationalities, passport or travel-document numbers, expiration dates and issuing countries, BleepingComputers reports.

It also included flight numbers and dates, airlines, departure and destination airports, transit airports, seat numbers, baggage references, and scheduled, estimated and actual flight times. The database covered many airlines across Asia-Pacific, Europe and the Middle East, so it could affect people from around the world who traveled to or through Vietnam between 2017 and 2026.

Kinryū Labs confirmed the data was real by matching records with its researchers’ own trips to Vietnam. The total also counts travel records, not unique people, so frequent travelers may appear multiple times.

While the researchers could not provide a complete breakdown by nationality, the data covered numerous international airlines across Asia-Pacific, Europe, and the Middle East. As a result, the exposed records could relate to people from virtually anywhere who visited or transited through Vietnam over the nine-year period.

Kinryū Labs verified that the information was legitimate by matching records in the database against its researchers’ own travel to Vietnam.

The figures represent travel records rather than unique individuals. Passengers and crew members who flew multiple times may therefore appear repeatedly in the database.

Kinryū Labs reached the exposed database by combining two security misconfigurations. Direct internet access returned a 401 error, but another cloud-based path exposed the cluster and accepted default credentials.

FOFA first detected the host in 2022 and identified it as a database in 2023, but researchers could not determine when the passenger data became accessible. The records cover more than nine years, but the actual exposure period remains unknown.

Kinryū Labs reported the issue to Vietnamese authorities, affected airlines and national CERTs on June 3. The database was secured by June 8, with Singapore Airlines helping coordinate the response.

Researchers found no evidence that the listed airlines operated the system or suffered a network breach. They also found no ransom notes or signs that attackers had altered the database.

However, without server logs, they could not determine whether anyone had copied or stolen the data before the system was secured.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, APIS)

  • ✇Firewall Daily – The Cyber Express
  • Exposed Database Left 220Mn Airline Passenger, Crew Records Open to the Internet Mihir Bagwe
    A misconfigured Elasticsearch cluster exposed roughly 220.8 million airline passenger and crew records, including passport numbers and full itineraries, before it was secured in June, researchers at Kinryu Labs disclosed. The records spanned January 2017 through April 2026 and came from an Advance Passenger Information System deployment - the standardized data feed airlines transmit to border authorities before departure, covering traveler identity and flight details. Researchers linked the ser
     

Exposed Database Left 220Mn Airline Passenger, Crew Records Open to the Internet

8 de Setembro de 2026, 11:51

Airline, Data Leak,

A misconfigured Elasticsearch cluster exposed roughly 220.8 million airline passenger and crew records, including passport numbers and full itineraries, before it was secured in June, researchers at Kinryu Labs disclosed.

The records spanned January 2017 through April 2026 and came from an Advance Passenger Information System deployment - the standardized data feed airlines transmit to border authorities before departure, covering traveler identity and flight details. Researchers linked the server to IP address space assigned to Vietnamese telecommunications operator Viettel in Hanoi but said they could not confirm which organization operated it.

What was exposed

As per BleepingComputer, the data set combined identity documents with granular travel history. Exposed fields included names, dates of birth, sex and nationality; passport or travel document numbers, expiration dates and issuing countries; and flight numbers and dates, airline names, departure, destination and transit airports, seat numbers, baggage references, and scheduled, estimated and actual flight times.

That combination is unusually sensitive. Passport numbers are difficult to change and useful for identity fraud and account takeover at travel providers, while the itinerary fields - particularly transit airports and actual flight times - allow reconstruction of an individual's movements over nine years. Security researchers have long flagged APIS-style data as a surveillance risk precisely because it maps people to places at fixed times.

Also read: Why Airline Data Breaches Matter – And Why Qantas Could Have Been Worse

Two misconfigurations

According to Kinryu Labs, the cluster was protected inconsistently. Direct access over the internet returned an HTTP 401 authentication error, which would give a casual scanner the impression the system was locked down. An alternative cloud-based access path, however, reached the same cluster and accepted default credentials.

The exposure appears to have been long-lived. Internet scanning service FOFA detected the host in 2022 and identified it as a database in 2023. Kinryu Labs reported the issue on June 3, 2026, and the cluster was secured by June 8. Singapore Airlines assisted in coordinating the response, the researchers said. There is no indication any airline was itself breached or operated the server.

Researchers said they found no evidence the data was stolen, but noted that without server logs they could not determine whether anyone copied it during the years it was reachable — a distinction that matters more than it may appear, because notification obligations in several jurisdictions turn on whether unauthorized access can be ruled out.

