news

Hacker Breach News Today

Data breaches keep reshaping how companies think about security. Articles in this section cover newly disclosed intrusions, the techniques attackers used, the scale of exposed data, and how affected organizations respond, along with lessons defenders can draw from each incident.

Reports here span everything from ransomware crippling large enterprises to leaked credential databases, supply chain compromises, and quiet intrusions discovered months after the fact. Follow-up pieces examine regulatory penalties, class action fallout, and how honestly companies communicate with affected users.

Security teams read breach coverage the way pilots study accident reports, extracting patterns that prevent the next failure. For everyone else, these stories are a reminder of where personal data actually goes, and they often prompt practical steps like enabling stronger authentication.

Canvas online again as ShinyHunters threatens to leak schools’ data
2026-05-08

Instructure's Canvas learning management platform has been restored online following a disruption caused by a confirmed data breach. The ShinyHunters hacking group claimed responsibility for the incident and is threatening to leak sensitive school data if ransom demands are not met.

City Learns Flock Accessed Cameras in Children's Gymnastics Room as a Sales Demo
2026-05-01

Dunwoody, Georgia residents are furious after learning that surveillance firm Flock accessed cameras inside a children's gymnastics room during a sales demonstration. The privacy breach has sparked intense backlash against the city's surveillance contract, prompting citizens to question whether local elected officials actually care about the incident.

4TB of voice samples just stolen from 40k AI contractors at Mercor
2026-04-27

Mercor, a company specializing in AI voice authenticity and deepfake detection, has suffered a data breach resulting in the theft of 4TB of voice samples. The compromised audio data belongs to 40,000 AI contractors whose recordings are used to train and verify the firm's audio forensics infrastructure.

Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
2026-04-23

Bitwarden CLI version 2026.4.0 was compromised after attackers abused a GitHub Action within Bitwarden's CI/CD pipeline. This breach is part of the ongoing Checkmarx supply chain campaign.

French government agency confirms breach as hacker offers to sell data
2026-04-23

France Titres, the French government agency responsible for issuing administrative documents, has confirmed a data breach involving stolen citizen data. The disclosure follows claims from a threat actor who compromised the system and is now offering the stolen information for sale.

The Vercel breach: OAuth attack exposes risk in platform environment variables
2026-04-21

A recent OAuth supply chain compromise at Vercel highlights how trusted third-party applications and platform environment variables can bypass traditional defenses to significantly amplify a breach's impact. This incident underscores the critical need for developers to reassess software supply chain risks and the underlying design tradeoffs of modern PaaS environments.

A Roblox cheat and one AI tool brought down Vercel's platform
2026-04-21

Vercel suffered a significant data breach after an employee at the AI startup Context AI inadvertently installed malware from a Roblox cheat, enabling attackers to exploit an OAuth integration and access internal systems. The incident led to the exfiltration of non-sensitive environment variables and has forced thousands of developers to undertake massive credential rotation efforts. Ultimately, the attack underscores the severe security vulnerabilities introduced by granting broad access permissions to third-party AI productivity tools.

Brussels launched an age checking app. Hackers took 2 minutes to break it
2026-04-20

The European Commission recently launched a new age verification app, claiming the technology was fully prepared for deployment, but cybersecurity experts quickly identified critical flaws. Hackers successfully breached the application in just two minutes, exposing significant security vulnerabilities in the EU digital initiative.

Vercel April 2026 security incident
2026-04-19

Cloud development platform Vercel has disclosed a security incident after threat actors claimed to have breached its systems. The attackers are currently attempting to sell the stolen data.

Vercel says internal systems hit in breach
2026-04-19

Vercel disclosed a security breach impacting its internal systems that came to light on Sunday. The company has brought in an incident response provider to investigate the intrusion, though specific details regarding the scope of the attack remain scarce.

This year’s insane timeline of hacks
2026-04-13

A newly compiled archive details a staggering timeline of major cybersecurity breaches that have largely flown under the radar this year. By documenting these underreported hacks, the collection sheds light on the escalating and often overlooked digital threats facing modern organizations.