Visualização normal

Antes de ontemCybersecurity News
  • ✇Cybersecurity News
  • Trezor Data Breach at ShipMonk Grows to 80,000 Customers Do Son
    The Trezor data breach at shipping partner ShipMonk exposed about 80,000 customers' order data. Wallets are safe, but phishing risk is high. Related Posts: Massive IDScan Data Breach Reported Independent Investigation Reveals 1,200 OpenAI Agents Breached Isolation in Hugging Face Attack JetBrains Cadence Server Compromised The post Trezor Data Breach at ShipMonk Grows to 80,000 Customers appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • JetBrains Cadence Server Compromised Do Son
    An unpatched JetBrains Cadence server exposed cloud infrastructure, AWS credentials, and critical developer secrets. Discover the details of this severe breach. Related Posts: Meta Settles Child Privacy Lawsuit Rapidly Mercor Data Breach Targets AI Supply Chain Exposed Git Repositories Leak Critical Cloud Secrets The post JetBrains Cadence Server Compromised appeared first on Daily CyberSecurity.
     

JetBrains Cadence Server Compromised

Por:Do Son
30 de Agosto de 2026, 23:50

An unpatched JetBrains Cadence server exposed cloud infrastructure, AWS credentials, and critical developer secrets. Discover the details of this severe breach.

Related Posts:

The post JetBrains Cadence Server Compromised appeared first on Daily CyberSecurity.

  • ✇Cybersecurity News
  • Meta Settles Child Privacy Lawsuit Rapidly Do Son
    Discover the details of Meta's massive $18 billion child privacy lawsuit settlement. Learn how new platform restrictions will impact young users worldwide. Related Posts: Mercor Data Breach Targets AI Supply Chain Exposed Git Repositories Leak Critical Cloud Secrets Take-Two Subpoenas Microsoft and Discord Over GTA VI "Cyberleek" Leaks The post Meta Settles Child Privacy Lawsuit Rapidly appeared first on Daily CyberSecurity.
     

Meta Settles Child Privacy Lawsuit Rapidly

Por:Do Son
27 de Agosto de 2026, 05:30

Discover the details of Meta's massive $18 billion child privacy lawsuit settlement. Learn how new platform restrictions will impact young users worldwide.

Related Posts:

The post Meta Settles Child Privacy Lawsuit Rapidly appeared first on Daily CyberSecurity.

  • ✇Cybersecurity News
  • Mercor Data Breach Targets AI Supply Chain Do Son
    Discover the details of the massive Mercor data breach exposing 4TB of recruiting data for OpenAI, Google, Meta, and Microsoft. Related Posts: Meta Settles Child Privacy Lawsuit Rapidly Exposed Git Repositories Leak Critical Cloud Secrets Take-Two Subpoenas Microsoft and Discord Over GTA VI "Cyberleek" Leaks The post Mercor Data Breach Targets AI Supply Chain appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Exposed Git Repositories Leak Critical Cloud Secrets Do Son
    A scan found 28,000 exposed Git repositories leak credentials, API keys, and sensitive files. Learn how to secure your public web servers today. Related Posts: Take-Two Subpoenas Microsoft and Discord Over GTA VI "Cyberleek" Leaks AliExpress Audio Fingerprinting Hijacks Your Bluetooth ChatGPT iMessage Integration: A macOS Privacy Clash The post Exposed Git Repositories Leak Critical Cloud Secrets appeared first on Daily CyberSecurity.
     
  • ✇Security Affairs
  • Cybercriminals Turn GTA VI Leaks Into Malware Bait Pierluigi Paganini
    A fake 113GB GTA VI build is packed with malware, using massive empty files to hide a tiny malicious payload. GTA VI hype has reached the point where people are volunteering to infect their own computers just to check if a leak is real. Someone on X asked their followers to “take one for the team” and test a 113GB file claiming to be a playable Grand Theft Auto VI build, according to Tom’s Hardware’s reporting. Someone did, and the results were exactly what you’d expect. A user that goes
     

Cybercriminals Turn GTA VI Leaks Into Malware Bait

24 de Agosto de 2026, 14:27

A fake 113GB GTA VI build is packed with malware, using massive empty files to hide a tiny malicious payload.