Compliance exposure

Vietnam's Personal Data Protection Law, Law No. 91/2025/QH15, took effect Jan. 1, 2026 - before the exposure was reported and remediated. The statute requires notification within 72 hours of detecting a violation, rather than from the time it occurred, and expands notification duties to affected individuals in defined circumstances. Its penalty ceiling for general violations is 3 billion Vietnamese dong, with cross-border transfer breaches exposed to fines of up to 5% of prior-year revenue.

Because the records cover international flights, EU and UK residents are almost certainly represented, which brings GDPR and UK GDPR into scope for any controller established in or targeting those markets. Passport numbers and travel history fall squarely within personal data, and passenger data processing has drawn repeated scrutiny from European data protection authorities.

Antes de ontemCybersecurity News
  • ✇Cybersecurity News
  • Trezor Data Breach at ShipMonk Grows to 80,000 Customers Do Son
    The Trezor data breach at shipping partner ShipMonk exposed about 80,000 customers' order data. Wallets are safe, but phishing risk is high. Related Posts: Massive IDScan Data Breach Reported Independent Investigation Reveals 1,200 OpenAI Agents Breached Isolation in Hugging Face Attack JetBrains Cadence Server Compromised The post Trezor Data Breach at ShipMonk Grows to 80,000 Customers appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • JetBrains Cadence Server Compromised Do Son
    An unpatched JetBrains Cadence server exposed cloud infrastructure, AWS credentials, and critical developer secrets. Discover the details of this severe breach. Related Posts: Meta Settles Child Privacy Lawsuit Rapidly Mercor Data Breach Targets AI Supply Chain Exposed Git Repositories Leak Critical Cloud Secrets The post JetBrains Cadence Server Compromised appeared first on Daily CyberSecurity.
     

JetBrains Cadence Server Compromised

Por:Do Son
30 de Agosto de 2026, 23:50

An unpatched JetBrains Cadence server exposed cloud infrastructure, AWS credentials, and critical developer secrets. Discover the details of this severe breach.

Related Posts:

The post JetBrains Cadence Server Compromised appeared first on Daily CyberSecurity.

  • ✇Cybersecurity News
  • Meta Settles Child Privacy Lawsuit Rapidly Do Son
    Discover the details of Meta's massive $18 billion child privacy lawsuit settlement. Learn how new platform restrictions will impact young users worldwide. Related Posts: Mercor Data Breach Targets AI Supply Chain Exposed Git Repositories Leak Critical Cloud Secrets Take-Two Subpoenas Microsoft and Discord Over GTA VI "Cyberleek" Leaks The post Meta Settles Child Privacy Lawsuit Rapidly appeared first on Daily CyberSecurity.
     

Meta Settles Child Privacy Lawsuit Rapidly

Por:Do Son
27 de Agosto de 2026, 05:30

Discover the details of Meta's massive $18 billion child privacy lawsuit settlement. Learn how new platform restrictions will impact young users worldwide.

Related Posts:

The post Meta Settles Child Privacy Lawsuit Rapidly appeared first on Daily CyberSecurity.

  • ✇Cybersecurity News
  • Mercor Data Breach Targets AI Supply Chain Do Son
    Discover the details of the massive Mercor data breach exposing 4TB of recruiting data for OpenAI, Google, Meta, and Microsoft. Related Posts: Meta Settles Child Privacy Lawsuit Rapidly Exposed Git Repositories Leak Critical Cloud Secrets Take-Two Subpoenas Microsoft and Discord Over GTA VI "Cyberleek" Leaks The post Mercor Data Breach Targets AI Supply Chain appeared first on Daily CyberSecurity.
     
  • ✇Security Affairs
  • Cybercriminals Turn GTA VI Leaks Into Malware Bait Pierluigi Paganini
    A fake 113GB GTA VI build is packed with malware, using massive empty files to hide a tiny malicious payload. GTA VI hype has reached the point where people are volunteering to infect their own computers just to check if a leak is real. Someone on X asked their followers to “take one for the team” and test a 113GB file claiming to be a playable Grand Theft Auto VI build, according to Tom’s Hardware’s reporting. Someone did, and the results were exactly what you’d expect. A user that goes
     

Cybercriminals Turn GTA VI Leaks Into Malware Bait

24 de Agosto de 2026, 14:27

A fake 113GB GTA VI build is packed with malware, using massive empty files to hide a tiny malicious payload.

GTA VI hype has reached the point where people are volunteering to infect their own computers just to check if a leak is real. Someone on X asked their followers to “take one for the team” and test a 113GB file claiming to be a playable Grand Theft Auto VI build, according to Tom’s Hardware’s reporting. Someone did, and the results were exactly what you’d expect.

