Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

DevaOnBreaches

@DevaOnBreaches@infosec.exchange
  • Open on infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot@infosec.exchange

0 Followers
0 Following
50 Posts
Joined November 24, 2022
Website:
https://XposedOrNot.com
Blog:
https://blog.xposedornot.com/
GitHub:
https://github.com/DevaOnBreaches
Website:
https://plus.xposedornot.com/

Posts

Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · 5d ago
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
Framework says a third-party #databreach impacted all of its customers after hackers exploited a zero-day vulnerability at business intelligence provider Metabase. Exposed data includes names, emails, phone numbers, and physical addresses. Payment information was not compromised. https://techcrunch.com/2026/08/07/computer-maker-framework-notifies-all-customers-of-a-data-breach/
Computer maker Framework notifies 'all customers' of a data breach | TechCrunch
TechCrunch

Computer maker Framework notifies 'all customers' of a data breach | TechCrunch

Framework told "all" of its customers that hackers accessed their names, email addresses, phone numbers, and physical addresses in a data breach.

0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Aug 06, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
A misconfigured database exposed 102,215 records (79GB) from Brazil’s Health Surveillance Information System (SISVISA), including IDs, tax numbers, addresses, inspection reports, and medical credentials. The database was secured after disclosure, but it's unclear how long it was exposed or if the data was accessed. #DataBreach https://hackread.com/brazil-health-surveillance-database-exposed-records/
Brazil Health Surveillance Database Exposed 79GB of Sensitive Records
Hackread - Cybersecurity News, Data Breaches, AI and More

Brazil Health Surveillance Database Exposed 79GB of Sensitive Records

Brazil's SISVISA health surveillance system left 102,215 files totaling 79GB open online, including tax IDs and identity documents, without password protection.

0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Aug 06, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
A cyberattack on the U.K.'s Police National Legal Database (PNLD) exposed the names, organizations, and email addresses of 100,000+ police officers and criminal justice professionals. ExfilSquad claims to have stolen 135,000 records, while authorities investigate. #databreach https://www.bleepingcomputer.com/news/security/exfilsquad-hackers-leak-info-of-over-100-000-uk-police-officers-staff/
ExfilSquad hackers leak info of over 100,000 UK police officers, staff
BleepingComputer

ExfilSquad hackers leak info of over 100,000 UK police officers, staff

A cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals.

0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Aug 03, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
"Free breach monitoring" usually means "we eat the cost until we can't." Here is how @XposedOrNot@infosec.exchange stays free: Google Cloud with Datastore for the breach index, Cloudflare in front for caching and abuse handling, and a codebase you can read end to end. The expensive part of this problem is curation, not serving. Serving your slice of already-compiled breach data costs close to nothing at the edge. The code is public. If it earns it, a star helps others find it: https://github.com/XposedOrNot/XposedOrNot-API
GitHub

GitHub - XposedOrNot/XposedOrNot-API: XposedOrNot: Open-source API for real-time alerts on domain da

XposedOrNot: Open-source API for real-time alerts on domain data breaches. Protects your online identity with user-friendly monitoring and immediate notifications. Ideal for personal and profession...

0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 31, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange

SysAdmin Day gift from XposedOrNot: a breach-monitoring toolkit that is free and open source (MIT), end-to-end.

  • check an address for breach exposure from a script, no API key
  • RSS feed of newly indexed breaches
  • verify your domain once, get alerts for every address on it
  • Microsoft Sentinel connector if you live in a SIEM

Built by someone who did the job. Setup fits in a coffee break:

https://blog.xposedornot.com/free-breach-monitoring-toolkit-sysadmins

0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 31, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
The best sysadmin work leaves no trace. Certs renewed. Backups that actually restore. Maintenance windows you slept through. Tools, tech, the thinking. All learned on the job. Happy SysAdmin Day. If you work with one, say it out loud today.
0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 30, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
CareCloud says a March cyberattack exposed sensitive medical, financial, and personal data of at least 345,000 people after hackers accessed an AWS-hosted health records database for six days. #databreach https://techcrunch.com/2026/07/30/carecloud-begins-to-notify-hundreds-of-thousands-after-hackers-stole-medical-records/
CareCloud begins to notify hundreds of thousands after hackers stole medical records | TechCrunch
TechCrunch

CareCloud begins to notify hundreds of thousands after hackers stole medical records | TechCrunch

The health tech data giant, which handles vast amounts of patients' medical data, said hackers struck one of its protected health data stores.