GTA VI hype has reached the point where people are volunteering to infect their own computers just to check if a leak is real. Someone on X asked their followers to “take one for the team” and test a 113GB file claiming to be a playable Grand Theft Auto VI build, according to Tom’s Hardware’s reporting. Someone did, and the results were exactly what you’d expect.

A user that goes online with the handler @Aidas29506493 analyzed the file and found that it was completely fake and contained malware. Almost all of its 113GB consisted of empty data, with a tiny malicious payload hidden inside.

did some reverse engineering.
it is fully fake and full of viruses pic.twitter.com/An6VnSNTkd

— Aidas (@Aidas29506493) August 22, 2026

“The decompiled bytecode literally contains commands to whitelist the entire C:\ drive in Windows Defender (powershell Add-MpPreference -ExclusionPath %SystemDrive%\) and kill security software (taskkill -f),” The researcher added in a post on X. They also added in another response, “It’s not 100 GB of actual code—it’s just a tiny 50 KB virus padded with 99.99% empty junk (literally endless zeroes).”

It’s not 100 GB of actual code—it’s just a tiny 50 KB virus padded with 99.99% empty junk (literally endless zeroes).

— Aidas (@Aidas29506493) August 22, 2026

The malware became obvious when researchers examined its code. It included commands to exclude the entire C: drive from Windows Defender and shut down other security software. Anyone who ran it could effectively disable their antivirus before the malware launched its next stage. This was not an accidental side effect, it was a deliberate step to prepare the system for further attacks.

This particular fake didn’t appear in a vacuum. According to to the website IGN, that fake GTA 6 downloads have flooded piracy and torrent sites throughout the recent leak wave, riding genuine momentum from a leaker going by CyberLeek, who’s been releasing real gameplay clips and map footage in protest of Rockstar’s digital pre-order plans. That real leak activity is exactly what makes the fake downloads believable, since fans searching for CyberLeek’s actual content are primed to trust whatever else shows up alongside it.

Every time GTA 6 appears in the news because of leaked footage, people quickly share it across Discord, mirror sites and other platforms. This creates the perfect conditions to trick users with fake downloads and phishing pages. With real and fake content mixed together, it becomes harder for users to tell what is safe.

The scams go beyond huge fake game files. Researchers have found fake GTA 6 websites offering Windows installers that use DLL side-loading to run malware. They also found a fake “GTA 6 Mobile” app that redirects users to a domain linked to infostealers and ransomware. Other fake Rockstar Social Club login pages try to steal users’ account credentials.

None of this should be surprising given the numbers involved. Kaspersky separately documented over 19 million attempted downloads of malware disguised as popular game titles across a single year, with GTA, Minecraft, and Call of Duty topping the list of abused brands specifically because of their large, dedicated communities. Big anticipated titles are a magnet for this stuff regardless of whether there’s an active leak cycle happening, and GTA VI right now has both the hype and the leak chaos simultaneously.

There is no legitimate playable build of GTA VI circulating anywhere, full stop. The game launches November 19 on consoles, with a PC version to follow, and the only responsible move for anyone tempted by a torrent claiming otherwise is to close the tab. If the file looks too good to be true and it’s a hundred gigabytes of an unreleased AAA game showing up on a torrent site months early, it’s not a leak, it’s bait.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, GTA VI Leaks)