A user that goes online with the handler @Aidas29506493 analyzed the file and found that it was completely fake and contained malware. Almost all of its 113GB consisted of empty data, with a tiny malicious payload hidden inside.

did some reverse engineering.
it is fully fake and full of viruses pic.twitter.com/An6VnSNTkd

— Aidas (@Aidas29506493) August 22, 2026

“The decompiled bytecode literally contains commands to whitelist the entire C:\ drive in Windows Defender (powershell Add-MpPreference -ExclusionPath %SystemDrive%\) and kill security software (taskkill -f),” The researcher added in a post on X. They also added in another response, “It’s not 100 GB of actual code—it’s just a tiny 50 KB virus padded with 99.99% empty junk (literally endless zeroes).”

It’s not 100 GB of actual code—it’s just a tiny 50 KB virus padded with 99.99% empty junk (literally endless zeroes).

— Aidas (@Aidas29506493) August 22, 2026

The malware became obvious when researchers examined its code. It included commands to exclude the entire C: drive from Windows Defender and shut down other security software. Anyone who ran it could effectively disable their antivirus before the malware launched its next stage. This was not an accidental side effect, it was a deliberate step to prepare the system for further attacks.

This particular fake didn’t appear in a vacuum. According to to the website IGN, that fake GTA 6 downloads have flooded piracy and torrent sites throughout the recent leak wave, riding genuine momentum from a leaker going by CyberLeek, who’s been releasing real gameplay clips and map footage in protest of Rockstar’s digital pre-order plans. That real leak activity is exactly what makes the fake downloads believable, since fans searching for CyberLeek’s actual content are primed to trust whatever else shows up alongside it.

Every time GTA 6 appears in the news because of leaked footage, people quickly share it across Discord, mirror sites and other platforms. This creates the perfect conditions to trick users with fake downloads and phishing pages. With real and fake content mixed together, it becomes harder for users to tell what is safe.

The scams go beyond huge fake game files. Researchers have found fake GTA 6 websites offering Windows installers that use DLL side-loading to run malware. They also found a fake “GTA 6 Mobile” app that redirects users to a domain linked to infostealers and ransomware. Other fake Rockstar Social Club login pages try to steal users’ account credentials.

None of this should be surprising given the numbers involved. Kaspersky separately documented over 19 million attempted downloads of malware disguised as popular game titles across a single year, with GTA, Minecraft, and Call of Duty topping the list of abused brands specifically because of their large, dedicated communities. Big anticipated titles are a magnet for this stuff regardless of whether there’s an active leak cycle happening, and GTA VI right now has both the hype and the leak chaos simultaneously.

There is no legitimate playable build of GTA VI circulating anywhere, full stop. The game launches November 19 on consoles, with a PC version to follow, and the only responsible move for anyone tempted by a torrent claiming otherwise is to close the tab. If the file looks too good to be true and it’s a hundred gigabytes of an unreleased AAA game showing up on a torrent site months early, it’s not a leak, it’s bait.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, GTA VI Leaks)

  • ✇Firewall Daily – The Cyber Express
  • 678,000 People Hit in French Tax Authority Data Breach Samiksha Jain
    A DGFiP cyberattack has exposed sensitive tax and cadastral information after attackers allegedly used stolen credentials to access systems belonging to France's Directorate General of Public Finances. The French Public Finances Directorate said investigations found that data linked to 678,000 individuals and professionals had been consulted and extracted during intrusions in June and July 2026. The DGFiP cyberattack incidents were identified after a malicious actor claimed illegitimate acces
     

678,000 People Hit in French Tax Authority Data Breach

18 de Agosto de 2026, 03:57

DGFiP cyberattack

A DGFiP cyberattack has exposed sensitive tax and cadastral information after attackers allegedly used stolen credentials to access systems belonging to France's Directorate General of Public Finances. The French Public Finances Directorate said investigations found that data linked to 678,000 individuals and professionals had been consulted and extracted during intrusions in June and July 2026. The DGFiP cyberattack incidents were identified after a malicious actor claimed illegitimate access to the French tax authority's information system on August 12 and 13. DGFiP said the intrusions involved the usurpation of identifiers belonging to a DGFiP agent and an authorized third party.

DGFiP Cyberattack Exposed Taxpayer Information

After detecting the intrusions, DGFiP immediately suspended access to the accounts involved. Initial access controls did not identify data theft, which the authority attributed to the sophistication of the attack. A subsequent investigation established that the compromised access points had been used to consult and extract information concerning 678,000 individuals and professionals. The exposed information included reference tax income, family quotient and withholding tax rate for individuals. For businesses, the accessed information included company names and SIREN numbers. Cadastral data, including addresses and property sizes, was also accessed. DGFiP said online accounts belonging to individual and professional users were not compromised, and user IDs and passwords were not affected. The authority notified France's data protection regulator, CNIL, after identifying the data breaches.

