Canadian Investment Regulatory Organization (CIRO)
August 11, 2025
•[ hack, finance ]
Cybersecurity breach at CIRO confirmed Aug 11, 2025. Some personal data of member firms and their registered employees were compromised. CIRO continues core surveillance operations, is investigating impact, will notify affected individuals, and provide mitigation.
74 yr old Bank of America customer
August 10, 2025
•[ financial, hack, malware ]
$70,000 drained from a 74-year-old customer's bank account after hackers infected his computer and added themselves as co-owner, temporarily locking him out; media pressure prompted reimbursement
Kurgan-Telecom
August 10, 2025
•[ hack, ddos, technology ]
On August 10, 2025, Kurgan-Telecom customers in Russia experienced major internet outages due to a distributed denial-of-service (DDoS) attack. The provider limited foreign traffic as a mitigation step; no data was reported stolen or systems encrypted. No group has claimed responsibility.
University of Western Australia
August 9, 2025
•[ hack, education ]
University of Western Australia detected unauthorized access to password data of thousands of staff and students on or around August 9, 2025. As a precaution, all accounts were locked, and passwords reset. There is no evidence any other data was accessed, and no indication of ransomware. Systems have been restored with enhanced security measures.
Scotch College, Melbourne
August 9, 2025
•[ hack, education ]
Scotch Colleges IT systems were accessed by an unknown third party over the weekend of August 910, 2025. The school shut down servers, disabled accounts, and enlisted forensic and ACSC support. In a letter, they apologized to families and alumni for the breach and warned to be vigilant pending the completion of investigations.
University of Southeastern Philippines
August 9, 2025
•[ hack, leak, education ]
Unauthorized access to student records system; ~175,000 records including student ID, name, email, enrollment status, academic monitoring records; data put up for sale; USeP responded by suspending system, migrating servers, enhancing security
Plex Inc
August 9, 2025
•[ hack, leak, technology ]
Plex reported an intrusion into one database leading to theft of a subset of customer authentication data (emails, usernames, securely hashed passwords). Plex urged password resets, recommended signing out all devices, and enabling 2FA; no credit-card data was affected.
Multiple Crypto Users
August 9, 2025
•[ financial, hack, malware ]
Malicious updates to popular npm packages deployed credential/wallet-stealing malware impacting crypto/DeFi users; community advisories urged halting transactions and rotating secrets; maintainers removed tainted packages; early losses ~$900$1,043 total.
Npm ecosystem
August 9, 2025
•[ phishing, malware, hack ]
Phished npm maintainer account used to publish trojanized releases of widely used packages; malicious code attempted crypto address swapping. Packages were pulled within ~2 hours, yet reached ~10% of cloud environments; profits remained under $1,000; no confirmed data theft or sustained outages.
1000ua.ru (Russian POW portal)
August 6, 2025
•[ hack, ddos, government ]
On August 6, 2025, immediately after launch, the Russian website 1000ua.ru which published portraits of 1,000 Ukrainian POWs was hit with a DDoS attack. RT attributed the traffic to Ukraine, but no specific group has been identified. The attack caused partial disruption but no data theft or encryption.
Bouygues Telecom
August 4, 2025
•[ hack, technology ]
Bouygues Telecom, Frances third-largest mobile operator, detected a cyberattack on August 4, 2025, which exposed personal and contractual customer data including IBANs for approximately 6.4 million accounts; passwords and payment card details were not compromised.
Bouygues Telecom
August 4, 2025
•[ hack, technology ]
In August 2025, the French telecommunications company Bouygues Telecom detected a cyber attack against their services. The incident resulted in a data breach that exposed almost 6.4M customer records, including 5.7M unique email addresses. The breach also exposed names, physical addresses, phone numbers, dates of birth and IBANs (International Bank Account Numbers). Bouygues Telecom advised that all affected customers had been notified about the incident.
Sevastopol main internet provider (Miranda Media)
August 2, 2025
•[ hack, ddos, technology ]
On August 2, 2025, Sevastopols main internet provider Miranda Media came under a large-scale DDoS attack, causing widespread disruption of mobile and fixed-line connectivity across the city. Services were intermittently unavailable for several days. Officials acknowledged the disruption on August 4, 2025. No group has claimed responsibility.
Qilin ransomware group
July 31, 2025
•[ ransomware, hack, leak ]
Compromise of Qilins affiliate panel by rival actors enabled access to internal systems and stolen victim files.
Ministry of iTaukei Affairs
July 31, 2025
•[ hack, government ]
The Ministry of iTaukei Affairs official Facebook page was hacked again after an April 2025 incident.
Orange Belgium S.A.
July 30, 2025
•[ hack, technology ]
On July 30, 2025, Orange Belgium S.A. suffered a cyberattack that compromised data from approximately 850,000 customers. Exposed information included names, phone numbers, SIM card and PUK codes, and tariff plan details. Passwords, email addresses, and financial information were not affected. The incident was disclosed publicly on August 20, 2025, and is separate from other Orange Group cyber incidents.
TransUnion
July 28, 2025
•[ hack, misconfiguration, finance ]
Unauthorized access via third-party contractor application used in U.S. consumer support operations enabled viewing and copying of files.
Government servers of Russian-occupied Crimea
July 25, 2025
•[ hack, government ]
Ukraines military intelligence agency said it hacked into government servers in Russian-occupied Crimea that allegedly contained evidence of Russias forced deportation of Ukrainian children from occupied territories.
Parliament of Aruba
July 25, 2025
•[ hack, government ]
Parliamentary email systems in Aruba were hacked in late July 2025, compromising official accounts. The attack affected email communications but did not disrupt broader parliamentary operations. No attribution or data theft has been confirmed.
Brightstar Lottery Group
July 24, 2025
•[ hack ]
Unauthorized access to Brightstar Lottery Groups corporate network occurred July 24 2025 and was discovered July 25 2025. The Rhode Island-based vendor notified affected individuals in September after confirming that roughly 550 Connecticut residents personal information was compromised. No operational disruption or encryption reported.