  • ✇Cybersecurity News
  • Take-Two Subpoenas Microsoft and Discord Over GTA VI “Cyberleek” Leaks Do Son
    Take-Two has subpoenaed Microsoft and Discord for account data, IPs, and device IDs tied to "Cyberleek," the source behind a wave of GTA VI gameplay leaks. Related Posts: AliExpress Audio Fingerprinting Hijacks Your Bluetooth ChatGPT iMessage Integration: A macOS Privacy Clash Leaked Corporate AWS Keys Expose Full Admin Rights The post Take-Two Subpoenas Microsoft and Discord Over GTA VI “Cyberleek” Leaks appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • AliExpress Audio Fingerprinting Hijacks Your Bluetooth Do Son
    AliExpress audio fingerprinting uses hidden WebAudio scripts for browser fingerprinting, silently seizing your Bluetooth audio. Learn to block it. Related Posts: Take-Two Subpoenas Microsoft and Discord Over GTA VI "Cyberleek" Leaks ChatGPT iMessage Integration: A macOS Privacy Clash Leaked Corporate AWS Keys Expose Full Admin Rights The post AliExpress Audio Fingerprinting Hijacks Your Bluetooth appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • ChatGPT iMessage Integration: A macOS Privacy Clash Do Son
    Discover how the new ChatGPT iMessage integration on macOS operates. Uncover the severe privacy concerns and Apple's potential security retaliation. Related Posts: Take-Two Subpoenas Microsoft and Discord Over GTA VI "Cyberleek" Leaks AliExpress Audio Fingerprinting Hijacks Your Bluetooth Leaked Corporate AWS Keys Expose Full Admin Rights The post ChatGPT iMessage Integration: A macOS Privacy Clash appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Leaked Corporate AWS Keys Expose Full Admin Rights Do Son
    Truffle Security found leaked corporate AWS keys holding full control. See how leaked corporate AWS keys admin rights expose enterprise cloud accounts. Related Posts: Take-Two Subpoenas Microsoft and Discord Over GTA VI "Cyberleek" Leaks AliExpress Audio Fingerprinting Hijacks Your Bluetooth ChatGPT iMessage Integration: A macOS Privacy Clash The post Leaked Corporate AWS Keys Expose Full Admin Rights appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Sakura Internet Breach Exposes 1.36 Million Customer Accounts Do Son
    Sakura Internet disclosed a breach of its customer management system affecting 1.36 million accounts, though passwords were hashed and salted and no ransom was demanded. Related Posts: Leaked Corporate AWS Keys Expose Full Admin Rights Kimi Work Silently Uploads Five Recent Agent Sessions With Feedback Reports SafePal Data Breach Exposes Order Information of 39,798 Customers The post Sakura Internet Breach Exposes 1.36 Million Customer Accounts appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • SafePal Data Breach Exposes Order Information of 39,798 Customers Do Son
    A SafePal data breach exposed order information for about 39,798 customers via an order-tracking flaw. Wallet funds and keys were not affected. Related Posts: Researchers Rebuild Leaked Tiangou Secure Gateway, Find Great Firewall Ties OpenAI AI Agents Collude to Breach Internal Systems WebKit Flaw Triggers iCloud Private Relay IP Leak The post SafePal Data Breach Exposes Order Information of 39,798 Customers appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Researchers Rebuild Leaked Tiangou Secure Gateway, Find Great Firewall Ties Do Son
    Researchers rebuilt the leaked Tiangou Secure Gateway censorship system from 100,000+ leaked files and found DNS-handling quirks matching the Great Firewall. Related Posts: SafePal Data Breach Exposes Order Information of 39,798 Customers OpenAI AI Agents Collude to Breach Internal Systems WebKit Flaw Triggers iCloud Private Relay IP Leak The post Researchers Rebuild Leaked Tiangou Secure Gateway, Find Great Firewall Ties appeared first on Daily CyberSecurity.
     