Cadastral Data Leak Claim Targets DGFiP

Separately, a hacker using the alias ZeroBytes claimed an attack against DGFiP's Professional Cadastral Data Server (SPDC). According to the claim cited by FrenchBreaches, the alleged extraction contains 252,149 lines of data representing 2,041,778 people, with multiple holders potentially associated with the same property plot. The claimed dataset reportedly includes names, surnames, sex, dates and places of birth, addresses, land identifiers, cadastral sections and parcel numbers, as well as information about rights held on properties. The claim would therefore link individuals to personal information and real estate assets. However, the figures and technical details in this second claim remain allegations by the cybercriminal. The claim that the system could contain information relating to approximately 20 million citizens is also an estimate made by ZeroBytes and does not establish that this number of people was affected.

Investigation Into French Tax Authority Attack Continues

DGFiP said additional security measures were implemented after investigators uncovered new information. These included preventative shutdowns of access to sensitive information systems. Investigations remain underway to determine the precise nature and volume of data extracted and the number of users affected. DGFiP teams are working with France's economic and financial ministries, the High Official for Defence and Security and the National Agency for Information Systems Security, ANSSI. The authority said it will contact affected individuals and professionals directly from the following week by email or letter. Those notifications will identify the information that may have been accessed or extracted and outline any precautionary measures where applicable. DGFiP also said it will file a complaint and provide further information as the investigation progresses. The separate cadastral data breach claim remains subject to confirmation, including the alleged number of affected people, duration of access, methods used to bypass authentication, the full scope of extracted information and whether access remained active when the claim was published. The confirmed DGFiP investigation and the separate ZeroBytes claim therefore present different sets of figures and allegations, with the full scope of the incidents still being determined.
  • ✇Security Affairs
  • Chess.com Leak Exposes 7.3 Million Users – Evidence Points to Scraping Pierluigi Paganini
    7.3 million Chess.com profiles leaked online: the data is genuine, but evidence points to large-scale scraping, not a server breach. Free is a strange price for stolen data, and that’s exactly what makes this listing worth a second look. A 15.5 GB file containing over 7.3 million chess.com user records showed up on two data-leak forums this week, no cost, no ransom demand, just handed out. Ransomnews’s technical analysis confirms the data is real and recent. What it isn’t, on the evidence, i
     

Chess.com Leak Exposes 7.3 Million Users – Evidence Points to Scraping

14 de Agosto de 2026, 05:24

7.3 million Chess.com profiles leaked online: the data is genuine, but evidence points to large-scale scraping, not a server breach.

Free is a strange price for stolen data, and that’s exactly what makes this listing worth a second look. A 15.5 GB file containing over 7.3 million chess.com user records showed up on two data-leak forums this week, no cost, no ransom demand, just handed out. Ransomnews’s technical analysis confirms the data is real and recent. What it isn’t, on the evidence, is a hack.

“The archive is a single 744 MB 7-Zip file that expands to a 15.5 GB tab-separated table: one header row and 7,337,395 records, each with 38 fields. The schema is chess.com-specific throughout. Alongside the obvious identifiers, email, partial email, username, user ID, UUID, first and last name, country, location and locale, it carries platform state: chess title, points, skill level, premium status and label, verification and activation flags, best rating and rating type, official rating, member-since and last-login timestamps.” reads the report published by Ransomnew. “Two fields at the end are the interesting ones. Every record has gam_audiences and audiences_member_of populated, Google Ad Manager audience segments, with values like coach-nudge experiment groups, trial eligibility, lapsed-user cohorts and rating-band targeting. Those are marketing-stack fields, not profile data. They do not appear in chess.com’s public API.”

The file carries email addresses, usernames, real names, countries, chess ratings, subscription tiers, and something odder: internal Google Ad Manager audience tags, the kind of marketing segmentation data that never shows up in chess.com’s public API. Roughly three-quarters of records include an email address. There are no passwords, no password hashes, and no payment data anywhere in the file, which matters a lot for how seriously affected users need to react.

Proving this data is genuine didn’t require touching chess.com’s servers at all. Every account UUID in the file is a version-1 identifier, the kind that embeds the exact timestamp it was generated, and researchers decoded that hidden timestamp across 200,000 sample records to compare it against each account’s registration date. The match rate came back at 100%, which isn’t something anyone could fake without possessing actual chess.com-issued identifiers down to the millisecond.

