<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CyberShitty.com — data breach tracker</title>
  <link>https://cybershitty.com/breaches</link>
  <description>New entries on the 2026 data breach tracker, each with its sources and confirmed-or-claimed status.</description>
  <language>en-in</language>
  <atom:link href="https://cybershitty.com/breaches.xml" rel="self" type="application/rss+xml"/>
  <item>
    <title>Keio Corporation: ransomware (Confirmed)</title>
    <link>https://cybershitty.com/breaches/keio-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/keio-2026</guid>
    <pubDate>Fri, 25 Sep 2026 18:30:00 GMT</pubDate>
    <description>Japanese railway operator confirmed ransomware on group servers that disrupted some group business systems, not trains; data access still under investigation.</description>
  </item>
  <item>
    <title>Renfe (via Adif systems): unknown (Confirmed)</title>
    <link>https://cybershitty.com/breaches/renfe-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/renfe-2026</guid>
    <pubDate>Thu, 24 Sep 2026 18:30:00 GMT</pubDate>
    <description>Spanish rail operator confirmed an attack via compromised Adif servers; names and emails, later ID numbers and encrypted passwords, possibly affected.</description>
  </item>
  <item>
    <title>Times Car (Park24): unknown (Confirmed)</title>
    <link>https://cybershitty.com/breaches/times-car-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/times-car-2026</guid>
    <pubDate>Thu, 24 Sep 2026 18:30:00 GMT</pubDate>
    <description>Park24 confirmed a third party took data from about 6.6M Times Car accounts, including licence images and unrecoverable passwords; card data not leaked.</description>
  </item>
  <item>
    <title>US Department of Defense (Defense Manpower Data Center): vulnerability (Confirmed)</title>
    <link>https://cybershitty.com/breaches/pentagon-dmdc-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/pentagon-dmdc-2026</guid>
    <pubDate>Wed, 23 Sep 2026 18:30:00 GMT</pubDate>
    <description>Unauthorised users reached a DMDC file-sharing server; unencrypted SSNs and service data of 2.76M living and 294,000 deceased people exposed.</description>
  </item>
  <item>
    <title>FBI (FBIJobs.gov portal): vulnerability (Claimed)</title>
    <link>https://cybershitty.com/breaches/fbi-jobs-portal-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/fbi-jobs-portal-2026</guid>
    <pubDate>Mon, 21 Sep 2026 18:30:00 GMT</pubDate>
    <description>ShinyHunters claims staff data theft via a PeopleSoft flaw; FBI confirms only that it is investigating, and its job portals are offline.</description>
  </item>
  <item>
    <title>Revolut: social engineering (Confirmed)</title>
    <link>https://cybershitty.com/breaches/revolut-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/revolut-2026</guid>
    <pubDate>Fri, 11 Sep 2026 18:30:00 GMT</pubDate>
    <description>Revolut handed customer data, including ID documents and statements, to a third party that sent fraudulent requests from a real government email domain.</description>
  </item>
  <item>
    <title>IDScan.net: unknown (Confirmed)</title>
    <link>https://cybershitty.com/breaches/idscan-net-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/idscan-net-2026</guid>
    <pubDate>Mon, 31 Aug 2026 18:30:00 GMT</pubDate>
    <description>ID-verification firm said an unauthorised party may have copied customer names and licence numbers; Krebs tied it to a service selling 153M+ licences.</description>
  </item>
  <item>
    <title>Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF): unknown (Confirmed)</title>
    <link>https://cybershitty.com/post/atf-major-incident-qilin-calea</link>
    <guid isPermaLink="true">https://cybershitty.com/post/atf-major-incident-qilin-calea</guid>
    <pubDate>Wed, 26 Aug 2026 18:30:00 GMT</pubDate>
    <description>ATF confirmed a breach of a standalone CALEA-related system, designated a major incident; Qilin claimed it and posted ~6.3GB of unverified files.</description>