  • ✇Firewall Daily – The Cyber Express
  • 678,000 People Hit in French Tax Authority Data Breach Samiksha Jain
    A DGFiP cyberattack has exposed sensitive tax and cadastral information after attackers allegedly used stolen credentials to access systems belonging to France's Directorate General of Public Finances. The French Public Finances Directorate said investigations found that data linked to 678,000 individuals and professionals had been consulted and extracted during intrusions in June and July 2026. The DGFiP cyberattack incidents were identified after a malicious actor claimed illegitimate acces
     

678,000 People Hit in French Tax Authority Data Breach

18 de Agosto de 2026, 03:57

DGFiP cyberattack

A DGFiP cyberattack has exposed sensitive tax and cadastral information after attackers allegedly used stolen credentials to access systems belonging to France's Directorate General of Public Finances. The French Public Finances Directorate said investigations found that data linked to 678,000 individuals and professionals had been consulted and extracted during intrusions in June and July 2026. The DGFiP cyberattack incidents were identified after a malicious actor claimed illegitimate access to the French tax authority's information system on August 12 and 13. DGFiP said the intrusions involved the usurpation of identifiers belonging to a DGFiP agent and an authorized third party.

DGFiP Cyberattack Exposed Taxpayer Information

After detecting the intrusions, DGFiP immediately suspended access to the accounts involved. Initial access controls did not identify data theft, which the authority attributed to the sophistication of the attack. A subsequent investigation established that the compromised access points had been used to consult and extract information concerning 678,000 individuals and professionals. The exposed information included reference tax income, family quotient and withholding tax rate for individuals. For businesses, the accessed information included company names and SIREN numbers. Cadastral data, including addresses and property sizes, was also accessed. DGFiP said online accounts belonging to individual and professional users were not compromised, and user IDs and passwords were not affected. The authority notified France's data protection regulator, CNIL, after identifying the data breaches.

Cadastral Data Leak Claim Targets DGFiP

Separately, a hacker using the alias ZeroBytes claimed an attack against DGFiP's Professional Cadastral Data Server (SPDC). According to the claim cited by FrenchBreaches, the alleged extraction contains 252,149 lines of data representing 2,041,778 people, with multiple holders potentially associated with the same property plot. The claimed dataset reportedly includes names, surnames, sex, dates and places of birth, addresses, land identifiers, cadastral sections and parcel numbers, as well as information about rights held on properties. The claim would therefore link individuals to personal information and real estate assets. However, the figures and technical details in this second claim remain allegations by the cybercriminal. The claim that the system could contain information relating to approximately 20 million citizens is also an estimate made by ZeroBytes and does not establish that this number of people was affected.

Investigation Into French Tax Authority Attack Continues

DGFiP said additional security measures were implemented after investigators uncovered new information. These included preventative shutdowns of access to sensitive information systems. Investigations remain underway to determine the precise nature and volume of data extracted and the number of users affected. DGFiP teams are working with France's economic and financial ministries, the High Official for Defence and Security and the National Agency for Information Systems Security, ANSSI. The authority said it will contact affected individuals and professionals directly from the following week by email or letter. Those notifications will identify the information that may have been accessed or extracted and outline any precautionary measures where applicable. DGFiP also said it will file a complaint and provide further information as the investigation progresses. The separate cadastral data breach claim remains subject to confirmation, including the alleged number of affected people, duration of access, methods used to bypass authentication, the full scope of extracted information and whether access remained active when the claim was published. The confirmed DGFiP investigation and the separate ZeroBytes claim therefore present different sets of figures and allegations, with the full scope of the incidents still being determined.
  • ✇Security Affairs
  • Chess.com Leak Exposes 7.3 Million Users – Evidence Points to Scraping Pierluigi Paganini
    7.3 million Chess.com profiles leaked online: the data is genuine, but evidence points to large-scale scraping, not a server breach. Free is a strange price for stolen data, and that’s exactly what makes this listing worth a second look. A 15.5 GB file containing over 7.3 million chess.com user records showed up on two data-leak forums this week, no cost, no ransom demand, just handed out. Ransomnews’s technical analysis confirms the data is real and recent. What it isn’t, on the evidence, i
     

Chess.com Leak Exposes 7.3 Million Users – Evidence Points to Scraping

14 de Agosto de 2026, 05:24

7.3 million Chess.com profiles leaked online: the data is genuine, but evidence points to large-scale scraping, not a server breach.

