Index live· 1,284 files · 148 editions
ForensicPost

Search the index

12 results
Try
Results for “Credential compromise”Newest first
26-0612
File

DentaQuest Data Published After Extortion Demand Refused

Extortion refused, 234 GB published, 2.6 million addresses verified. The refusal produced a record that payment never does.

ShinyHuntersCredential compromiseHealthcareHealthcare
Sev 4TargetDentaQuestActorShinyHunters
26-0611
File

Klue Compromise Reached Salesforce Environments at Two Dozen Customers

A legacy credential and stolen OAuth tokens reached Salesforce environments at ~24 customers. The tokens were used exactly as designed.

UnattributedOAuth token theftCloudTokens
Sev 4TargetKlueActorUnattributed
26-0606
File

A Worm in the Registry, Wearing a Vendor’s Name

A credential-stealing worm in a major vendor’s npm namespace. The namespace is the trust signal, and it delivered the reviewer’s assumption too.

UnattributedPackage compromiseCloudSupply chain
Sev 4TargetRed Hat-associated npm packagesActorUnattributed
26-0602
File

Tens of Thousands of Firewalls, and the Credentials Were Already Inside

Mass credential compromise across tens of thousands of firewalls. Patching fixes the device; it does not un-disclose the credentials.

UnattributedCredential compromiseMultipleEdge devices
Sev 4TargetFortiGate firewallsActorUnattributed
25-1126
File

Several Agencies, One Contractor, Thanksgiving Week

Holiday timing is not a coincidence. And a resident who needs a permit has exactly one place to get it.

UnattributedCompromised credentialsPublic sectorPublic sector
Sev 3TargetPuerto Rico government agenciesActorUnattributedUSA
25-0912
File

India Accounted for 49% of Compromised Accounts Recorded Across Asia

Half the compromised accounts in Asia belong to people about whom this corpus can say nothing further.

MultipleCredential compromiseMultipleInternational
Sev 3TargetAsian internet usersActorMultiple
25-0612
File

Compromised Account Downloaded 300,000 Texas Crash Reports

A crash report exists because someone was in a collision. No vulnerability was exploited — a valid account did a permitted thing 300,000 times.

UnattributedCompromised credentialsPublic sectorPublic sector
Sev 3TargetTexas Department of TransportationActorUnattributedUSA
25-0523
File

Attackers Drained Cetus Protocol Liquidity Using Spoof Tokens

No credential stolen, no server compromised, no employee deceived. The contract executed exactly as published — the specification and the intent diverged.

UnattributedContract logic manipulationFinanceProtocol
Sev 3TargetCetus ProtocolActorUnattributed
25-0521
File

Matthew Lane Sentenced to Four Years Over the PowerSchool Breach

No zero-day, no custom tooling, no organisation. One person in their late teens and a credential without MFA.

Convicted individualCompromised credentialsEducationEnforcement
Sev 3TargetPowerSchoolActorConvicted individual
25-0421b
File

Compromised Credentials Led the Root Causes at 41%, Against 22% for Exploits

The corpus has been over-weighting the minority route, because a named CVE generates documentation and a stolen password does not.

MultipleValid credentialsMultipleMethod
Sev 4TargetIncident response caseloadActorMultiple
25-0105
File

One Credential, and the Records of a Continent’s Schoolchildren

A support portal is a production system. 18,000 schools did not make 18,000 bad decisions — but the security did not scale with the concentration.

Unaffiliated individualCompromised credentialsEducationEducation
Sev 5TargetPowerSchoolActorUnaffiliated individualUSA
23-1119
File

Fidelity National Financial Blocked Its Own Systems and House Sales Stopped

Containment converts an unbounded loss into a bounded one, and moves it onto whoever needed the service that week.

UnattributedCredential compromiseFinanceAvailability
Sev 4TargetFidelity National FinancialActorUnattributedUSA
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging