Healthcare and pharmaceutical-distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and the theft of data.
McKesson Corporation is an American healthcare company that distributes pharmaceuticals and provides medical supplies, health information technology, and care management tools.
McKesson says it discovered the cybersecurity incident on August 25, 2026, and that its investigation is still in early stages.
“Based on our investigation thus far, including assessments by leading cybersecurity industry experts supporting our response, we’ve confirmed that the unauthorized access to certain third-party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units.”
For now, McKesson provides no information about the amount or nature of the stolen data.
The attack has been claimed by ransomware/extortion group Shiny Hunters. On their leak site the group claims to have stolen hundreds of millions of records containing very sensitive information spanning from Personally Identifiable Information (PII) to Protected Health Information (PHI).
ShinyHunters listing for McKesson Corporation
The ShinyHunters extortion group told BleepingComputer that it was behind the attack, claiming it gained access after conducting voice phishing (or vishing) attacks—a form of social engineering—against multiple McKesson employees. Subsequently, the group said it used compromised Okta single-sign-on accounts to access Salesforce and Snowflake environments. It further claimed to have removed approximately 1 TB of data between August 21 and 25.
The group also said the data includes roughly 284 million records, which does not necessarily mean they belong to 284 million unique patients.
A combination of identity information and healthcare-related details could make affected people targets for convincing scams. Criminals could impersonate a pharmacy, insurer, medical provider, debt collector, or patient-support service and use personal details to make the approach appear legitimate.
Healthcare data is especially useful in social-engineering attacks because it can be used to create a sense of urgency: Criminals could scare a target by sending a supposed prescription problem, unpaid claim, delivery issue, appointment change, or request to “verify” insurance details. At this stage, however, McKesson has not confirmed that any particular category of patient data was accessed.
What to do if you’re affected
While waiting for more information about the nature of the breach and how you might be affected, there are a few things you can do:
Check the company’s advice. Every breach is different, so check with the company to find out what’s happened and follow any specific advice it offers.
Change your password. You can make a stolen password useless to thieves by changing it. Choose a strong password that you don’t use for anything else. Better yet, let a password manager choose one for you.
Enable two-factor authentication (2FA). If you can, use a FIDO2-compliant hardware key, laptop, or phone as your second factor. Some forms of 2FA can be phished just as easily as a password, but 2FA that relies on a FIDO2 device can’t be phished.
Watch out for impersonators. Cybercriminals may contact you posing as the breached company. Check its official website to see if it’s contacting victims, and verify the identity of anyone who contacts you using a different communication channel.
Take your time. Phishing attacks often impersonate people or brands you know and use themes that require urgent attention, such as missed deliveries, account suspensions, and security alerts.
Consider not storing your card details. It’s definitely more convenient to let sites remember your card details, but it increases the risk if a company suffers a breach.
Let’s face it, an incognito window can only do so much.
Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance.
Healthcare technology giant CareCloud has confirmed that a data breach earlier this year impacted more than 3.75 million people, making it one of the largest healthcare data incidents disclosed this year.
The New Jersey-based company, which provides electronic health record (EHR) and practice management services, first flagged the intrusion in an SEC filing back in March, but the true scope only became clear this month when the Department of Health and Human Services (HHS) breach tracker updated the affected total from roughly 345,000 to 3,756,469 individuals.
CareCloud says an unauthorized third party accessed one of its Amazon Web Services (AWS) environments between March 10 and March 16, 2026. The intrusion caused an eight-hour disruption to one of the company’s six EHR environments before systems were restored that same evening. During a forensic investigation, CareCloud determined that the attacker claimed to have exfiltrated data from databases within that environment.
The stolen data reportedly includes both identity and medical information:
Full names, postal addresses, and dates of birth
Social Security numbers (SSNs) and driver’s license or passport numbers
Medical records and health insurance information
Bank account and financial details, plus full credit card data (including CVV) for a limited subset of victims
What affected customers should do
Anyone receiving a breach notification letter should take it seriously, given the combination of medical, identity, and financial data involved.
If you think you’ve been affected by a data breach, here are steps you can take to protect yourself:
Check the company’s advice. Every breach is different, so check with the company to find out what’s happened and follow any specific advice it offers.
Change your password. You can make a stolen password useless to thieves by changing it. Choose a strong password that you don’t use for anything else. Better yet, let a password manager choose one for you.
Enable two-factor authentication (2FA). If you can, use a FIDO2-compliant hardware key, laptop, or phone as your second factor. Some forms of 2FA can be phished just as easily as a password, but 2FA that relies on a FIDO2 device can’t be phished.
Watch out for impersonators. Cybercriminals may contact you posing as the breached company. Check its official website to see if it’s contacting victims, and verify the identity of anyone who contacts you using a different communication channel.
Take your time. Phishing attacks often impersonate people or brands you know and use themes that require urgent attention, such as missed deliveries, account suspensions, and security alerts.
Consider not storing your card details. It’s definitely more convenient to let sites remember your card details, but it increases the risk if a company suffers a breach.
Heights Finance Holdings’ online data breach notification says an unauthorized party accessed a third-party cloud platform containing customer data, potentially exposing highly sensitive personal, banking, and identity information.
Heights Finance is a consumer lender that offers personal installment loans. Reportedly, the company filed a report with Texas regulators mentioning 734,828 affected people, though that figure should not automatically be read as a confirmed nationwide total, since Heights Finance operates dozens of personal loan companies across Alabama, Tennessee, Georgia, Texas, and South Carolina.
The company is associated with the former CURO Management business and related brands. The breach notice covers not only some Heights Finance customers, but potentially people connected to certain current or former CURO-related brands.
On May 7, Heights Finance discovered that an unauthorized party had gained access to a cloud-based platform run by a third party and used to store certain customer information. The company says its investigation found that the intruder may have viewed or copied information in that environment.
Heights says affected people may include:
People who received a loan through Heights Finance.
People who inquired about or applied for a loan product, including through a third party.
Some customers of former parent company CURO Management and its present or former related brands.
What makes the incident especially concerning is the nature of the potentially exposed records, which can include the combination of information criminals need to impersonate someone, target their bank accounts, or create highly convincing phishing attempts.
Breaches happen every day. Don’t be the last to know.
Contact information: Name, home address, phone number, and email address.
Financial information: Account details, bank name, bank account number, routing number, and related financial information.
Government identifiers: Social Security number (SSN), tax identification number, driver’s license number, or state ID number.
Other personal data: Date of birth and personal circumstances voluntarily disclosed during customer service interactions.
The combination of a Social Security number, date of birth, address, and bank account details can create a much more serious risk than a breach exposing only email addresses. It can support identity fraud, financial fraud, account takeover attempts, and tailored social engineering scams.
The personal circumstances customers may have shared with support staff could also make scams more persuasive or potentially more harmful, particularly for people who discussed financial distress, repayment problems, or other sensitive subjects.
What affected customers should do
People who receive a letter from Heights Finance should follow the company’s instructions and enroll in the offered protection service. Exact instructions can be found on Heights Finance’s website.
Since people who were not actual customers could also be affected, there may be some uncertainty about whether someone’s information was included in the data breach. If you believe you fall into one of the listed groups but do not receive a notice, use contact details published by Heights Finance for inquiries. Do not use a number provided in an unexpected email, text, phone call, or even sponsored search result to ask whether your information was involved.
Most of us are wise to phishing emails that don’t contain much personal information. Generic “your account is suspended” messages usually get binned on sight. But what about the phishing emails that use your real name and address, and reference the specific product you bought last month? Even for the most suspicious of people, that can be convincing.
It’s also the situation European Steam hardware buyers walked into this week. On August 10, Valve, the company behind the Steam gaming platform and Steam hardware, warned customers that a cyberattack had exposed names, home addresses, phone numbers, Steam email addresses, and details of their hardware orders.
It wasn’t Valve itself that got hacked. Rather, it was its shipping partner CEVA Logistics, which handles delivery of hardware from the gaming store. Passwords and payment information were not touched.
What got stolen
The attack window ran from July 29 to August 1, 2026. Valve learned about it on August 7 and started notifying customers three days later. CEVA stores delivery data for roughly 90 days after shipment, meaning anyone who received a Steam Deck, Steam Controller, or Steam Machine in Europe over the past three months could be affected.
The exposed information may include:
Name
Street address, postal code, and city
Country
Phone number
Email address linked to the customer’s Steam account
The type and price of the ordered hardware
Exact numbers are still unconfirmed. Neither Valve nor CEVA has said how many customer records were involved. Dutch retailers Bol and De Bijenkorf were reportedly told about the same CEVA incident on August 1 and warned their own customers.
Why shipping data is valuable to scammers
A scammer can send an email, text, or even make a phone call that references your genuine order and delivery address before asking you to pay a small customs or redelivery fee, confirm your delivery, or sign in to “verify” your order.
Data like this is already widely traded online. Malwarebytes researchers found more than 7,500 compromised datasets containing over 8.4 billion records on the dark web during the first six months of 2026.
Not Valve’s first security incident
Although Valve’s own systems weren’t compromised, that doesn’t mean the consequences can’t be severe.
In May 2025, a threat actor called Machine1337 tried to sell what looked like a dataset of 89 million Steam user records for $5,000. The data turned out to be older SMS messages carrying expired two-factor codes, routed through a third-party intermediary Valve says it never partnered with.
Valve has suffered a direct breach in the past though. November 2011 saw one that exposed records from 35 million users, including usernames, emails, and encrypted credit card details.
What affected buyers should do
In an email to customers, Valve advises them to assume that any message referencing their recent Steam hardware order is fake. That covers email, SMS, and phone calls, even the ones that quote your address correctly.
Steam Support never contacts users through email, Steam Chat, or Discord, and only handles account problems through its help page.
So you don’t need to rush to reset your password, although it never hurts to use a strong, unique password and enable Steam Guard’s two-factor authentication. Instead, be skeptical of any unsolicited emails, texts, or calls about a recent Steam hardware delivery, even if they include details only a real customer would know.
Something feel off? Check it before you click.
Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.
Fast-food chain Chick-fil-A is warning customers after attackers hijacked loyalty accounts using stolen passwords in a credential stuffing attack.
Chick-fil-A says it detected suspicious login activity against some Chick-fil-A One accounts in June and launched an investigation. The company later concluded that unauthorized parties ran an automated credential stuffing attack against its website and mobile app between June 17 and June 19, 2026, using usernames and passwords obtained from previous data breaches or other third‑party sources. Chick-fil-A says it reset passwords and ended active sessions for affected accounts while investigating the incident.
Credential stuffing is an attack where criminals take username–password pairs stolen from one service and automatically try them on many other websites and apps to see where they still work. Because many people reuse passwords, attackers often gain access to accounts without ever breaking into the company’s systems in the traditional sense.
So, some may conclude that there are two sides to this. On the one hand, customers who reuse passwords across multiple sites make credential stuffing attacks much more likely to succeed. On the other, companies also have a responsibility to put protections in place to detect and block automated credential stuffing attacks before accounts are compromised.
How it works
To understand how it works, we’ve created a typical scenario:
Cybercriminals obtain large lists of breached credentials from previous data breaches, dark web markets, or public dumps.
They use automated tools to fire those credentials at login endpoints for popular services like retailers, banks, and loyalty programs.
They take over accounts where the credentials still work, then siphon off stored value, personal data, or loyalty rewards, or resell the access to other criminals.
To a victim, this may seem like a breach at the company, but technically speaking, the cybercriminals already had the credentials and were able to enrich their database with additional information about the victims.
What do cybercriminals know about you?
Use Malwarebytes’ free Digital Footprint scan to see whether your personal information has been exposed online.
Chick-fil-A One membership number and mobile pay number.
QR codes associated with the account.
The balance of any Chick-fil-A credit, such as gift cards or rewards on the account.
The last four digits of the stored credit or debit card number.
If you saved more details in your Chick-fil-A One account, attackers may also have seen:
Birthdate (month and day).
Phone number.
Physical address.
Advice for Chick-fil-A customers
The real problem is that, over the years, we’ve designed and adopted a system that no longer works well for most people: passwords. We tell people not to reuse them and to use a password manager to keep track of unique passwords for every account. But for many people, password managers still seem complicated or untrustworthy. I’m afraid the same may turn out to be true for passkeys.
If you have or suspect you had a Chick-fil-A One account, you should act even if you haven’t received a letter.
Set a new, unique password for your Chick-fil-A One account that you do not use anywhere else. And if you’ve used the same password elsewhere, change it on those accounts too.
Turn on multi-factor authentication (MFA) if you haven’t already. Chick-fil-A supports MFA for Chick-fil-A One accounts using a verified mobile phone number.
Be aware that attackers can use the exposed data to craft more convincing phishing messages and scams.
Something feel off? Check it before you click.
Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.
A data breach at Paidwork, a platform that pays people small amounts to complete online microtasks, has exposed personal and financial information of more than 23 million users.
According to public breach reports, the intrusion took place in March 2026, with the stolen database first advertised on a cybercrime forum in April as an 11 GB dump allegedly taken from Paidwork’s production systems.
The exposed data reportedly includes full names, email and home addresses, phone numbers, dates of birth, gender, education details, bank account numbers, transaction records, device and IP information, profile photos, personal interests, and passwords stored as hashes.
That is a lot of sensitive information to hand over to a site that, for many users, pays only a few cents per task.
Why this kind of breach matters
For cybercriminals, a dataset like this is a goldmine for targeted phishing, account takeover, and identity fraud. Banking details and transaction histories can be abused directly, while combinations of email addresses, password hashes, and personal details make credential stuffing and social engineering much easier. Even if passwords were hashed with bcrypt, weak or reused passwords can still be cracked and tried elsewhere.
Many Paidwork users likely signed up with their “throwaway” email and a reused password, thinking the risk was low because the amounts involved were tiny. But attackers do not care how much you earned. They care how much they can make by abusing your data.
Data for pennies, risk for years
More than anything, this breach is a reminder to think critically about who you give your personal information to.
Before you hand over your full name, home address, date of birth, and bank details to a site that pays a few cents per task, ask yourself whether the trade-off is worth it.
If any service wants sensitive data, check what security and privacy commitments it makes, whether it offers meaningful support in case of a breach, and whether you can limit what you share to the minimum needed. When in doubt, keep high-value data like banking details and copies of ID reserved for organizations that genuinely need them and can be held accountable when they fail to protect them.
Check if your data was exposed
While Paidwork has not publicly acknowledged the alleged breach, the stolen data is reportedly circulating in criminal circles, and we have indexed it in our Digital Footprint Scanner so you can check whether your information was exposed.