Free is a strange price for stolen data, and that’s exactly what makes this listing worth a second look. A 15.5 GB file containing over 7.3 million chess.com user records showed up on two data-leak forums this week, no cost, no ransom demand, just handed out. Ransomnews’s technical analysis confirms the data is real and recent. What it isn’t, on the evidence, is a hack.

“The archive is a single 744 MB 7-Zip file that expands to a 15.5 GB tab-separated table: one header row and 7,337,395 records, each with 38 fields. The schema is chess.com-specific throughout. Alongside the obvious identifiers, email, partial email, username, user ID, UUID, first and last name, country, location and locale, it carries platform state: chess title, points, skill level, premium status and label, verification and activation flags, best rating and rating type, official rating, member-since and last-login timestamps.” reads the report published by Ransomnew. “Two fields at the end are the interesting ones. Every record has gam_audiences and audiences_member_of populated, Google Ad Manager audience segments, with values like coach-nudge experiment groups, trial eligibility, lapsed-user cohorts and rating-band targeting. Those are marketing-stack fields, not profile data. They do not appear in chess.com’s public API.”

The file carries email addresses, usernames, real names, countries, chess ratings, subscription tiers, and something odder: internal Google Ad Manager audience tags, the kind of marketing segmentation data that never shows up in chess.com’s public API. Roughly three-quarters of records include an email address. There are no passwords, no password hashes, and no payment data anywhere in the file, which matters a lot for how seriously affected users need to react.

Proving this data is genuine didn’t require touching chess.com’s servers at all. Every account UUID in the file is a version-1 identifier, the kind that embeds the exact timestamp it was generated, and researchers decoded that hidden timestamp across 200,000 sample records to compare it against each account’s registration date. The match rate came back at 100%, which isn’t something anyone could fake without possessing actual chess.com-issued identifiers down to the millisecond.

Three separate details point toward scraping rather than an actual system breach. The data wasn’t captured in one moment, it was stamped across nine consecutive days in daily batches, the pattern of a scheduled collection job rather than a single database dump. About 7.4% of user records appear twice, the same accounts revisited on different days, something that simply doesn’t happen inside a genuine database export.

This has happened to chess.com before, and the company was blunt about it at the time. Back in 2023, a similar leak of 828,000 records surfaced with a nearly identical field structure, and chess.com stated plainly,

“In November 2023 a threat actor published 828,000 chess.com records with a near-identical field set. Chess.com’s response then was unambiguous: as it told Hackread, “This was NOT a data breach.” continues the report. “Our infrastructure, member accounts, and data such as passwords are secure.” The data had been pulled by abusing the platform’s find-friends feature, feeding in externally sourced email addresses to resolve them against accounts. A second scrape affecting roughly 476,000 users followed. This 2026 file is the same technique at roughly nine times the scale.”

That earlier incident came from abusing the platform’s find-friends feature to resolve external email lists against real accounts; this new file looks like the same technique running at roughly nine times the scale.

One detail doesn’t fit a purely public-facing scrape, though. Advertising-audience segment data isn’t something chess.com’s open API exposes, and it appears on every single row in this file, which suggests whoever built this had access to an authenticated or internal-facing endpoint rather than just the public developer tools. That’s the specific question chess.com is best positioned to answer, and it’s the one that actually matters for understanding how this happened.

The account distributing the file, going by V0idix, isn’t monetizing anything here. The same handle has posted dozens of free database dumps across other unrelated companies, building reputation through volume rather than through sales, which fits a collector who harvests and republishes data rather than someone selling access to a fresh intrusion.