Three separate details point toward scraping rather than an actual system breach. The data wasn’t captured in one moment, it was stamped across nine consecutive days in daily batches, the pattern of a scheduled collection job rather than a single database dump. About 7.4% of user records appear twice, the same accounts revisited on different days, something that simply doesn’t happen inside a genuine database export.

This has happened to chess.com before, and the company was blunt about it at the time. Back in 2023, a similar leak of 828,000 records surfaced with a nearly identical field structure, and chess.com stated plainly,

“In November 2023 a threat actor published 828,000 chess.com records with a near-identical field set. Chess.com’s response then was unambiguous: as it told Hackread, “This was NOT a data breach.” continues the report. “Our infrastructure, member accounts, and data such as passwords are secure.” The data had been pulled by abusing the platform’s find-friends feature, feeding in externally sourced email addresses to resolve them against accounts. A second scrape affecting roughly 476,000 users followed. This 2026 file is the same technique at roughly nine times the scale.”

That earlier incident came from abusing the platform’s find-friends feature to resolve external email lists against real accounts; this new file looks like the same technique running at roughly nine times the scale.

One detail doesn’t fit a purely public-facing scrape, though. Advertising-audience segment data isn’t something chess.com’s open API exposes, and it appears on every single row in this file, which suggests whoever built this had access to an authenticated or internal-facing endpoint rather than just the public developer tools. That’s the specific question chess.com is best positioned to answer, and it’s the one that actually matters for understanding how this happened.

The account distributing the file, going by V0idix, isn’t monetizing anything here. The same handle has posted dozens of free database dumps across other unrelated companies, building reputation through volume rather than through sales, which fits a collector who harvests and republishes data rather than someone selling access to a fresh intrusion.

None of this means chess.com users should shrug it off just because passwords weren’t exposed. A verified email sitting next to a real name, country, skill rating, and subscription tier is more than enough raw material for a convincing phishing message about a membership renewal or a fair-play dispute. The right response isn’t panicking about a hacked account, it’s treating unexpected chess.com emails with more suspicion than usual and checking whether that same email address has turned up anywhere else, since reused credentials remain the far more dangerous exposure than anything sitting in this particular file.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Chess.com)

  • ✇Security Affairs
  • Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance Records Pierluigi Paganini
    An exposed SISVISA database leaked 102,215 Brazilian health records, exposing IDs, tax data, and regulatory documents without authentication. Researcher Jeremiah Fowler found a publicly accessible database that turned out to belong to SISVISA, Brazil’s Health Surveillance Information System, and alerted ExpressVPN, which later shared the findings with Hackread. The exposed instance held exactly 102,215 files, roughly 79 GB of data, tied to a platform regulators use to track health rules,
     

Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance Records

6 de Agosto de 2026, 13:44

An exposed SISVISA database leaked 102,215 Brazilian health records, exposing IDs, tax data, and regulatory documents without authentication.

Researcher Jeremiah Fowler found a publicly accessible database that turned out to belong to SISVISA, Brazil’s Health Surveillance Information System, and alerted ExpressVPN, which later shared the findings with Hackread.

The exposed instance held exactly 102,215 files, roughly 79 GB of data, tied to a platform regulators use to track health rules, issue licences and manage inspections for hospitals, restaurants and pharmacies. In other words, it wasn’t some forgotten test box in a corner; it was wired into how the state does its job.

“Over 102,000 private records belonging to Brazil’s health surveillance system were left online without passwords or basic encryption.  Security researcher Jeremiah Fowler found this publicly accessible database and alerted cybersecurity firm ExpressVPN, which later shared the details with Hackread.com.” reads the report published by Hackread. “According to Fowler, this open database stored exactly 102,215 files (around 79GB). Further probing revealed that these records belong to Brazil’s Health Surveillance Information System (SISVISA). For your information, this is a crucial platform used by Brazilian health authorities to track public health rules, issue business permits, and manage inspections for hospitals, restaurants, and pharmacies.”

Once inside, Fowler didn’t need exploits or clever tricks. Anyone who knew the URL could browse folders called “backups”, “imports”, “documents” and “uploads” with no login at all. Inside there were full names, home addresses, phone numbers, CPF and CNPJ tax IDs, scans of driver’s licences and federal doctor ID cards, photos of faces and fingerprints, inspection reports, complaint records and compressed backup archives.

This is the kind of data that doesn’t just identify you; it lets someone convincingly pretend to be you. With that in hand, attackers can run phishing and impersonation campaigns, open lines of credit, or plug tax IDs into other breached datasets until something cracks. They can also weaponise the files themselves by adding malware to documents and re-uploading them, or by locking the whole thing and asking for ransom.