  </item>
  <item>
    <title>Boston Scientific: unknown (Confirmed)</title>
    <link>https://cybershitty.com/post/boston-scientific-cyberattack-guidance</link>
    <guid isPermaLink="true">https://cybershitty.com/post/boston-scientific-cyberattack-guidance</guid>
    <pubDate>Tue, 25 Aug 2026 18:30:00 GMT</pubDate>
    <description>Global disruption from late August; CrowdStrike's findings (22 Sep) say entry was via an external network device, with no evidence data was accessed or taken.</description>
  </item>
  <item>
    <title>Dodo Payments: vulnerability (Confirmed)</title>
    <link>https://cybershitty.com/breaches/dodo-payments-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/dodo-payments-2026</guid>
    <pubDate>Sun, 16 Aug 2026 18:30:00 GMT</pubDate>
    <description>Bengaluru payments firm said attackers used a Metabase flaw to reach an internal analytics system holding some merchant data; a dark-web listing claims more.</description>
  </item>
  <item>
    <title>Aesto Health: unknown (Confirmed)</title>
    <link>https://cybershitty.com/breaches/aesto-health-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/aesto-health-2026</guid>
    <pubDate>Thu, 13 Aug 2026 18:30:00 GMT</pubDate>
    <description>Health-data archiving vendor reported 9,540,683 people to HHS after unauthorised access to its AWS environment in December 2025.</description>
  </item>
  <item>
    <title>CEVA Logistics: unknown (Confirmed)</title>
    <link>https://cybershitty.com/post/ceva-logistics-cyberattack-european-warehouses</link>
    <guid isPermaLink="true">https://cybershitty.com/post/ceva-logistics-cyberattack-european-warehouses</guid>
    <pubDate>Sun, 09 Aug 2026 18:30:00 GMT</pubDate>
    <description>Intrusion from 29 July halted eight European warehouses and exposed shipping data held for clients incl. Bol, De Bijenkorf, ING and Valve.</description>
  </item>
  <item>
    <title>Bank of Baroda: social engineering (Confirmed)</title>
    <link>https://cybershitty.com/post/bank-of-baroda-cyber-incident-data-leak-claims</link>
    <guid isPermaLink="true">https://cybershitty.com/post/bank-of-baroda-cyber-incident-data-leak-claims</guid>
    <pubDate>Mon, 27 Jul 2026 18:30:00 GMT</pubDate>
    <description>Bank disclosed a cyber incident linked to a possible business email compromise after an anonymous claim of data access; ~1TB leak claims are unverified.</description>
  </item>
  <item>
    <title>DentaQuest: data theft (Confirmed)</title>
    <link>https://cybershitty.com/breaches/dentaquest-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/dentaquest-2026</guid>
    <pubDate>Thu, 16 Jul 2026 18:30:00 GMT</pubDate>
    <description>Dental benefits firm began notifying at least 15M people of May network access exposing SSNs, Medicaid/Medicare IDs and dental data.</description>
  </item>
  <item>
    <title>Abbott (Exact Sciences): data theft (Confirmed)</title>
    <link>https://cybershitty.com/breaches/abbott-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/abbott-2026</guid>
    <pubDate>Wed, 15 Jul 2026 18:30:00 GMT</pubDate>
    <description>Abbott confirmed unauthorised access to legacy Exact Sciences cancer-diagnostics systems; ShinyHunters claims 30M customer rows.</description>
  </item>
  <item>
    <title>Reliance Infrastructure (Kudankulam project data): data theft (Confirmed)</title>
    <link>https://cybershitty.com/post/reliance-infrastructure-kudankulam-data-breach</link>
    <guid isPermaLink="true">https://cybershitty.com/post/reliance-infrastructure-kudankulam-data-breach</guid>
    <pubDate>Wed, 15 Jul 2026 18:30:00 GMT</pubDate>
    <description>Reliance confirmed a 'partial breach' of a Yotta-hosted server after files tied to Kudankulam nuclear plant work appeared on a leak site.</description>
  </item>
  <item>
    <title>UMANG (MeitY government services app): vulnerability (Confirmed)</title>