None of this means chess.com users should shrug it off just because passwords weren’t exposed. A verified email sitting next to a real name, country, skill rating, and subscription tier is more than enough raw material for a convincing phishing message about a membership renewal or a fair-play dispute. The right response isn’t panicking about a hacked account, it’s treating unexpected chess.com emails with more suspicion than usual and checking whether that same email address has turned up anywhere else, since reused credentials remain the far more dangerous exposure than anything sitting in this particular file.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Chess.com)

  • ✇Security Affairs
  • Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance Records Pierluigi Paganini
    An exposed SISVISA database leaked 102,215 Brazilian health records, exposing IDs, tax data, and regulatory documents without authentication. Researcher Jeremiah Fowler found a publicly accessible database that turned out to belong to SISVISA, Brazil’s Health Surveillance Information System, and alerted ExpressVPN, which later shared the findings with Hackread. The exposed instance held exactly 102,215 files, roughly 79 GB of data, tied to a platform regulators use to track health rules,
     

Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance Records

6 de Agosto de 2026, 13:44

An exposed SISVISA database leaked 102,215 Brazilian health records, exposing IDs, tax data, and regulatory documents without authentication.

Researcher Jeremiah Fowler found a publicly accessible database that turned out to belong to SISVISA, Brazil’s Health Surveillance Information System, and alerted ExpressVPN, which later shared the findings with Hackread.

The exposed instance held exactly 102,215 files, roughly 79 GB of data, tied to a platform regulators use to track health rules, issue licences and manage inspections for hospitals, restaurants and pharmacies. In other words, it wasn’t some forgotten test box in a corner; it was wired into how the state does its job.

“Over 102,000 private records belonging to Brazil’s health surveillance system were left online without passwords or basic encryption.  Security researcher Jeremiah Fowler found this publicly accessible database and alerted cybersecurity firm ExpressVPN, which later shared the details with Hackread.com.” reads the report published by Hackread. “According to Fowler, this open database stored exactly 102,215 files (around 79GB). Further probing revealed that these records belong to Brazil’s Health Surveillance Information System (SISVISA). For your information, this is a crucial platform used by Brazilian health authorities to track public health rules, issue business permits, and manage inspections for hospitals, restaurants, and pharmacies.”

Once inside, Fowler didn’t need exploits or clever tricks. Anyone who knew the URL could browse folders called “backups”, “imports”, “documents” and “uploads” with no login at all. Inside there were full names, home addresses, phone numbers, CPF and CNPJ tax IDs, scans of driver’s licences and federal doctor ID cards, photos of faces and fingerprints, inspection reports, complaint records and compressed backup archives.

This is the kind of data that doesn’t just identify you; it lets someone convincingly pretend to be you. With that in hand, attackers can run phishing and impersonation campaigns, open lines of credit, or plug tax IDs into other breached datasets until something cracks. They can also weaponise the files themselves by adding malware to documents and re-uploading them, or by locking the whole thing and asking for ransom.

During the investigation, Fowler found that the exposed server could be accessed without login credentials, revealing sensitive personal and government documents, including IDs, tax records, photos, and regulatory files.

“Scammers can get quick access to sensitive data like tax numbers or photos of driver’s licenses and trick people or steal funds. They may also download the files, add viruses to them, and put them back online or even lock the whole system and demand ransom to return access.” continues the report.

If you’ve spent years pushing “go digital” inside a public body, this is the flip side. SISVISA replaced slow, paper-based workflows in 2015 and made it much easier to approve applications and track compliance. That speed gain is real, but paper stored in a filing cabinet doesn’t show up in a Shodan scan or get scraped at scale in a weekend.

It’s still not clear whether this instance was run directly by a government team or handed off to a third-party provider. Fowler sent urgent notices to several agencies; public access went away shortly afterwards, but no one ever replied, and there’s no public timeline for how long the data was exposed or who else may have pulled it. That silence is a finding in sé, and not il migliore.

“However, Fowler clarified that it is still unclear if government staff ran this database themselves or hired a third party to do it.” concludes the report. “The researcher sent quick warnings to several government offices after finding the exposed data, and public access was turned off shortly after that. However, no official ever replied to the warnings, so no one knows how long the files were left open or if anyone accessed them already.”

From a defender’s point of view, the scenario is depressingly familiar: a critical system, no authentication, no encryption, and no clear owner who feels personally responsible. The twist here is the domain: health surveillance, with fingerprints and medical regulators in the mix, not just another marketing list. That raises the stakes for fraud and for long-term abuse of identity data.