0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 30, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
NYC Health + Hospitals faces new claims from extortion group LeakNet, which alleges it stole an 11TB archive affecting 12M people. So far, only 1.8M victims have been officially confirmed. The leaked samples appear sensitive, but the 12M claim remains unverified pending independent review and an official response. #databreach https://hackread.com/leaknet-11tb-stolen-nyc-health-hospitals-data-breach/
LeakNet Claims 11TB of Data Stolen in NYC Health + Hospitals Breach
Hackread - Cybersecurity News, Data Breaches, AI and More

LeakNet Claims 11TB of Data Stolen in NYC Health + Hospitals Breach

LeakNet claims it stole 11TB of NYC Health + Hospitals data containing sensitive medical, financial and biometric records linked to more than 12 million people.

0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 30, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
Breach check with no API key, no signup, one line: curl "https://api.xposedornot.com/v1/check-email/you@example.com" Returns every breach from the @XposedOrNot@infosec.exchange index the email appears in, as JSON. Free.
0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 30, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
The UK's Department for Education (DfE) has confirmed a #databreach affecting around 607,000 records following a cyberattack. Exposed data includes phone numbers and email addresses of individuals and organizations. https://www.bbc.com/news/articles/cq6dmgrp21po?at_medium=RSS&at_campaign=rss
Education department says 607,000 records taken in cyber attack
www.bbc.com

Education department says 607,000 records taken in cyber attack

The DfE says it is working closely with the National Cyber Security Centre and the National Crime Agency.

0
0
2
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 30, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
Healthcare billing company MCBS has disclosed a #databreach affecting 1.26M+ individuals after attackers accessed its network in 2025. Exposed data may include names, SSNs, dates of birth, insurance details, and medical records. https://www.bleepingcomputer.com/news/security/data-breach-at-medical-billing-firm-mcbs-affects-126-million-people/
Data breach at medical billing firm MCBS affects 1.26 million people
BleepingComputer

Data breach at medical billing firm MCBS affects 1.26 million people

Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people.

1
0
5
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 28, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
You fix the family printer. You get the scary emails forwarded to you. My Circle on @XposedOrNot@infosec.exchange: invite up to 25 family and friends. Once they accept, you see their breaches, what data leaked, and which are sensitive. Open source, free, no card. https://blog.xposedornot.com/introducing-my-circle/
0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 28, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
Bank of Baroda confirmed that an employee email account was compromised, exposing some customer data, though core banking systems remain unaffected. #databreach https://www.indiatoday.in/business/companies/story/bank-of-baroda-data-leak-1tb-breach-rbi-cert-in-face-penalties-rbi-customer-safety-2957745-2026-07-28
Bank of Baroda confirms data breach. Can the lender now face penalties?
India Today

Bank of Baroda confirms data breach. Can the lender now face penalties?

Bank of Baroda has confirmed a customer data breach after an employee email account was compromised. The case now turns on regulatory scrutiny, possible penalties and the steps customers must take aga

0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 28, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
The oldest breach in @XposedOrNot@infosec.exchange: gPotato 2007, exposing 2.1 million records. Nineteen years old. The people in it changed jobs, emails, and countries. The data went nowhere. Breach data doesn't expire. What's the oldest breach your email is in? Free, 10 seconds: xposedornot.com
0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 27, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
ShinyHunters has claimed responsibility for Ernst & Young's recent data breach, alleging it used a supply-chain attack to steal credentials and access EY's Jira, GitHub, and Azure environments. EY has not confirmed the claims, but says attackers stole tax-related support ticket data and is offering affected clients 24 months of identity monitoring. #databreach https://www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/
Ernst & Young data breach claimed by ShinyHunters extortion gang
BleepingComputer

Ernst & Young data breach claimed by ShinyHunters extortion gang

The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company's systems via a supply-chain attac

0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 27, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
OnTrac disclosed a cyberattack after hackers accessed its corporate network between Mar. 20–22, with the breach detected on Mar. 23. Customer names were exposed, while other affected data remains undisclosed. #databreach https://www.bleepingcomputer.com/news/security/ontrac-notifies-customers-of-data-breach-after-network-hack/
OnTrac notifies customers of data breach after network hack
BleepingComputer

OnTrac notifies customers of data breach after network hack

OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers.