During the investigation, Fowler found that the exposed server could be accessed without login credentials, revealing sensitive personal and government documents, including IDs, tax records, photos, and regulatory files.

“Scammers can get quick access to sensitive data like tax numbers or photos of driver’s licenses and trick people or steal funds. They may also download the files, add viruses to them, and put them back online or even lock the whole system and demand ransom to return access.” continues the report.

If you’ve spent years pushing “go digital” inside a public body, this is the flip side. SISVISA replaced slow, paper-based workflows in 2015 and made it much easier to approve applications and track compliance. That speed gain is real, but paper stored in a filing cabinet doesn’t show up in a Shodan scan or get scraped at scale in a weekend.

It’s still not clear whether this instance was run directly by a government team or handed off to a third-party provider. Fowler sent urgent notices to several agencies; public access went away shortly afterwards, but no one ever replied, and there’s no public timeline for how long the data was exposed or who else may have pulled it. That silence is a finding in sé, and not il migliore.

“However, Fowler clarified that it is still unclear if government staff ran this database themselves or hired a third party to do it.” concludes the report. “The researcher sent quick warnings to several government offices after finding the exposed data, and public access was turned off shortly after that. However, no official ever replied to the warnings, so no one knows how long the files were left open or if anyone accessed them already.”

From a defender’s point of view, the scenario is depressingly familiar: a critical system, no authentication, no encryption, and no clear owner who feels personally responsible. The twist here is the domain: health surveillance, with fingerprints and medical regulators in the mix, not just another marketing list. That raises the stakes for fraud and for long-term abuse of identity data.

If you suspect you or your organisation might be in that dataset, you can’t retroactively make it private. What you can do is watch financial accounts more closely, treat unexpected calls and emails that reference tax IDs or licences as hostile by default, and turn on multi-factor authentication wherever it’s available.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, SISVISA)

  • ✇Security Affairs
  • VPN Breach Exposes 58 Million Connection Logs Despite “No-Logs” Claims Pierluigi Paganini
    A breached “no-logs” VPN exposed 58 million connection logs and millions of user, device, and payment records, contradicting its privacy claims. A threat actor on the Altenen cybercrime forum is distributing a 17 GB SQL database claimed to have been stolen from SplitVPN, formerly known as NotVPN, a Russian VPN marketed for bypassing internet censorship. Mysterium’s research team obtained a copy, verified it against the raw dump, and confirmed the numbers: roughly 23.4 million user records, 1
     

VPN Breach Exposes 58 Million Connection Logs Despite “No-Logs” Claims

29 de Julho de 2026, 05:28

A breached “no-logs” VPN exposed 58 million connection logs and millions of user, device, and payment records, contradicting its privacy claims.

A threat actor on the Altenen cybercrime forum is distributing a 17 GB SQL database claimed to have been stolen from SplitVPN, formerly known as NotVPN, a Russian VPN marketed for bypassing internet censorship. Mysterium’s research team obtained a copy, verified it against the raw dump, and confirmed the numbers: roughly 23.4 million user records, 13.6 million device records, 2.6 million payment records, and 58 million connection logs. A VPN that promised zero logs kept tens of millions of them.

“NotVPN’s own marketing promises “No logs or history: We never store your activity or connection logs. 100% privacy guaranteed.” The database contains a table (deviceProxy) that records which device connected to which server, and exactly when — nearly 58 million times, right up to the day of the breach.” states Mysterium’s research team. “No full credit-card numbers were exposed (card data is masked to BIN + last four). But emails, IP addresses, device identifiers, approximate location, subscription status, and recurring-billing tokens were.”

VPN

The timestamps run continuously from June 2025 to July 21, 2026, the day of the dump. These aren’t stale test records. The service was still writing connection logs as it was being breached.

The deviceProxy table structure is simple: which device, which server, what time. That’s a connection log. Cross-referenced with the users table, which holds account emails and last-seen IP addresses, and the device table, which holds hardware identifiers, those 58 million rows are enough to reconstruct who connected, from where, to which server, and when, for tens of millions of people.

“A VPN’s single most important promise is that it doesn’t keep the records that would let anyone reconstruct your activity. NotVPN kept them by the tens of millions.” continues the report.

To be precise: the logs record server connections, not destination websites visited. This is metadata, not full browsing history. But metadata is exactly what “we never store your connection logs” promises not to keep.

The seller lists the user base as concentrated in Russia, Iran, India, and Myanmar. That’s not an arbitrary demographic detail.