Use our Digital Footprint Scanner to check whether your email address appears in known breach data, including data associated with this incident. If it does, treat it as a prompt to take action rather than a cause for panic:
Change your password on Paidwork (if you still use the service) and on any other accounts where you reused the same or a similar password.
Enable multi-factor authentication (MFA) wherever possible, especially on email, banking, and other important accounts, and consider using a password manager to generate and store unique passwords for every site.
Monitor bank statements for unexpected withdrawals or suspicious activity.
Be prepared for phishing emails, texts, and phone calls. Cybercriminals can use the leaked information to make their scams more convincing.
Abbott Laboratories, one of the world’s largest healthcare and medical device companies, is investigating two apparently unrelated cyber incidents after confirming unauthorized access to internal systems. While Abbott says there has been no impact on manufacturing, laboratory operations, or patient care, cybercriminal groups ShinyHunters and ShadowByt3$ claim the breaches were far more extensive. Those claims remain unverified at the time of writing and, so far, unsupported by publicly leaked data.
The incidents reportedly involve Abbott’s Cancer Diagnostics business and its LabCentral customer portal for core laboratory diagnostics.
“Abbott is investigating a cyber incident in which there was unauthorized access to a limited number of internal systems in our Cancer Diagnostics business only. This does not impact any business operations, product or product availability, manufacturing or lab operations, or our ability to serve patients.”
Regarding LabCentral, Abbott told reporters that it is an externally hosted portal and that there has been “no known exposure of sensitive customer or business information.”
ShinyHunters told BleepingComputer it stole internal documents, contracts, customer information, more than 22 million doctor‑patient notes, over 20 million medical orders, and more than one million US Social Security numbers, along with personally identifiable information (PII) such as names, addresses, dates of birth, emails, and phone numbers.
On July 18, ShinyHunters gave Abbott until July 21 to respond before leaking the alleged data:
Extended deadline
“This is a final warning to reach out by 21 July 2026 before we leak along with several annoying (digital) problems that’ll come your way. Make the right decision, don’t be the next headline”
The threat of “digital problems” is a familiar one from ShinyHunters. During the Canvas attacks, the group defaced school login pages and the Canvas app with an on‑screen ransom message.
Separately, ShadowByt3$ claims it accessed the LabCentral portal on July 4, using compromised customer credentials plus a “weak point” in the environment, allegedly exfiltrating technical documentation, manufacturing certificates, operating manuals, technical specs, and regulatory docs for Abbott lab systems.
If the attackers’ claims prove accurate, the breach could affect healthcare providers that use Abbott’s diagnostic systems and potentially expose sensitive patient and healthcare data. Abbott, however, says it has found no evidence that sensitive customer or business information was exposed through the LabCentral incident and has not confirmed any patient data was compromised.
What we can reasonably assume to be true
There was a genuine compromise affecting Cancer Diagnostics systems. Abbott has publicly acknowledged unauthorized access and engaged incident response and law enforcement. This doesn’t appear to be a purely “fake” extortion attempt.
There was also a separate cyber incident involving the LabCentral portal. Abbott says the portal primarily hosts public reference material and that it has found no evidence that sensitive customer or business information was exposed.
Both ShinyHunters and ShadowByt3$ have listed Abbott on their extortion sites and have provided narrative details to media outlets, so this is not just generic name‑dropping.
As of the latest reporting, neither group has publicly released samples of the data they claim to have stolen.
What Abbott customers can do
There are some actions you can take if you are, or suspect you may have been, the victim of a data breach.
Check the vendor’s advice. Every breach is different, so check with the vendor to find out what’s happened and follow any specific advice they offer.
Change your password. You can make a stolen password useless to thieves by changing it. Choose a strong password that you don’t use for anything else. Better yet, let a password manager choose and store one for you.
Enable two-factor authentication (2FA). If you can, use a FIDO2-compliant hardware key, laptop, or phone as your second factor. Some forms of 2FA can be phished just as easily as a password. 2FA that relies on a FIDO2 device can’t be phished.
Watch out for impersonation scams. Criminals may contact you pretending to be the company. Check the company’s website to see how it is contacting affected customers, and verify anyone who contacts you using a different communication channel.
Take your time. Phishing attacks often impersonate people or brands you know, and create a false sense of urgency with messages about missed deliveries, suspended accounts, or security alerts.
Consider not storing your card details. It’s definitely more convenient to get sites to remember your card details for you, but we highly recommend not storing that information on websites.
Set up identity monitoring.Identity monitoring alerts you if your personal information is found being traded illegally online and helps you recover if your identity is stolen.
What do cybercriminals know about you?
Use Malwarebytes’ free Digital Footprint scan to see whether your personal information has been exposed online.
Insurance provider AssuranceAmerica has confirmed a data breach affecting the personal information and driver’s license numbers of up to 6.9 million people.
AssuranceAmerica provides car and rental insurance to customers across 14 US states through a network of over 9,500 independent agents.
TechCrunch reports: “AssuranceAmerica said it discovered hackers in its computer systems on March 17. The company concluded its investigation on June 15, finding that the hackers had stolen customers’ names, contact information, and driver’s license numbers.“
The breach notice letter also mentions information about customers’ auto insurance policies and accounts, their drivers and vehicles, and details about customer claims.
AssuranceAmerica has not yet released a public statement about the data breach. However, public breach notices and independent reporting indicate that the incident began with a targeted phishing attack against a single employee. An unauthorized third party accessed parts of the insurer’s IT systems and copied files containing customer policy information and driver’s license numbers. So far, no law‑enforcement or vendor report has publicly linked this activity to a specific threat group, ransomware operation, or nation‑state actor.
No public source has reported a ransom demand, negotiations, or payment, and AssuranceAmerica’s public filings are quiet about any contact with the attackers.
Protecting yourself after a data breach
There are some actions you can take if you are, or suspect you may have been, the victim of a data breach.
Check the vendor’s advice. Every breach is different, so check with the vendor to find out what’s happened and follow any specific advice they offer.
Change your password. You can make a stolen password useless to thieves by changing it. Choose a strong password that you don’t use for anything else. Better yet, let a password manager choose and store one for you.
Enable two-factor authentication (2FA). If you can, use a FIDO2-compliant hardware key, laptop, or phone as your second factor. Some forms of 2FA can be phished just as easily as a password. 2FA that relies on a FIDO2 device can’t be phished.
Watch out for impersonation scams. Criminals may contact you pretending to be the company. Check the company’s website to see how it is contacting affected customers, and verify anyone who contacts you using a different communication channel.
Take your time. Phishing attacks often impersonate people or brands you know, and create a false sense of urgency with messages about missed deliveries, suspended accounts, or security alerts.
Consider not storing your card details. It’s definitely more convenient to get sites to remember your card details for you, but we highly recommend not storing that information on websites.
Set up identity monitoring.Identity monitoring alerts you if your personal information is found being traded illegally online and helps you recover if your identity is stolen.
Check your personal data exposure
You can check whether any of your personal information has been exposed using our Digital Footprint portal. Enter the email address you use most often and we’ll generate a free Digital Footprint report.
Some organizations exist to be exclusive. They’re invite-only, and discreet, the kind of place where the membership directory is the product.
Dialog, the exclusive network founded by billionaire investor and PayPal co-founder Peter Thiel, whose members include a sitting NATO commander, two US senators, and the US Treasury Secretary, is one of those.