0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 26, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
I maintain @XposedOrNot@infosec.exchange , a catalog of 770 data breaches. 84 stored passwords in plaintext. Not hashed. Not encrypted. Just text. 1 in 9. Newest: this year. Reused a password anywhere? Assume it's readable. Here, it literally is. Free check, no signup:
0
1
1
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 26, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
Replying to @DevaOnBreaches@infosec.exchange
@XposedOrNot@infosec.exchange Entertainment. 220 of 770 breaches. Not even close. Retail: 107. Finance: 49. Everyone guards the bank. But everyday accounts, gaming, media, forums, are where reused passwords live. Full breakdown by industry AND by record count (the ranking flips): https://xposedornot.com/our-repository
0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 26, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
Click To Pray, the Pope-backed prayer app, reportedly exposed users' names and email addresses due to a basic security flaw. A hacker says she reported it 6 months ago, but it’s still unfixed. With over 719K accounts at risk, experts warn the leaked data could be used for phishing scams. #dataleak https://www.theregister.com/security/2026/07/24/popes-official-prayer-app-commits-cardinal-sin-leaks-700k-users-info/5278603
0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 26, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
From our H1 breach report: 10 entries held 81.9% of the half-billion records. But the median breach? 922,685 records. Mid-sized, no headlines, same per-person damage. Mega breaches get the coverage. Median breaches get the victims. Check yours: xposedornot.com
0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 25, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange

Across the 770 breaches in the @XposedOrNot@infosec.exchange catalog, which industry shows up most often?