“The seller lists the user base as concentrated in Russia, Iran, India, and Myanmar. Look at that list again. These are places where people reach for a VPN specifically to get around state censorship: to read independent news, to use blocked messaging apps, to speak freely. For those users, a leaked email-plus-IP-plus-timestamp record isn’t an abstract privacy nuisance.” continues the report. “It’s a document that ties a real person to the act of evading state controls, sitting in a file now circulating on a criminal forum.”

The payment records include masked card numbers, expiry dates, and recurring billing tokens from the Tinkoff payment gateway. Full card numbers aren’t present, but the linkage between a person’s email, their payment history, and a recurring billing token is enough to cause problems.

The admin table exposes five operator accounts, pavel, valerii, maria, andrei, vladislav, with bcrypt password hashes, roles, and a complete admin action log. Account creation dates run from January to June 2026. The database also contains tables pointing to back-office infrastructure for provisioning App Store accounts, which is the plumbing behind distributing a VPN that Russia has been actively removing from app stores.

Mysterium frames the structural lesson clearly: a conventional VPN is a centralized intermediary where the provider, not the user, decides what gets logged. “No-logs” is an unauditable marketing claim backed by nothing the user can verify. When the provider logs anyway, for billing, anti-fraud, capacity planning, or less benign reasons, the user has no way to know until a 17 GB file with their email shows up on a forum. If you used NotVPN or SplitVPN, treat the associated email address and IP as compromised, change passwords everywhere that email was reused, enable two-factor authentication, and factor into your threat model that connection metadata records now exist outside the operator’s control.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, data leak)

  • ✇Firewall Daily – The Cyber Express
  • Tanaka Dominates Data Leak Landscape With 25 Leak Posts Ashish Khaitan
    Ransomware often dominates cybersecurity headlines, but stolen data has become an equally valuable commodity in the cybercrime economy. In the first half of 2026, one threat actor stood out in the data leak ecosystem: Tanaka, a prolific data leak broker responsible for more publicized leak activity than any other actor tracked by Cyble.  Cyble researchers recorded 367 data breach and leak incidents worldwide between January and June 2026. While dozens of actors participated in selling or publ
     

Tanaka Dominates Data Leak Landscape With 25 Leak Posts

Tanaka

Ransomware often dominates cybersecurity headlines, but stolen data has become an equally valuable commodity in the cybercrime economy. In the first half of 2026, one threat actor stood out in the data leak ecosystem: Tanaka, a prolific data leak broker responsible for more publicized leak activity than any other actor tracked by Cyble.  Cyble researchers recorded 367 data breach and leak incidents worldwide between January and June 2026. While dozens of actors participated in selling or publishing stolen information, Tanaka emerged as the most active, accounting for 25 distinct leak posts — more than double the activity of several other major actors. 

A Data Leak Operation Without Industry Boundaries 

Unlike threat actors that specialize in a single vertical, Tanaka followed a broad targeting approach across multiple industries and regions. The actor’s campaigns showed no strict preference for a specific sector, instead focusing on organizations where stolen information could hold financial or strategic value.  The Banking, Financial Services, and Insurance (BFSI) sector remained the most targeted industry globally, accounting for 38 breach incidents during the reporting period. Financial organizations continue to attract attackers due to the value of customer information, account data, and personally identifiable information (PII).  Government and Technology organizations were also frequent targets, reflecting the wider value of sensitive records, intellectual property, and institutional data. 

Regional Presence Across Major Markets 

Tanaka’s activity was visible across multiple regions. In North America, the actor was responsible for seven leak posts, making it the most active data leak actor in the region alongside other prominent sellers.  Europe and the UK also saw significant activity, with Tanaka linked to six leak posts during H1 2026. The region’s BFSI, Telecommunications, and Retail sectors faced heightened exposure due to the amount of valuable customer and financial data they hold.  The actor’s global footprint demonstrates how modern data leak operations can function independently of geography. Instead of focusing on a single country or industry, operators like Tanaka exploit opportunities wherever valuable information becomes available. 

The Rise of the Data Leak Marketplace 

Tanaka’s activity reflects a broader shift in the cybercrime ecosystem. Data leaks are no longer only a byproduct of ransomware attacks; they have become a standalone business model.  Threat actors monetize stolen information through underground marketplaces, using leaked databases for fraud, extortion, intelligence gathering, or resale. This specialization mirrors other parts of the cybercrime economy, where access brokers, ransomware affiliates, and data sellers perform separate roles.  For organizations, this means a breach does not always begin with a ransomware demand. A stolen database appearing in underground channels may indicate an earlier compromise that requires immediate investigation. 