If you suspect you or your organisation might be in that dataset, you can’t retroactively make it private. What you can do is watch financial accounts more closely, treat unexpected calls and emails that reference tax IDs or licences as hostile by default, and turn on multi-factor authentication wherever it’s available.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, SISVISA)

  • ✇Security Affairs
  • VPN Breach Exposes 58 Million Connection Logs Despite “No-Logs” Claims Pierluigi Paganini
    A breached “no-logs” VPN exposed 58 million connection logs and millions of user, device, and payment records, contradicting its privacy claims. A threat actor on the Altenen cybercrime forum is distributing a 17 GB SQL database claimed to have been stolen from SplitVPN, formerly known as NotVPN, a Russian VPN marketed for bypassing internet censorship. Mysterium’s research team obtained a copy, verified it against the raw dump, and confirmed the numbers: roughly 23.4 million user records, 1
     

VPN Breach Exposes 58 Million Connection Logs Despite “No-Logs” Claims

29 de Julho de 2026, 05:28

A breached “no-logs” VPN exposed 58 million connection logs and millions of user, device, and payment records, contradicting its privacy claims.

A threat actor on the Altenen cybercrime forum is distributing a 17 GB SQL database claimed to have been stolen from SplitVPN, formerly known as NotVPN, a Russian VPN marketed for bypassing internet censorship. Mysterium’s research team obtained a copy, verified it against the raw dump, and confirmed the numbers: roughly 23.4 million user records, 13.6 million device records, 2.6 million payment records, and 58 million connection logs. A VPN that promised zero logs kept tens of millions of them.

“NotVPN’s own marketing promises “No logs or history: We never store your activity or connection logs. 100% privacy guaranteed.” The database contains a table (deviceProxy) that records which device connected to which server, and exactly when — nearly 58 million times, right up to the day of the breach.” states Mysterium’s research team. “No full credit-card numbers were exposed (card data is masked to BIN + last four). But emails, IP addresses, device identifiers, approximate location, subscription status, and recurring-billing tokens were.”

VPN

The timestamps run continuously from June 2025 to July 21, 2026, the day of the dump. These aren’t stale test records. The service was still writing connection logs as it was being breached.

The deviceProxy table structure is simple: which device, which server, what time. That’s a connection log. Cross-referenced with the users table, which holds account emails and last-seen IP addresses, and the device table, which holds hardware identifiers, those 58 million rows are enough to reconstruct who connected, from where, to which server, and when, for tens of millions of people.

“A VPN’s single most important promise is that it doesn’t keep the records that would let anyone reconstruct your activity. NotVPN kept them by the tens of millions.” continues the report.

To be precise: the logs record server connections, not destination websites visited. This is metadata, not full browsing history. But metadata is exactly what “we never store your connection logs” promises not to keep.

The seller lists the user base as concentrated in Russia, Iran, India, and Myanmar. That’s not an arbitrary demographic detail.

“The seller lists the user base as concentrated in Russia, Iran, India, and Myanmar. Look at that list again. These are places where people reach for a VPN specifically to get around state censorship: to read independent news, to use blocked messaging apps, to speak freely. For those users, a leaked email-plus-IP-plus-timestamp record isn’t an abstract privacy nuisance.” continues the report. “It’s a document that ties a real person to the act of evading state controls, sitting in a file now circulating on a criminal forum.”

The payment records include masked card numbers, expiry dates, and recurring billing tokens from the Tinkoff payment gateway. Full card numbers aren’t present, but the linkage between a person’s email, their payment history, and a recurring billing token is enough to cause problems.

The admin table exposes five operator accounts, pavel, valerii, maria, andrei, vladislav, with bcrypt password hashes, roles, and a complete admin action log. Account creation dates run from January to June 2026. The database also contains tables pointing to back-office infrastructure for provisioning App Store accounts, which is the plumbing behind distributing a VPN that Russia has been actively removing from app stores.