Finance
25.0% (1)
Retail
25.0% (1)
Healthcare
50.0% (2)
Entertainment
0.0% (0)
4 votes Poll closed
View on infosec.exchange
0
1
1
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 25, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
One thing I did not expect in our @XposedOrNot@infosec.exchange H1 data: months have personalities. March was a museum. Median lag 1,328 days, mostly old breaches finally making it into the catalog. April was a newsroom. Median lag 34 days, and 17 of its 22 additions were brand new. That is the healthy version, by the way. An index should breathe in both directions: surfacing the new, deepening the old. We just never let the two mix in the stats. Full report: https://blog.xposedornot.com/h1-2026-breach-report/
0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 24, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
Chick-fil-A disclosed a credential stuffing attack that compromised an undisclosed number of customer accounts between June 17–19, 2026. Exposed data may include names, emails, membership details, payment info, and more. Impacted users were logged out, payment methods removed, and urged to change passwords. #databreach https://www.bleepingcomputer.com/news/security/chick-fil-a-discloses-data-breach-after-credential-stuffing-attacks/
0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 22, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
Origin Energy is investigating a potential cyber incident involving unauthorized access to some customer data. The company says no credit card or bank details are believed to be affected, but has notified the ACSC and AFP as investigations continue. https://www.nine.com.au/australia-news/origin-energy-security-incident-20260722-p60hjj.html
0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 22, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
South Korea disclosed a #databreach of its National Diplomatic Academy after hackers exploited a server flaw, maintaining access for 10 months (Apr 2025–Feb 2026). At least 6,000 MFA employees and diplomats had personal data (IDs, names, emails, encrypted passwords) exposed. https://www.bleepingcomputer.com/news/security/south-korea-discloses-data-breach-impacting-diplomats-worldwide/
0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 21, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
Small update from my side. @XposedOrNot@infosec.exchange now works in Turkish and Polish too. Alongside English, that is 14 other languages you can now use, so more people can check for data breaches in the language they think in. More coming soon.
0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 21, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
Estée Lauder says hackers broke into its HR system using an Oracle software flaw and stole personal data like names, emails, SSNs, bank details, and health info. #databreach https://www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/
0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 21, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
My Circle is live on @XposedOrNot@infosec.exchange: free breach monitoring for the family you look after. They accept before you see anything. They can withdraw at any time; up to 25 people, free, open source. You are the family tech person. This is for you. https://blog.xposedornot.com/introducing-my-circle
0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 21, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
Healthcare billing software company Craneware confirmed a cyberattack where hackers stole a significant amount of customer, employee, and partner data. #databreach https://techcrunch.com/2026/07/20/hackers-stole-significant-amount-of-data-from-tech-firm-relied-on-by-thousands-of-us-hospitals-and-pharmacies/
0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 20, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
101 breaches. 1,024,063,499 records. That was H1 2026 in my breach index. Fresh breaches now surface in a median of 34 days. Identity data has overtaken passwords. Full report, free, no email gate, every number reproducible: 👇 https://blog.xposedornot.com/h1-2026-breach-report/ #databreach @XposedOrNot@infosec.exchange
0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 17, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
Lidl says hackers stole some customer data through one of its service providers. The online shop wasn't hacked, and passwords, payment details, and addresses are safe. #databreach https://www.bleepingcomputer.com/news/security/lidl-discloses-online-shop-breach-after-service-provider-hack/
0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 11, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
Accenture has confirmed a #data breach after a hacker claimed to have stolen 35 GB of company data, including source code and security keys. https://www.bleepingcomputer.com/news/security/accenture-confirms-breach-after-hacker-offers-stolen-data-for-sale/
0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 11, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
Fashion marketplace Miinto has confirmed a #databreach after hackers accessed its order management system. Exposed data may include customer names, email and home addresses, phone numbers, and payment method types (but not full card details). https://www.theregister.com/security/2026/07/10/miinto-fesses-up-to-breach-says-customers-open-to-phishing/5269891
0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 11, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
Mount Royal University says hackers stole data from its file storage system and deleted files to make recovery harder. The attack disrupted campus systems, and the stolen data may include student and employee information. #databreach https://www.bleepingcomputer.com/news/security/mount-royal-university-confirms-breach-as-hackers-claim-attack/
0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jul 11, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
Nextcloud exposed an unsecured database with 367,000 records, including invoices, contracts, employee and client details, and setup scripts. The company fixed the issue after it was reported. #dataleak https://cybernews.com/security/nextcloud-cloud-provider-data-leak/
0
0
0
1
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Jun 29, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
NAIC, the U.S. insurance regulator, disclosed a #databreach after #ShinyHunters exploited the #Oracle PeopleSoft zero-day (CVE-2026-35273). NAIC said the attackers accessed only public reports, outdated logs, and configuration files, https://www.bleepingcomputer.com/news/security/naic-says-public-data-stolen-in-shinyhunters-peoplesoft-breach/
0
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Apr 12, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange

Silent Ransom Group hacked Orrick (after its 2023 #databreach), stole sensitive data via phishing/social engineering, and leaked it after rejecting a $1M offer as too low.

https://databreaches.net/2026/04/10/silent-ransom-group-leaked-another-big-law-firm-orrick-herrington-sutcliffe/

infosec.exchange

Infosec Exchange

0
0
3
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Apr 04, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange
Replying to @nihkeys@mastodontti.fi
@nihkeys@mastodontti.fi Actual use cases are large and beneficial. However in this case and based on the style, it maybe attributed as such. Unless and until a full forensic report is published with verifiable evidences , I do not think anything else matters.
1
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Apr 04, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange

Hims & Hers confirms #databreach of third-party support system (Feb 4–7) via social engineering. Hackers stole customer tickets incl. names, emails + other personal data (medical records not affected).

https://techcrunch.com/2026/04/02/telehealth-giant-hims-hers-says-its-customer-support-system-was-hacked/

infosec.exchange

Infosec Exchange

0
0
2
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Apr 03, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange

Drift Protocol hacked for ~$280M after attacker seized Security Council admin control via pre-signed txs + multisig manipulation (no smart contract flaw). DPRK-linked tactics suspected.

https://www.bleepingcomputer.com/news/security/drift-loses-280-million-north-korean-hackers-seize-security-council-powers/

Drift loses $280 million as North Korean hackers seize Security Council powers
BleepingComputer

Drift loses $280 million as North Korean hackers seize Security Council powers

The Drift Protocol lost at least $280 million after a threat actor took control of its Security Council administrative powers in a planned, sophisticated operation.