Staying Ahead of Data Exposure Risks 

Security teams must treat underground data exposure monitoring as part of their broader defense strategy. Identifying leaked credentials, compromised databases, or mentions in cybercrime marketplaces can provide early warning before stolen information is weaponized.  To understand the 2026 data breach landscape, including the most active threat actors, targeted industries, and regional trends, access the full Cyble H1 2026 Cyber Threat Landscape Report. 
  • ✇Security Affairs
  • 24 Billion Stolen Credentials Exposed in Massive Data Leak Pierluigi Paganini
    24 Billion Records Left Open Online: Passwords, Emails, and Everything Else Exposed database with 24 Billion records revealed stolen credentials from infostealers, Telegram channels, and breach collections, risking account takeovers. Cybernews researchers found an exposed Elasticsearch cluster on June 12th containing 24 billion records and more than 8.3 terabytes of data. They triple-checked the numbers. The numbers held up. “The vast majority of the 24 billion exposed records, our res
     

24 Billion Stolen Credentials Exposed in Massive Data Leak

19 de Junho de 2026, 02:09

24 Billion Records Left Open Online: Passwords, Emails, and Everything Else

Exposed database with 24 Billion records revealed stolen credentials from infostealers, Telegram channels, and breach collections, risking account takeovers.

Cybernews researchers found an exposed Elasticsearch cluster on June 12th containing 24 billion records and more than 8.3 terabytes of data. They triple-checked the numbers. The numbers held up.

“The vast majority of the 24 billion exposed records, our researchers believe, were infostealer logs. In other words, stolen usernames, passwords, and services that these credentials were supposed to grant access to.” reads the report published by Cybernews. “The credential data leak is dangerous simply because of its enormous size. Since the data leaked online, billions of affected accounts are at serious risk of takeovers, especially if they are not protected with multi-factor authentication,” the team explained.”

The vast majority of records were infostealer logs: usernames, email addresses, and plaintext passwords, each credential saved separately alongside the URL it was supposed to unlock. Twenty-four billion is not a typo.

The data came from 36 distinct sources. Over 1.7 billion records traced back to Telegram channels, most of them openly involved in cybercrime and trading stolen credentials. More than 30 of the 36 sources were Telegram channels, with records ranging from a few thousand to hundreds of millions each, written in English and Russian.

The biggest chunk, 22.6 billion records, came from what the owner labeled “collections.” That term is deliberately vague.

“A staggering 22.6 billion records supposedly came from what the data owner named “collections.” These records could come from various infostealer collections previously leaked online, or they may indicate that the records are grouped by the services they are supposed to provide unauthorized access to.” continues the report. “Since the data was taken out of public view soon after the discovery, our researchers could not further investigate the origin of the information within the so-called “collection” source.”

24 Billion

Because the database was taken offline shortly after discovery, researchers couldn’t dig further into what’s actually inside those collections.

Interestingly, nearly 260 million records came from Telegram channels with “Darkside” in the name — yes, the same Darkside ransomware group that knocked out the Colonial Pipeline. Another 150 million records came from a source labeled “local database dumps,” which typically means someone downloaded the contents of a live server. Another 146 million came from a “breach compilation combo,” which is exactly what it sounds like: old breach data repackaged because people reuse passwords and rarely change them.

The researchers also found something unusual mixed in: around 17,000 records containing CVE vulnerability IDs with GitHub links, over 5,200 logs of news articles about recent data breaches, and nearly 2,900 logs of social media posts about cybersecurity incidents. One news article in the dataset was published as recently as February 2026.

“One of the vulnerabilities identified in the exposed cluster involved a Valhall GPU Kernel Driver issue.” states Cybernews. “All of this points to the data owner actively monitoring the cybersecurity landscape, with a likely intent to update their vast collection of credentials with records from the latest data breaches and data leaks.”

Someone isn’t just hoarding old data; they’re keeping it current.

The researchers can’t say how many records are duplicates, how old most of the data is, or who owns the database. They also can’t confirm exactly how many people are affected. What they can say is that the database is no longer publicly accessible, which doesn’t help anyone whose password was already in there. If you reuse passwords and don’t have two-factor authentication turned on, that’s the problem worth fixing today.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, 24 Billion data leak)

iFood Confirms Data Breach Affecting 1.2 Million Users in Brazil

iFood confirms a data breach affecting 1.2 million customers in Brazil, while hackers on BreachForums claim the actual theft is much larger.

Instructure Reaches Deal with ShinyHunters to Prevent Canvas Data Leak

Instructure has reached an agreement with the ShinyHunters group to return and destroy stolen Canvas data, protecting millions of student records from a public leak.
❌
❌