    <link>https://cybershitty.com/breaches/umang-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/umang-2026</guid>
    <pubDate>Mon, 13 Jul 2026 18:30:00 GMT</pubDate>
    <description>Researchers found flaws exposing EPFO UANs, LPG bookings and plaintext Aadhaar numbers via linked services; MeitY said data in affected APIs is now encrypted.</description>
  </item>
  <item>
    <title>National Testing Agency (CUET-UG 2026 candidate data): unknown (Claimed)</title>
    <link>https://cybershitty.com/breaches/national-testing-agency-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/national-testing-agency-2026</guid>
    <pubDate>Tue, 07 Jul 2026 18:30:00 GMT</pubDate>
    <description>MediaNama found about 15.5 lakh CUET-UG 2026 candidate records offered for sale; NTA says it shares data only via DigiLocker and authorised APIs. Origin unclear.</description>
  </item>
  <item>
    <title>AdaptHealth: social engineering (Confirmed)</title>
    <link>https://cybershitty.com/post/adapthealth-breach-4-1-million-patients</link>
    <guid isPermaLink="true">https://cybershitty.com/post/adapthealth-breach-4-1-million-patients</guid>
    <pubDate>Wed, 01 Jul 2026 18:30:00 GMT</pubDate>
    <description>Home medical equipment provider disclosed June data theft via a contractor's session; later reported 4,115,802 people affected to HHS.</description>
  </item>
  <item>
    <title>IDRBT (.bank.in domain registry): vulnerability (Confirmed)</title>
    <link>https://cybershitty.com/breaches/idrbt-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/idrbt-2026</guid>
    <pubDate>Sun, 28 Jun 2026 18:30:00 GMT</pubDate>
    <description>Unauthenticated APIs in the RBI-mandated .bank.in registrar exposed data on 5,576 bank staff for 13+ months; CERT-In said the issue was fixed.</description>
  </item>
  <item>
    <title>LastPass: data theft (Confirmed)</title>
    <link>https://cybershitty.com/breaches/lastpass-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/lastpass-2026</guid>
    <pubDate>Mon, 22 Jun 2026 18:30:00 GMT</pubDate>
    <description>Password manager said support-case data with names and contact details was stolen via the Klue breach; vaults and its own systems unaffected.</description>
  </item>
  <item>
    <title>Bajaj Auto: ransomware (Confirmed)</title>
    <link>https://cybershitty.com/post/bajaj-auto-ransomware-attack</link>
    <guid isPermaLink="true">https://cybershitty.com/post/bajaj-auto-ransomware-attack</guid>
    <pubDate>Mon, 22 Jun 2026 18:30:00 GMT</pubDate>
    <description>Automaker told stock exchanges ransomware hit its systems and tech subsidiary; operations continued and it did not say if data was taken.</description>
  </item>
  <item>
    <title>Tata Electronics: data theft (Confirmed)</title>
    <link>https://cybershitty.com/post/tata-electronics-cyber-incident-world-leaks-claims</link>
    <guid isPermaLink="true">https://cybershitty.com/post/tata-electronics-cyber-incident-world-leaks-claims</guid>
    <pubDate>Sun, 21 Jun 2026 18:30:00 GMT</pubDate>
    <description>Apple and Tesla supplier confirmed a cyber incident after ~630GB (204,000+ files) of alleged company data was posted online.</description>
  </item>
  <item>
    <title>Klue: data theft (Confirmed)</title>
    <link>https://cybershitty.com/breaches/klue-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/klue-2026</guid>
    <pubDate>Thu, 18 Jun 2026 18:30:00 GMT</pubDate>
    <description>Competitive-intel vendor said a 2022 pilot credential was reused to reach customer Salesforce data, hitting LastPass, Jamf and others.</description>
  </item>
  <item>
    <title>Ultrahuman: data theft (Confirmed)</title>
    <link>https://cybershitty.com/breaches/ultrahuman-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/ultrahuman-2026</guid>
    <pubDate>Mon, 01 Jun 2026 18:30:00 GMT</pubDate>
    <description>Wearables maker told users in June that credentials stolen from an employee laptop gave read-only access to contact, purchase and fitness data on 27 March.</description>