1
2
2
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Apr 03, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange

Duc App (by Duales) exposed 360K+ sensitive files (passports, licenses, selfies, transactions) via a public, unencrypted Amazon storage bucket. #dataleak

https://techcrunch.com/2026/04/02/canadian-money-transfer-app-duc-expose-drivers-licenses-passports-amazon-server/

infosec.exchange

Infosec Exchange

1
0
2
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Apr 03, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange

Mercor confirms #databreach tied to compromised LiteLLM supply chain attack (malicious PyPI versions live ~40 mins). TeamPCP linked to initial access; Lapsus$ claims 4TB stolen (PII, code, APIs).

https://hackread.com/ai-firm-mercor-breach-hackers-4tb-data/

infosec.exchange

Infosec Exchange

1
0
2
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Apr 03, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange

ShinyHunters (UNC6040) issues “final warning” to Cisco ahead of Apr 3, 2026, threatening to leak 3M+ stolen Salesforce records + PII, AWS & internal data. Claims tied to vishing + cloud access. #databreach

https://hackread.com/shinyhunters-hackers-cisco-records-data-leak/

infosec.exchange

Infosec Exchange

1
0
3
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Apr 01, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange

CareCloud disclosed a March 16 cyberattack that disrupted one EHR system for ~8 hours and exposed limited patient data. Systems are now restored, attackers removed, and an investigation is ongoing with external cybersecurity experts. #databreach

https://www.bleepingcomputer.com/news/security/healthcare-tech-firm-carecloud-says-hackers-stole-patient-data/

infosec.exchange

Infosec Exchange

1
0
2
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Mar 31, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange

Here’s your weekly #databreach news roundup:

Dutch National Police, European Commission, AFC Ajax, Crunchyroll, and Infinite Campus.

https://blog.xposedornot.com/weekly-databreaches-roundup-week-13-2026/

infosec.exchange

Infosec Exchange

0
0
2
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Mar 28, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange

Dutch National Police says a phishing attack briefly breached internal systems but was quickly contained.

Impact appears limited; no citizen or investigative data exposed. Probe and criminal investigation ongoing.
#databreach

https://www.bleepingcomputer.com/news/security/dutch-police-discloses-security-breach-after-phishing-attack/

infosec.exchange

Infosec Exchange

1
0
0
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Mar 28, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange

Threatactor ShinyHunters quits BreachForums post-FBI seizure, calling it “a waste of time,” and leaks updated data of 300K+ users. Warns all current forums are fake and threatens more massive data dumps. #databreach

https://hackread.com/shinyhunters-breachforums-leak-300000-user-database/

infosec.exchange

Infosec Exchange

0
0
2
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Mar 28, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange

European Commission probes #databreach of an Amazon Web Services account after a hacker claimed to steal 350GB of data.

Attack was quickly contained; investigation ongoing.

https://www.bleepingcomputer.com/news/security/european-commission-investigating-breach-after-amazon-cloud-account-hack/

infosec.exchange

Infosec Exchange

1
0
1
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Mar 28, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange

AFC Ajax says a hacker exploited system flaws to access limited fan data and manipulate tickets & stadium bans. Issues were revealed by journalists tipped off by the hacker. #databreach

https://www.bleepingcomputer.com/news/security/ajax-football-club-hack-exposed-fan-data-enabled-ticket-hijack/

infosec.exchange

Infosec Exchange

0
0
1
0
Open post
DevaOnBreaches
DevaOnBreaches @DevaOnBreaches@infosec.exchange · Mar 25, 2026
DevaOnBreaches
@DevaOnBreaches@infosec.exchange

Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot

infosec.exchange

Crunchyroll is investigating claims that hackers stole data from about 6.8M users after compromising a support agent’s account via a third-party vendor. Exposed info mainly comes from support tickets, raising phishing risks. #databreach

https://www.bleepingcomputer.com/news/security/crunchyroll-probes-breach-after-hacker-claims-to-steal-68m-users-data/

infosec.exchange

Infosec Exchange

0
0
0
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 19:41:59 UTC