Last week, information on hundreds of those members was sitting in plaintext on its app distribution site, visible to anyone who knew how to right-click. Then Dialog said it had been hacked.
A signup page that led straight to members’ files
The site was set up to distribute a phone app to support an upcoming gathering for the network, which arranges high-end get-togethers. Any visitor could sign up using any email address. It did not request a password.
After submitting an email, the visitor landed on a near-empty holding page that reportedly loaded internal files on roughly 200 high-profile people directly into their browser. They were visible using “tools built into every major browser,” which appears to refer to the browser’s built-in developer tools.
Those files were not minimal. Loading the questionnaire forms returned dates of birth, emergency contacts, cell phone numbers, the political leanings Dialog assigns to its members, internal rankings and grading notes, and the digital keys that serve as members’ logins. For nearly all of them, the exposed data was comprehensive, from private contact information through to active login tokens.
The records also included a current White House intelligence official, a retired general who held a senior role in US intelligence, and the heads of national security policy at two leading AI firms. Dialog also privately scores attendees, weighing their wealth and prominence in decisions about admission, seating, and pricing. Those scores were among the things sitting in the public HTML.
Dialog on the defensive
Dialog’s managing director described the access as a hack
“executed by a well-known criminal who is wanted in the United States.”
WIRED, which broke the story, found no evidence that any break-in was required. In fact, it seems to have involved little more than clicking on a link on a web page.
The forms were built using Fillout, a popular online form builder. The data was stored in Airtable, a widely used cloud database platform. Fillout said it was unaware of any compromise to its own systems and noted that customers are responsible for configuring their forms, connected data sources, and workflows.
Dialog has not said when the misconfigured page first went live, meaning members’ data could have been openly accessible for an indeterminate period before it was discovered.
Security misconfiguration now ranks #2 on the OWASP Top 10 for 2025, which is an industry list of the top application security risks. It has risen from #5 in 2021. The category accounts for more than 719,000 of documented security weaknesses.
The fix is also routine: build systems with only the features you need, and configure them securely.
What this means for the rest of us
How organizations describe incidents matters beyond a single breach. If simply accessing publicly available information is routinely labeled a “hack,” security researchers may become more reluctant to investigate and responsibly disclose exposed systems, leaving misconfigurations undiscovered for longer.
For end users, the lesson is older than the internet. If an organization collects your date of birth, your emergency contacts, and a private score of how much you’re worth to them, ask where that data lives. Any answer involving “our website” deserves a second question, and anything that stops at “we take your security very seriously” deserves further questioning.
Most people have heard of the dark web, but few understand what it actually looks like or what goes on there. To separate fact from fiction, our research team spent 48 hours exploring it firsthand and documenting what we found.
The dark web isn’t inherently bad. It also serves legitimate purposes, providing a layer of privacy for journalists, whistleblowers, activists, and others who need to communicate anonymously. Accessing it typically requires the Tor browser, and a number of reputable organizations operate official dark web sites. For example, the BBC’s news website is available through the following Tor address: http://bbcweb3hytmzhn5d532owbu6oqadra5z3ar726vq5kgwwn6aucdccrad.onion
But alongside these legitimate uses is a thriving criminal ecosystem.
What we discovered was an organized, active underground economy that operates in ways most people never imagine. Cybercriminals don’t work alone. They gather in underground cybercrime forums where they discuss emerging attack methods, share techniques, and collaborate on ways to target people around the world.
Think of it less as a dark alley and more as a professional network for cybercriminals.
WWH is a Russian-language community that advertises itself as a meeting place for professionalsMore than 115,000 members on the underground forum Dark Forums, a hub for stolen data and hacking tools
Beyond these forums, we encountered dedicated cybercrime marketplaces. These function like online stores where hackers and fraudsters can buy and sell a range of compromised digital goods, from stolen account credentials to hacking tools, all transacted anonymously using cryptocurrency.
Fun fact: Many of these marketplaces are named after well-known public figures, including US President Donald Trump.
A “Donald Trump Store” ad for stolen credit card data
The dark web compass
Cybercriminals come from every corner of the world, and like any global community, they need a way to find each other. That’s where link boards come in.
Link boards are directories that collect hundreds of underground forums and marketplaces. They’re organized by language, and act as a dark web compass.
A cybercriminal can operate within a community that speaks their native language or join larger English-language forums that attract an international audience.
Not all forums carry the same weight, though. In 2026, the community is largely concentrated around dominant platforms like BreachForums and DarkForums. More exclusive Russian-language forums such as Exploit and XSS tend to attract some of the underground’s more sophisticated cybercriminals.
The Link-Base directory
Compromised data: Your information may already out there
Most people have no idea how much of their personal information is already circulating on the dark web. In many cases, the first challenge is simply knowing whether your information has been exposed at all. You can check yours here.
To understand the scale of the problem, it helps to compare what’s publicly known with what we found beneath the surface.
Publicly reported breaches are only part of the story. Since the beginning of 2026, Malwarebytes researchers have identified more than 7,500 compromised data sets containing over 8.4 billion records. These include data stolen in breaches, harvested through phishing campaigns, scraped from online services, and exposed through misconfigured systems.
Among the organizations affected are household names such as SoundCloud, ADT, Hallmark, Amtrak, Vimeo, and Instagram.
But as significant as those numbers are, they only tell part of the story.
A section of DarkForums dedicated to leaked databases
When we examined the databases section on DarkForums, one of the underground’s most active platforms, we found 63 pages of listings posted since the start of 2026. With 20 listings per page, that’s over 1,200 small and medium-sized data breaches, most of which never made public headlines.
The picture on BreachForums was similar. Since the beginning of the year, the platform has accumulated 37 pages of database listings, each containing 20 entries, adding more than 700 additional compromised databases to the already huge pool of stolen data.
Add it all together, and the publicly reported breaches are only the tip of the iceberg. Much of the stolen personal data traded online changes hands quietly and out of sight.
Typical forum page listing compromised data
US identities for sale
One of the most consistently sought-after commodities in the cybercrime underground is something hackers call “fullz”: a complete package of a real person’s identity information. In 2026, US identities remain especially valuable due to the country’s financial infrastructure, high credit limits, and wide range of services that can be exploited for fraud.
A typical fullz package includes a full name, Social Security Number (SSN), date of birth, address, and other personal details. In the wrong hands, this information is a ready-made toolkit for identity fraud. It allows cybercriminals to open fraudulent credit accounts, file fake tax returns, access financial accounts, or even obtain medical services under someone else’s name.
What makes fullz particularly dangerous is that victims often have no ideatheir identity has been compromised until long after the damage is done. Sometimes that’s months or even years later, when debt collectors come calling or a credit application gets unexpectedly denied.
It’s no surprise that the US remains one of the countries most heavily targeted by identity thieves. More than 1.15 million cases of identity theft were reported to the Federal Trade Commission (FTC) in the first three quarters of 2025 alone, already surpassing the total number reported during all of 2024.
During our research, we came across 9-Digits Market, one of many dark web marketplaces specializing in selling stolen identity data. What stood out was the price. A complete US identity profile was listed for as little as $0.95.
For less than the cost of a cup of coffee, a cybercriminal can buy enough information to devastate someone’s financial life.
9-Digits marketplace selling stolen US identities
How cybercriminals use malware to target your computer
Data breaches aren’t the only way your personal information ends up on the dark web. Sometimes the source is much closer to home: your own computer. During our time on the dark web, we encountered the developers behind a particularly dangerous category of malware known as infostealers, or just “stealers”. The concept is simple, which is partly why it’s so effective.
