Flat Earth Sun, Moon and Zodiac App
October 15, 2024
•[ leak, misconfiguration, technology ]
In October 2024, the flat earth sun, moon and zodiac app created by Flat Earth Dave was found to be leaking extensive personal information of its users. The data included 33k unique email addresses along with usernames, latitudes and longitudes (their position on the globe) and passwords stored in plain text. A small number of profiles also contained names, dates of birth and genders.
Central Tickets
October 14, 2024
•[ leak ]
Central Tickets confirms a data breach occurred in July 2024.
The Club Penguin Experience
October 14, 2024
•[ leak, technology ]
In October 2024, The Club Penguin Experience (TCPE) suffered a data breach. The incident exposed over 6k subscribers' email addresses alongside usernames, age groups, passwords stored as bcrypt hashes and in some cases, plain text password hints. TCPE sent prompt disclosure notices to impacted customers following the breach.
Game Freak
October 12, 2024
•[ leak, technology ]
Japanese video game developer Game Freak confirms it suffered a cyberattack in August after source code and game designs for unpublished games were leaked online.
Maxar Space Systems
October 11, 2024
•[ hack, leak, manufacturing ]
U.S. satellite maker Maxar Space Systems reveals that threat actors breached its systems and accessed personal data belonging to its employees, the company informs in a notification to impacted individuals.
The Wayback Machine
October 9, 2024
•[ leak, misconfiguration, technology ]
Internet Archive's "The Wayback Machine" suffers a data breach after a threat actor compromised the website and stole a user authentication database containing 31 million unique records.
Healthcare Services Group Inc. (HSGI)
October 7, 2024
•[ hack, leak, healthcare ]
Unauthorized actor accessed HSGI network between 2024-09-27 and 2024-10-03; intrusion discovered on 2024-10-07; data exfiltration confirmed June 2025; notifications issued Aug 2025. No encryption/disruption reported.
Mystic Valley Elder Services
October 5, 2024
•[ leak, healthcare ]
Mystic Valley Elder Services suffers a data breach impacting many individuals.
Universal Music Group
October 3, 2024
•[ leak ]
Universal Music Group informs hundreds of individuals about a recent data breach impacting their personal information.
Switch
October 1, 2024
•[ leak, misconfiguration, technology ]
In October 2024, the Hungarian IT headhunting service Switch inadvertently exposed thousands of customer records via a public GitHub repository. The exposed data contained job applications with names, email addresses and in some cases, commentary on the applicant.
Dell
September 25, 2024
•[ leak, technology ]
The threat actor going by the handle of 'grep' claims to have breached Dell for the third time and leaks 500 MB of sensitive data.
French Citizens
September 25, 2024
•[ leak, misconfiguration, finance ]
In September 2024, over 90M rows of data on French Citizens was found left exposed in a publicly facing database. Compiled from various data breaches, the corpus contained 28M unique email addresses with the various source breaches each exposing different fields including name, physical and IP address, phone number and partial credit card data including payment type and last 4 digits.
Deloitte
September 24, 2024
•[ leak, misconfiguration, technology ]
The threat actor known as IntelBroker announces late last week on the BreachForums cybercrime forum the availability of internal communications obtained from Deloitte, specifically an internet-exposed Apache Solr server that was accessible with default credentials. However the company replies that there is no thret to sensitive data.
U.S. Capitol
September 24, 2024
•[ leak, government ]
The personal information of over 3,000 congressional staffers is leaked on the dark web following a major breach on the U.S. Capitol.
Dell
September 19, 2024
•[ leak, technology ]
Dell confirms to be investigating recent claims that it suffered a data breach after a threat actor dubbed "grep" leaked the data for over 10,000 employees.
Regional Care
September 18, 2024
•[ leak, healthcare ]
Nebraska-based healthcare insurance firm Regional Care discloses a data breach impacting more than 225,000 individuals as a result of an incident identified in mid-September 2024.
Muah.AI
September 17, 2024
•[ leak, technology ]
In September 2024, the "AI girlfriend" website Muah.AI suffered a data breach. The breach exposed 1.9M email addresses alongside prompts to generate AI-based images. Many of the prompts were highly sexual in nature, with many also describing child exploitation scenarios.
Experience Engine
September 16, 2024
•[ leak, technology ]
The threat actor known as IntelBroker claims to have breached the UK-based company Experience Engine, allegedly exposing sensitive data. The hacker is selling the data on an online forum, raising concerns about data security for affected clients and businesses.
Kawasaki Motors Europe
September 13, 2024
•[ ransomware, leak, manufacturing ]
Kawasaki Motors Europe announces that it's recovering from a cyberattack that caused service disruptions as the RansomHub ransomware gang threatens to leak 487 GB of stolen data.
Fortinet
September 12, 2024
•[ leak, misconfiguration, technology ]
Fortinet confirms it suffered a data breach after a threat actor with the moniker of "Fortibitch" claims to have stolen 440GB of files from the company's Microsoft Sharepoint server.