Mysterium frames the structural lesson clearly: a conventional VPN is a centralized intermediary where the provider, not the user, decides what gets logged. “No-logs” is an unauditable marketing claim backed by nothing the user can verify. When the provider logs anyway, for billing, anti-fraud, capacity planning, or less benign reasons, the user has no way to know until a 17 GB file with their email shows up on a forum. If you used NotVPN or SplitVPN, treat the associated email address and IP as compromised, change passwords everywhere that email was reused, enable two-factor authentication, and factor into your threat model that connection metadata records now exist outside the operator’s control.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, data leak)

  • ✇Firewall Daily – The Cyber Express
  • Tanaka Dominates Data Leak Landscape With 25 Leak Posts Ashish Khaitan
    Ransomware often dominates cybersecurity headlines, but stolen data has become an equally valuable commodity in the cybercrime economy. In the first half of 2026, one threat actor stood out in the data leak ecosystem: Tanaka, a prolific data leak broker responsible for more publicized leak activity than any other actor tracked by Cyble.  Cyble researchers recorded 367 data breach and leak incidents worldwide between January and June 2026. While dozens of actors participated in selling or publ
     

Tanaka Dominates Data Leak Landscape With 25 Leak Posts

Tanaka

Ransomware often dominates cybersecurity headlines, but stolen data has become an equally valuable commodity in the cybercrime economy. In the first half of 2026, one threat actor stood out in the data leak ecosystem: Tanaka, a prolific data leak broker responsible for more publicized leak activity than any other actor tracked by Cyble.  Cyble researchers recorded 367 data breach and leak incidents worldwide between January and June 2026. While dozens of actors participated in selling or publishing stolen information, Tanaka emerged as the most active, accounting for 25 distinct leak posts — more than double the activity of several other major actors. 

A Data Leak Operation Without Industry Boundaries 

Unlike threat actors that specialize in a single vertical, Tanaka followed a broad targeting approach across multiple industries and regions. The actor’s campaigns showed no strict preference for a specific sector, instead focusing on organizations where stolen information could hold financial or strategic value.  The Banking, Financial Services, and Insurance (BFSI) sector remained the most targeted industry globally, accounting for 38 breach incidents during the reporting period. Financial organizations continue to attract attackers due to the value of customer information, account data, and personally identifiable information (PII).  Government and Technology organizations were also frequent targets, reflecting the wider value of sensitive records, intellectual property, and institutional data. 

Regional Presence Across Major Markets 

Tanaka’s activity was visible across multiple regions. In North America, the actor was responsible for seven leak posts, making it the most active data leak actor in the region alongside other prominent sellers.  Europe and the UK also saw significant activity, with Tanaka linked to six leak posts during H1 2026. The region’s BFSI, Telecommunications, and Retail sectors faced heightened exposure due to the amount of valuable customer and financial data they hold.  The actor’s global footprint demonstrates how modern data leak operations can function independently of geography. Instead of focusing on a single country or industry, operators like Tanaka exploit opportunities wherever valuable information becomes available. 

The Rise of the Data Leak Marketplace 

Tanaka’s activity reflects a broader shift in the cybercrime ecosystem. Data leaks are no longer only a byproduct of ransomware attacks; they have become a standalone business model.  Threat actors monetize stolen information through underground marketplaces, using leaked databases for fraud, extortion, intelligence gathering, or resale. This specialization mirrors other parts of the cybercrime economy, where access brokers, ransomware affiliates, and data sellers perform separate roles.  For organizations, this means a breach does not always begin with a ransomware demand. A stolen database appearing in underground channels may indicate an earlier compromise that requires immediate investigation. 

Staying Ahead of Data Exposure Risks 

Security teams must treat underground data exposure monitoring as part of their broader defense strategy. Identifying leaked credentials, compromised databases, or mentions in cybercrime marketplaces can provide early warning before stolen information is weaponized.  To understand the 2026 data breach landscape, including the most active threat actors, targeted industries, and regional trends, access the full Cyble H1 2026 Cyber Threat Landscape Report. 
❌
❌