Once installed, an infostealer silently searches a device for anything valuable. That can include saved usernames and passwords, autofill data, stored payment details, cryptocurrency wallets and other sensitive information. That stolen data is then sent back to the attacker.
Below is a sneak peek at the STORM stealer panel, which compromised a US-based computer and stole 87 username-and-password combinations from the device.
STORM infostealer discovered on a Russian-language cybercrime forumSTORM infostealer management panelSTORM infostealer capabilities
Perhaps the most alarming part is how accessible this type of malware has become. In 2026, any aspiring cybercriminal can rent an infostealer on a subscription basis, requiring little technical knowledge and no major financial investment. Cybercrime-as-a-service has dramatically lowered the barrier to entry.
The STORM infostealer can be rented by cybercriminals
The stolen data is then sold or leaked on underground forums and marketplaces. We were shocked by the sheer volume involved.
On any given day, millions of stolen credentials are shared across these platforms. Behind each of those rows is a real person, completely unaware that their digital life is being picked apart and traded like a commodity.
Datasets of leaked usernames and passwords shared on the dark webCorrelations of leaked usernames and passwords shared on the dark web
Fake investments and cryptocurrency scams
Not all cybercrime revolves around stolen passwords or leaked databases. Some criminals chase much more lucrative payouts through carefully planned social engineering scams. One of the most sophisticated and damaging examples we encountered were crypto investment scams, also known as pig butchering.
The tactic behind it is highly effective. Criminals invest considerable time and effort into building what appears to be a genuine relationship with their target through dating apps, social media, or messaging platforms.
They are patient, friendly, and convincing, slowly earning the victim’s trust over days or even weeks. Only after establishing trust do they introduce what appears to be an exciting investment opportunity. By the time the victim realizes something is wrong, their money is gone and the person they trusted has vanished without a trace.
Active crypto scam operation on a dark web forum
During our research, we observed a large-scale crypto fraud operation already fully up and running, targeting new victims with polished, high-end fake investment platforms specifically designed to keep victims hooked for long periods.
The operation offered:
Full documentation, scripts, and credibility props. Everything needed to appear legitimate from day one.
Carefully crafted communication guides and social engineering playbooks designed to psychologically pressure victims into maxing out credit cards, taking out loans, and repeatedly investing more money.
In-house development teams building fake trading platforms that closely mimic legitimate investment services.
Ongoing scam project on a dark web forum
Our researchers also managed to gain access to one of these fraudulent platforms, and we were unsettled by the level of sophistication.
These are not amateur operations. They are well-funded, professionally run criminal enterprises that treat deception as a business.
Sneak peek into real investment scam project
In just 48 hours, we found stolen identities, malware-for-hire, leaked passwords, and industrial-scale fraud operations. Most people will never visit the dark web, but its effects can still reach them through data breaches, malware infections, and scams.
Malwarebytes helps protect against each of those threats. Our data breach monitoring service alerts you if your personal information appears in a known breach. Identity Theft Protection monitors sensitive information, including your Social Security number, while Scam Guard uses AI-powered detection to help identify suspicious texts, emails, links, and phone numbers before they can cause harm.
The dark web thrives on stolen information. Knowing when your data is exposed is the first step to staying ahead of it.
You can change a password and cancel a card. But replacing a passport or driver’s license number every time someone leaves yours unsecured in a vendor database isn’t so easy.
More than three million Texans are facing that problem after a data breach involving a vendor used by the Texas Parks and Wildlife Department (TPWD) to process hunting and fishing licenses.
In an announcement confirming the breach, TPWD says the hackers gained access through the third-party vendor’s systems and exposed personal information belonging to 3,087,721 people. The agency says the exposed data may include driver’s license information, passport numbers, email addresses, phone numbers, and residential addresses.
However, exactly what information was stolen remains unclear.
Conflicting accounts of what was exposed
In a breach notification filed with the Texas Attorney General’s office, TPWD said the incident affected:
Name of individual
Address
Social Security number information
Driver’s license number
Government-issued ID number (e.g. passport, state ID card)
Date of birth
When we asked them for clarification, TPWD referred us to the same public statement they put on the website, which lists this data as possibly stolen:
Driver license information
Passport numbers (if provided)
Email addresses
Phone numbers
Residential addresses
It explicitly said that Social Security numbers, dates of birth, and financial information, including credit card details, were not included in the incident.
“Social Security numbers, dates of birth and financial information, including credit card details were not obtained from this incident.”
Those two lists don’t tally up, leaving Texans unclear as to exactly what information has been stolen.
TPWD has not identified the third-party vendor involved in the incident. It also declined to answer questions about when it first learned of the breach, how the attackers gained access to the data, or what specific security controls failed.
TPWD did say it is working with the license system vendor to implement increased safeguards. It didn’t say what those safeguards were, though, or exactly how the information was stolen in the first place.
Not the first major Texas data exposure
This isn’t the Texas government’s first data breach rodeo, which matters because criminals often combine data from multiple leaks. Information that seems limited on its own becomes much more useful when paired with other stolen data.
In 2020, software vendor Vertafore exposed records belonging to nearly 28 million Texas drivers by leaving the data in an unsecured external storage service, according to a StateScoop investigation.
In January last year, the Texas Department of Health and Human Services informed people that its employees had been stealing their data. At least 61,000 people were affected, it said at the time, before expanding that number in April to at least 94,000.
The latest breach, and the admission that government IDs were among the stolen data, may also complicate the Texas government’s repeated attempts to introduce digital identity programs. Senate Bill 215, which proposed a state digital ID for citizens, didn’t make it past committee.
If you bought a Texas hunting or fishing license
TPWD has offered affected individuals one year of free credit monitoring through Kroll. Enrollment closes September 14, 2026.
If you may have been affected:
Freeze your credit with Equifax, Experian, and TransUnion to make it harder for identity thieves to open accounts in your name.
Enroll in the Kroll credit monitoring before September 14, 2026.
Watch for phishing emails and texts referencing TPWD, fishing licenses, or the breach itself. Leaked emails and phone numbers are exactly what scammers use next.
Be suspicious of anyone who contacts you unexpectedly and asks you to verify driver’s license, passport, or other personal information.
Whether Texas ever reveals the vendor’s identity remains to be seen. What is certain is that the personal information of more than three million Texans is now in criminal hands.
Your name, address, and phone number are probably already for sale.
Data brokers collect and sell your personal details to anyone willing to pay. Malwarebytes Personal Data Remover finds them and gets your information removed, then keeps watch so it stays that way.
The Eastman Kodak Company (Kodak) confirmed to BleepingComputer that it is investigating a security breach after the ShinyHunters extortion group claimed responsibility for the incident.
Kodak is the latest organization to land on the group’s leak site. ShinyHunters claims it stole more than 2.2 million records and threatened to publish the data unless the company responded by June 18.
“Over 2.2 million records containing customer PII and other internal corporate data was compromised. This is a final warning to reach out by 18 June 2026 before we leak along with several annoying (digital) problems that’ll come your way.”
Kodak has now confirmed a data breach, while also saying the incident was limited in scope, contained, and did not pose a threat to its systems or operations.
ShinyHunters has been busy making the same point across multiple victims: modern extortion is often less about ransomware (encryption) and more about access, stealing valuable data, and applying pressure.