  </item>
  <item>
    <title>Pay Tel Communications: misconfiguration (Confirmed)</title>
    <link>https://cybershitty.com/breaches/pay-tel-communications-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/pay-tel-communications-2026</guid>
    <pubDate>Wed, 27 May 2026 18:30:00 GMT</pubDate>
    <description>UpGuard found an open cloud server with 300,000+ callers' IDs at the prison payphone firm; Pay Tel says it closed it by 14 May and only researchers accessed it.</description>
  </item>
  <item>
    <title>Carnival Corporation: social engineering (Confirmed)</title>
    <link>https://cybershitty.com/breaches/carnival-corporation-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/carnival-corporation-2026</guid>
    <pubDate>Tue, 26 May 2026 18:30:00 GMT</pubDate>
    <description>Cruise operator told Maine's AG that just under 6M people had names, contact details, birth dates and state ID numbers exposed after an April attack.</description>
  </item>
  <item>
    <title>UK Visa Portal (third-party visa service): misconfiguration (Claimed)</title>
    <link>https://cybershitty.com/breaches/uk-visa-portal-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/uk-visa-portal-2026</guid>
    <pubDate>Tue, 26 May 2026 18:30:00 GMT</pubDate>
    <description>A private visa-help site exposed at least 100,000 documents incl. passports and selfies via a cloud storage flaw, TechCrunch found.</description>
  </item>
  <item>
    <title>Charter Communications: social engineering (Confirmed)</title>
    <link>https://cybershitty.com/breaches/charter-communications-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/charter-communications-2026</guid>
    <pubDate>Mon, 25 May 2026 18:30:00 GMT</pubDate>
    <description>Charter confirmed a breach; ShinyHunters claims vishing and Salesforce access and 40M records. Charter says no sensitive personal data or CPNI was taken.</description>
  </item>
  <item>
    <title>CBSE (On-Screen Marking portal): vulnerability (Confirmed)</title>
    <link>https://cybershitty.com/breaches/cbse-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/cbse-2026</guid>
    <pubDate>Thu, 21 May 2026 18:30:00 GMT</pubDate>
    <description>Student researchers showed admin access to CBSE's marking portal; CBSE said on 26 May it was a test site, then on 1 June that the vulnerabilities were contained.</description>
  </item>
  <item>
    <title>HDFC Asset Management Company: unknown (Confirmed)</title>
    <link>https://cybershitty.com/breaches/hdfc-asset-management-company-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/hdfc-asset-management-company-2026</guid>
    <pubDate>Sun, 17 May 2026 18:30:00 GMT</pubDate>
    <description>Fund house reported a cyber incident found 16 May; Bombay HC barred use of data the Morpheus group claims to hold. HDFC AMC has not confirmed data loss.</description>
  </item>
  <item>
    <title>Reqrea (Tabiq hotel check-in): misconfiguration (Confirmed)</title>
    <link>https://cybershitty.com/breaches/reqrea-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/reqrea-2026</guid>
    <pubDate>Thu, 14 May 2026 18:30:00 GMT</pubDate>
    <description>A public cloud bucket held over 1M passports, licences and selfies from a hotel check-in system; the firm secured it and is reviewing exposure.</description>
  </item>
  <item>
    <title>Instructure (Canvas): vulnerability (Confirmed)</title>
    <link>https://cybershitty.com/breaches/instructure-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/instructure-2026</guid>
    <pubDate>Thu, 30 Apr 2026 18:30:00 GMT</pubDate>
    <description>Canvas maker confirmed two intrusions exposing usernames, emails, enrolments and messages; it later said it reached an agreement with the attacker.</description>
  </item>
  <item>
    <title>Vercel: data theft (Confirmed)</title>