ShinyHunters claims it stole customer information and internal corporate data, but has not publicly provided proof. That’s a common pattern for extortion groups. They make public claims, set a deadline, and use the threat of a data leak to pressure victims before the full facts are known.
Kodak told SecurityWeek that an unauthorized third party gained access to a limited amount of company data, and that the incident appears to have been contained. The company said it brought in external cybersecurity experts, notified law enforcement, and believes there is no threat to its systems or operations.
It’s not yet known how the attackers gained entry to Kodak’s systems, but the extortion group is well-known for social engineering, bribery, and utilizing zero-day vulnerabilities to perform supply-chain attacks. The investigation is ongoing.
How to stay safe
While Kodak works to determine who was affected and exactly what information was accessed, there’s no reason to panic. But there are a few things you can do:
Change the password on your Kodak account and make sure you haven’t reused the same password on other accounts.
Turn on multi-factor authentication (MFA) wherever possible, to ensure that a stolen password is not enough to take over your account.
If you’re in the US, consider placing a credit freeze with Equifax, Experian, and TransUnion. A credit freeze helps prevent identity thieves from opening new accounts in your name by blocking lenders from accessing your credit file.
Depending on the information involved, Kodak may offer affected customers free credit monitoring. Even if it doesn’t, you may want to consider identity monitoring services, which can alert you if your personal information appears in suspicious places or is used to open accounts, apply for credit, or commit fraud.
Check your Digital Footprint regularly to see if your personal details have been exposed.
Cybercriminals often exploit the confusion that follows a breach. They know victims will be expecting emails and updates from the affected company, making phishing messages more convincing.
Monitor Kodak’s official website for updates, and be skeptical of unsolicited emails, texts, or phone calls the reference the incident. Look for inconsistencies, unusual sender addresses, and strange links, and watch out for the two biggest warning signs: pressure to act immediately and requests for money, passwords, or personal information.
Let’s face it, an incognito window can only do so much.
Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance.
A newly discovered database containing 24 billion stolen records is a reminder that personal information from data breaches, phishing campaigns, and infostealer infections continues to circulate online.
The collection was exposed on the internet before being taken offline. While researchers can’t confirm exactly whose information was included, the discovery is a good opportunity to check whether your email addresses, passwords, or other personal data have already been exposed.
What happened?
Researchers at Cybernews found a publicly exposed database holding more than 8.3 TB of data.
The data, consisting of 24 billion credential records, reportedly came from 36 sources, including numerous Telegram channels, prior breach compilations, collections of infostealer logs, and some datasets apparently exported directly from live servers.
Because the data came from different sources there are some differences in what the records contain and how they are organized.
Some records were structured infostealer logs containing usernames, email addresses, and plaintext passwords, and the associated login URL. Infostealers are a type of malware designed to steal sensitive information from infected devices, such as your home computer.
An infostealer log from a single infected device can include passwords stored across all browsers, active session cookies and tokens (including those that bypass multi-factor authentication), autofill data, device fingerprints, and sometimes crypto wallets or messaging accounts. The complete bundle is what ends up in logs such as those seen by the Cybernews researchers.
Roughly 1.7 billion of the records came from hacking-related Telegram channels, mainly English and Russian, including at least one that was focused on stolen credit card data.
The exposed database was hosted on an Elasticsearch cluster. Elasticsearch is a tool used to quickly store and search lots of data. If an Elasticsearch server lacks passwords, authentication, or network restrictions, it can be accessed by anyone who finds it online. Without protections such as passwords or a firewall, anyone can read, copy, change, or even delete its data.
Other documents in the dataset contained information about known vulnerabilities, articles about breaches, and social media posts about cyberattacks. This suggests the owner actively monitors security news and vulnerabilities and enriches the credential hoard with fresh breach information, either for a commercial “monitoring” service or for offensive use.
This newly discovered 24 billion record exposure is in the same league as that previous mega‑dump, but appears more heavily weighted toward fresh infostealer logs, rather than older, static breach data.
Since the data was taken out of public view soon after the discovery, the researchers were unable to fully retrace everything they had found or determine how many duplicate records it contained. That’s reassuring because it reduces the chances of cybercriminals finding the database, but reused passwords may still put accounts at risk. And we still don’t know the purpose for the data collection in the first place.
What to do now
It’s good to be aware of how much information about you is out there and who’s gathering it, but it’s even more important to know exactly which information they have, since that is what they can use against you.
2. If you discover exposed passwords, change them immediately and make sure you aren’t reusing the same password across multiple accounts. Prioritize updating your important accounts such as email, banking, shopping, and social media accounts.
3. Turn on multi-factor authentication (MFA) wherever possible, since it can help protect accounts even if a password has been exposed.
How to protect your data
Infostealers often spread through malicious ads, fake browser updates, and one-click downloads. Avoid clicking sponsored ads, and instead visit official websites directly. Download software only from trusted sources such as official vendor sites or app stores.
Another increasingly popular technique is ClickFix, a social engineering attack that tricks users into infecting their own devices. Never run commands or scripts copied from websites, emails, or messages unless you trust the source and understand what they do.
Pirated software, game cheats, cracked tools, and shady browser extensions remain common sources of infostealer infections. Stick to reputable software and extensions, and be wary of anything asking for excessive permissions.
Lastly, phishing emails are still a major threat. Be cautious of unexpected attachments, links, and urgent requests. If you’re unsure whether a message is legitimate, verify it through the company’s official website rather than the link in the message.
You can also use Malwarebytes Scam Guard to check individual messages. Just upload a screenshot and we’ll let you know if it’s a scam.
Breaches happen every day. Don’t be the last to know.
Cardiac monitoring provider iRhythm has been hit by a data theft followed by an extortion attempt.
In a filing with the Securities and Exchange Commission (SEC), iRhythm revealed it was contacted by someone on June 9 who claimed to have stolen sensitive information, including proprietary data, patient PHI, and other personal information. That person demanded payment in exchange for not publishing the data.
iRhythm provides ambulatory cardiac monitoring and analysis (for example using the Zio patch) and has reportedly processed over two billion hours of heartbeat data from more than twelve million patients.
In the filing, the company said the data was obtained through social engineering and is from “certain third-party-hosted business applications”, without revealing any further details about the amount of data.
On its own website, iRhythm also doesn’t disclose much about the nature of the stolen data, but does seem to imply no financial data was affected:
“We have not identified any impact to our products, our clinical or medical device systems, our connections to customers, our manufacturing and distribution operations, patient safety, or our ability to meet patient needs. In addition, we do not store or retain individual financial account information or payment card information.
As we actively investigate, we will notify individuals affected by this incident in accordance with applicable law and take steps as needed to protect and remediate the impact to them.“
However, the SEC filing adds that iRhythm determined that the incident is significant, “in light of the volume of the potentially affected data.” Together with the extortionist’s claims that they have patients’ medical data, that makes the breach one worth noting if you have used iRhythm’s services.
Even without payment data, healthcare breaches have serious downstream effects:
Attackers can craft highly convincing emails, texts, or calls that reference specific procedures or monitoring episodes (for example, “about your recent Zio patch recording”) to trick patients into sharing more data or paying fake bills.
The breached data can be used to create a fake identity, insurance fraud, or medical identity theft.
Exposure of cardiac and other health‑related information can be deeply sensitive and may have employment/insurance ramifications, especially if data is posted publicly or sold to data brokers.
Healthcare breach data tends to circulate for years, and victims may face sporadic fraud and phishing attempts long after the headlines fade.
How to stay safe
If you’ve used iRhythm’s services, keep an eye on your post, email, and patient portals for official breach notifications from iRhythm or your healthcare provider.
In the US, breaches of protected health information that meet certain criteria must be reported to patients and regulators. iRhythm has promised to “notify individuals affected by this incident in accordance with applicable law and take steps as needed to protect and remediate the impact to them.”
To stay out of the hands of phishers and scammers:
When you receive a communication about the data breach, verify through other channels that it really came from iRhythm. Go directly to iRhythm’s official website or patient portal, or call a known phone number to confirm the communication is genuine.
Be extra suspicious of emails or texts that claim to offer compensation, refunds, or other financial consequences related to this incident.
Change passwords for your iRhythm‑linked portals and your cardiology or hospital patient portals, especially if you reused those passwords elsewhere.
Log into your health insurer’s portal and check claims on a regular basis.
If you see anything suspicious, report it immediately to your insurer and provider and ask them to flag your account for possible identity theft.
Do not provide personal or financial information over the phone just because the caller knows details about you which they may have obtained from the stolen data.
Let’s face it, an incognito window can only do so much.
Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance.
A data breach notice has been filed with the Maine Attorney General, saying more than 2.4 million users of VRChat have had their data breached.
The question is, was it VRChat who filed the breach notice, or did someone pretending to represent the company post it instead? On Reddit, a VRChat representative posted:
VRChat did not submit this Notice of Data Incident, and we have no reason to believe that our systems have been compromised. We are in the process of contacting the Maine Attorney General’s office to have this removed.
The breach notice states that VRChat experienced unauthorized access to some account data between May 10 and May 12, 2026. The access supposedly happened in VRChat’s cloud environment and involved user profile and login-related data.
According to the notice, the information exposed varied by account, but may have included:
VRChat username
Email address associated with the VRChat account
VRChat+ subscription status
Login history, including device information, hardware identifiers, and IP addresses
VRChat is a social platform designed primarily for virtual reality headsets, allowing users to interact with others through user-created 3D avatars and worlds. Users can access VRChat through Steam for PC, the Meta Quest Store, or as an Android app for compatible devices.
The notice states that no passwords or payment card data was exposed. However, even without passwords or card details, there are still potential risks when it comes to other breached data.
Phishing
Cybercriminals may use usernames and email addresses in targeted phishing attempts. For example, users may receive phishing emails or in‑platform messages claiming to be from “Support,” with fake security alerts or prompts to “confirm your age” via a malicious link.
Knowledge of subscription status could make scams more convincing. A scammer could send tailored lures like “billing issue with your subscription” or refund scams, which tend to have higher click-through rates among paying users.
Account takeover
Cybercriminals may combine usernames and email addresses from one breach with passwords stolen in other data breaches and try them against accounts. This technique, known as credential stuffing, takes advantage of people who reuse passwords across multiple sites.
Valuable accounts may then be sold to other players or used for scams.
Identity correlation
Steam and Meta user IDs linked to breached accounts can help cybercriminals connect identities across gaming and social platforms, especially if the same email or profile name is reused.
IP addresses, login history, device information, and other identifiers can also help build a more detailed advertising or tracking profile of a user.
How to stay safe
Whether or not the breach turns out to be an actual breach, here are some steps you can take to protect yourself:
First and foremost, be cautious of emails, texts, or calls claiming to come from VRChat or the gaming platforms you used it on, as cybercriminals often exploit breaches with phishing scams.
Update June 11, 2026: Article was updated to reflect VRChat’s post on Reddit.
Before publishing our original article, we tried to contact VRChat on two separate email addresses but received no meaningful response.
Let’s face it, an incognito window can only do so much.
Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance.
California has sued the former shell of DNA testing company 23andMe over alleged security failures and misleading statements surrounding its 2023 data breach.
On May 27, 2026, Attorney General Rob Bonta filed suit in San Francisco Superior Court against Chrome Holding Co., the company now handling 23andMe’s remaining assets following its bankruptcy.
California’s complaint accuses 23andMe of failing to implement reasonable security measures to protect sensitive data and alleges violations of several state privacy and consumer protection laws. It also accuses the company of making misleading statements about its security practices.
The 2023 breach used old-school credential-stuffing tactics against 23andMe’s login page. Attackers operated inside the systems for roughly five months without anyone noticing. The direct compromise was modest, affecting about 14,000 accounts, but that was all the attackers needed to steal the data of just under seven million customers.
The intruders pivoted from those accounts through DNA Relatives, the platform’s headline feature, which enabled people to determine who they were connected with through DNA similarity. The lawsuit alleges a critical coding error in that feature enabled the perpetrators to scrape data from millions of other users connected by biological kinship.
The victim-blaming defense became evidence
After the breach went public, 23andMe sent victims’ legal representatives a letter blaming users for reusing passwords from sites that had been compromised earlier. The exposed data, the company suggested, had been shared of the users’ own free will and would not cause “pecuniary harm.”
The harms stemming from genetic data theft extend far beyond financial losses, however. The genetic information that was stolen enabled thieves to determine an individual’s genetic origins.
The data was reportedly offered for sale on the dark web with this information as a selling point, enabling sellers to offer records on Asian American Pacific Islander (AAPI) or Jewish customers, for example. Bonta’s office pointed out that antisemitic violence was on the rise at the time.
In spite of the letter’s attempt to blame users, only about 14,000 accounts were directly compromised through password reuse. The rest of the data was allegedly exposed through 23andMe’s own product. According to the complaint, the coding error in DNA Relatives exposed the data of anyone who had opted into the service, not just those linked to the 14,000 compromised accounts.
Can the state recover damages?
California is seeking statutory penalties ranging from $1,000 to $7,500 per violation. With 855,541 Californians among the affected users, the costs could mount up quickly.
The question is how much of it the state will collect if it wins its case. 23andMe filed for Chapter 11 bankruptcy in March 2025, then sold most of its assets, including the genomic data of more than 15 million customers, to TTAM Research Institute, a nonprofit founded by former 23andMe CEO Anne Wojcicki. California and several other states opposed the sale on Genetic Information Privacy Act grounds, but a federal bankruptcy judge approved it. The states are now appealing that decision.
Chrome Holding Co., the corporate shell that remains of 23andMe, received $305 million from that sale. But others have already been picking over what’s left.
Other regulators have already had their turn. The UK Information Commissioner’s Office fined 23andMe £2.31 million in June last year following a joint investigation with the Privacy Commissioner of Canada. A federal court initially approved a $30 million class-action settlement covering most US customer claims. That settlement later grew to $50 million and received final approval in January 2026.
What customers can do
If you tested with 23andMe, the standard breach hygiene still applies. Reset any password you reused on other sites and turn on multi-factor authentication wherever it’s offered. Credential stuffing only works on usernames and passwords that have already been exposed elsewhere. Also watch for phishing attacks that name-drop 23andMe or the breach itself. And maybe weigh the benefits of using DNA testing services against the security risks.
Because there’s one part of this that no fine and no settlement can solve: stolen genetic data sold on the dark web cannot be taken back. Passwords can be changed. DNA can’t.
Browse like no one’s watching.
Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free →
Carnival Corporation, parent of Carnival Cruise Line, is sending out fresh “Notice of Cybersecurity Event” letters dated May 27, 2026. If you feel like you’ve read that sentence before, you’re not imagining things. Over the last decade, the world’s largest cruise operator has accumulated a worrying track record of breaches, ransomware incidents, and regulatory penalties, with this 2026 incident adding yet another entry to an already lengthy cybersecurity history.
There are several data breaches involving Carnival Corporation or one of its subsidiaries in our database.
Between 2019 and 2021 alone, Carnival reported four separate cybersecurity events to the New York Department of Financial Services. These included two ransomware attacks and a phishing incident in which attackers deployed malware, accessed and encrypted internal systems, and stole personal customer and employee information.
In this latest case, an attacker used social engineering to trick a Carnival employee into granting access to part of the company’s IT systems on April 14, 2026. By April 22, they used a compromised account to access a “limited portion” of Carnival’s IT systems, where they were able to copy personal data before being blocked.
According to the data breach notice filed in Maine, a total of 5,995,277 people were affected. Carnival determined that the intruder had illegally copied files containing personal information and is now writing to affected individuals to tell them that “data elements” relating to them were obtained.
Researchers cited by Gblock say the stolen data appears to include:
Full names
Email addresses
Dates of birth
Genders
Mariner Society membership status and tier
Internal customer identifiers
The template letter does not list specific data fields. Instead, it uses a placeholder:
“We have determined that your <<data elements>> were obtained.”
This strongly suggests that Carnival is populating each letter with data categories relevant to that particular individual, a common pattern in large breaches where people may have provided different information at different times.
Furthermore, the letters contain the usual content about the speed with which the company acted, involving third‑party experts, and frame the affected systems as a limited subset of the environment. For recipients, the important fact is not how limited the breach was from the company’s point of view, but whether the exposed information could be used for identity theft, fraud, or highly convincing phishing attacks.
Breaches happen every day. Don’t be the last to know.
We do know from past Carnival incidents that exposed data has included names, addresses, dates of birth, passport numbers, health information, and payment details. In previous breaches affecting cruise lines, compromised data has ranged from basic contact details to Social Security numbers and credit card information. Carnival has not publicly disclosed the full categories of data involved in the 2026 incident, but given that this 2026 event again involves “personal information” copied from internal systems, it is reasonable to treat it as a serious privacy incident, even if the exact mix of data varies per person.
The attack was claimed by extortion group ShinyHunters, which is known to steal data and then ask for a ransom. If the victim does not agree to the terms, the data will be published and/or sold to the highest bidder.
ShinyHunters offers Carnival data for download
From a cybercriminal’s perspective, cruise industry data is highly prized. Cruise passengers are often relatively wealthy, and passenger records can combine identity data (names, addresses, dates of birth, passport numbers), contact data (emails, phone numbers), and potentially payment data (card numbers and sometimes bank details), making them valuable for identity theft, targeted phishing, and fraud.
What to do if you’re affected
To mitigate the fallout, Carnival is offering a complimentary 24‑month TransUnion credit‑monitoring package, delivered via the MyTrueIdentity platform and supported by Cyberscout for fraud assistance.
On August 29, 2024, CISA announced the launch of a new cyber-incident Reporting Portal, part of the new CISA Services Portal.
“The Incident Reporting Portal enables entities and individuals reporting cyber incidents to create unique accounts, save reports and return to submit later, and eliminate the repetitive nature of inputting routine information such as contact information,” says Lauren Boas Hayes, Senior Advisor for Technology & Innovation, at CISA.
Shortly after the announcement, Security Intelligence reported on how the portal was designed and how it differs from other cyber incident reporting structures. We noted that CISA’s biggest advantage was its ability to assist the reporting organization with response and remediation.
“Any organization experiencing a cyberattack or incident should report it — for its own benefit and to help the broader community. CISA and our government partners have unique resources and tools to aid with response and recovery, but we can’t help if we don’t know about an incident,” said CISA Executive Assistant Director for Cybersecurity Jeff Greene in a formal statement covering the portal’s announcement.
Four months later
Since the announcement in August, a lot has happened. There was a presidential election, and a new administration will take charge on January 20. The current CISA director and other political appointees will step down. The agency’s future is uncertain as of this writing, particularly regarding who will oversee it and whether its functions will be divided across different federal departments. Still, it is expected that its work will continue.
Before these changes occur, we wanted to check in with CISA to follow up on the portal’s progress and what the future might look like.
CISA was first created in 2018, but federal agencies have collected cyber incident reports for decades.
“The launch of the Incident Reporting Portal is a significant step forward for CISA’s ability to collect operationally relevant data from reporters in a system which is more usable for reporters,” says Hayes. “The vision for the Incident Reporting Portal is for CISA’s Incident Reporting Portal to continue to enhance the functionality of the system to enable entities to share submitted reports with colleagues or clients to facilitate more effective third-party reporting, communicate directly with CISA, and access information and services relevant to the reporter.”
The portal is expected to make compliance with the Cyber Incident Reporting for Critical Infrastructure Act of 2022 easier. This act will “require CISA to coordinate with Federal partners and others on various cyber incident reporting and ransomware-related activities” across the 16 sectors, agencies and industries deemed “vital to the health, economy and security of the community or region.”
Hayes adds that while reporting under the Cyber Incident Reporting for Critical Infrastructure Act of 2022 will not be required until the Final Rule goes into effect, the agency encourages critical infrastructure owners and operators to voluntarily share information on cyber incidents prior to that date to help prevent other organizations from becoming victims of similar incidents.
“Sharing information allows us to work with our full breadth of partners to help prevent attackers from compromising other victims using the same techniques,” says Hayes. “Sharing information can provide insight into the scale of an adversary’s campaign.”
Why reporting is vital to overall cybersecurity
While reporting cyber incidents to the portal is voluntary at the moment, all organizations are encouraged to share the information. If they feel the need, they can do so anonymously. As cyberattacks and nation-state threats become more sophisticated and increasingly target critical infrastructure industries, sharing this information with CISA allows the agency to help other organizations prepare for emerging threats and implement preventive measures before the damage is done.
“Isolating cyberattacks and preventing them in the future requires the coordination of many groups and organizations,” CISA explained. “By rapidly sharing critical information about attacks and vulnerabilities, the scope and magnitude of cyber events can be greatly decreased.”
And it isn’t just CISA that uses this information. According to the U.S. Government Accountability Office (GAO), 14 federal agencies are responsible for protecting critical infrastructure from cyberattacks, many in unexpected ways. For example, TSA, which handles airport security screening, is also responsible for safeguarding the country’s gasoline pipelines.
“Entities representing critical infrastructure owners and operators told us there are great benefits in getting information about threats from federal agencies,” the GAO reported.
What comes next
Despite a changing presidential administration, CISA is moving forward. It is planning a future designed to keep the critical infrastructure safe from cyber threats, which, in turn, will provide a layer of protection for the nation’s citizens and businesses.
“Sharing information allows us to work with our full breadth of partners so that the attackers can’t use the same techniques on other victims and can provide insight into the scale of an adversary’s campaign,” Jeff Greene was quoted in Federal News Network. “CISA is excited to make available our new portal with improved functionality and features for cyber reporting.”
As for the Incident Reporting Portal’s future, Hayes says, “In the future, we are planning to implement additional features that will take time to develop and incorporate user feedback. Our user experience team is actively working to get feedback on how we can improve the system over time.”