    <link>https://cybershitty.com/breaches/vercel-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/vercel-2026</guid>
    <pubDate>Sat, 18 Apr 2026 18:30:00 GMT</pubDate>
    <description>Vercel said an attacker took over an employee's Google account via a compromised Context.ai OAuth app and read non-sensitive environment variables.</description>
  </item>
  <item>
    <title>Duales (Duc app): misconfiguration (Confirmed)</title>
    <link>https://cybershitty.com/breaches/duales-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/duales-2026</guid>
    <pubDate>Wed, 01 Apr 2026 18:30:00 GMT</pubDate>
    <description>Toronto money-transfer app left an Amazon storage server of customer licences and passports public; files locked after TechCrunch alert.</description>
  </item>
  <item>
    <title>European Commission: data theft (Confirmed)</title>
    <link>https://cybershitty.com/breaches/european-commission-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/european-commission-2026</guid>
    <pubDate>Thu, 26 Mar 2026 18:30:00 GMT</pubDate>
    <description>The Commission disclosed a breach on 27 March; CERT-EU later said a stolen AWS key from the Trivy supply-chain compromise led to theft of ~92GB of data.</description>
  </item>
  <item>
    <title>CareCloud: data theft (Confirmed)</title>
    <link>https://cybershitty.com/breaches/carecloud-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/carecloud-2026</guid>
    <pubDate>Mon, 23 Mar 2026 18:30:00 GMT</pubDate>
    <description>Health IT firm disclosed a March intrusion into an EHR environment; in August it reported about 3.7M patients' records stolen to HHS.</description>
  </item>
  <item>
    <title>Stryker: unknown (Confirmed)</title>
    <link>https://cybershitty.com/breaches/stryker-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/stryker-2026</guid>
    <pubDate>Tue, 10 Mar 2026 18:30:00 GMT</pubDate>
    <description>Stryker confirmed a global disruption of its Microsoft environment; pro-Iran group Handala claimed it wiped devices and took 50TB of data.</description>
  </item>
  <item>
    <title>Bhavnagar District Co-operative Bank: vulnerability (Confirmed)</title>
    <link>https://cybershitty.com/breaches/bhavnagar-district-co-operative-bank-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/bhavnagar-district-co-operative-bank-2026</guid>
    <pubDate>Tue, 10 Mar 2026 18:30:00 GMT</pubDate>
    <description>Police say the accused changed mobile numbers linked to four accounts and pushed ~1,170 NEFT transfers, siphoning ₹7.34 crore; ₹2.04 crore frozen.</description>
  </item>
  <item>
    <title>FBI (surveillance data system): unknown (Confirmed)</title>
    <link>https://cybershitty.com/breaches/fbi-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/fbi-2026</guid>
    <pubDate>Thu, 05 Mar 2026 18:30:00 GMT</pubDate>
    <description>FBI confirmed intrusion into an unclassified system holding pen-register surveillance returns, exposing targets' phone numbers; later a major incident.</description>
  </item>
  <item>
    <title>DavaIndia Pharmacy (Zota Healthcare): vulnerability (Confirmed)</title>
    <link>https://cybershitty.com/breaches/davaindia-pharmacy-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/davaindia-pharmacy-2026</guid>
    <pubDate>Thu, 12 Feb 2026 18:30:00 GMT</pubDate>
    <description>Insecure admin APIs exposed ~17,000 online orders and control of 883 stores, a researcher disclosed in February; the flaw was fixed in 2025 after a CERT-In report.</description>
  </item>
  <item>
    <title>Crunchbase: unknown (Confirmed)</title>
    <link>https://cybershitty.com/breaches/crunchbase-2026</link>
    <guid isPermaLink="true">https://cybershitty.com/breaches/crunchbase-2026</guid>
    <pubDate>Sun, 25 Jan 2026 18:30:00 GMT</pubDate>
    <description>Crunchbase confirmed documents were exfiltrated from its corporate network; ShinyHunters claims 2M+ records and says it used social engineering.</description>
  </item>
</channel>
</rss>
