Index live· 1,284 files · 148 editions
ForensicPost

Search the index

56 results
Try
Results for “Identity”Newest first
26-0714
File

Thirty Million Rows, Claimed. A Limited Number of Systems, Confirmed

Abbott confirmed unauthorised access to a limited number of systems. ShinyHunters claims thirty million rows. Almost everything in between is unestablished.

ShinyHuntersVishing → SSO (claimed)HealthcareIdentity
Sev 4TargetAbbott LaboratoriesActorShinyHuntersUSA
26-0726
File

AssuranceAmerica Breach Exposed 6.9 Million Driver's Licence Numbers

6.9 million driver’s licence numbers, a field that is neither ceremonially protected nor practically replaceable.

UnattributedUnder reviewInsuranceIdentity
Sev 4TargetAssuranceAmericaActorUnattributedUSA
26-0716b
File

Two Men Jailed for Five and a Half Years Over the Transport for London Attack

Twenty-seven thousand employees queued in person to reset a password. That is what a broken identity system looks like.

Scattered SpiderTransportAccountability
Sev 2TargetTransport for LondonActorScattered SpiderUnited Kingdom
26-0620
File

Estee Lauder Reports Oracle E-Business Suite Breach Undetected for Ten Months

An Oracle E-Business Suite flaw exploited in August 2025, found in June 2026. The records were employees’: identity documents, bank details, health data.

UnattributedOracle EBS flawRetailDetection
Sev 3TargetEstée LauderActorUnattributed
26-0619
File

The Company That Named the Technique Was Also Hit by It

The team that named the cluster was also caught by it, and published. That removes the easiest excuse for ignoring the technique.

UNC6040Vishing → OAuth consentCloudIdentity
Sev 2TargetGoogle (corporate CRM)ActorUNC6040
26-0616
File

ShinyHunters Claim 2.2 Million Records From Kodak

A claimed 2.2 million records. Long-lived brands hold data collected across decades, terms and regulatory regimes nobody has reconciled.

ShinyHuntersUnauthorised accessManufacturingIdentity
Sev 3TargetKodakActorShinyHunters
26-0608
File

Nobody Breached Anything; They Just Logged In

Valid credentials from somebody else’s breach, accepted. Nothing failed in the conventional sense, and customer data went anyway.

UnattributedCredential stuffingRetailIdentity
Sev 3TargetChick-fil-AActorUnattributed
26-0607
File

UNC6040 Phoned Staff to Authorise Salesforce Connected Apps

A phone call, a consent screen, and a refresh token that outlives every password change. No exploit is involved at any step.

UNC6040Vishing → OAuth consentCloudIdentity
Sev 4TargetSalesforce tenantsActorUNC6040
26-0527
File

Carnival Reports Phishing Breach Affecting Close to Six Million Guests

A phishing-led compromise affecting close to six million guests, including passport numbers a passenger could never have declined to provide.

UnattributedPhishing → accountRetailIdentity
Sev 4TargetCarnival CorporationActorUnattributed
26-0526
File

Charter Discloses Vishing Breach Affecting 4.9 Million Customer Accounts

A vishing call against an employee’s Entra account, then customer records in a connected CRM. The reported total has moved from 4.9 million upward.

ShinyHuntersVishing → EntraTelecomIdentity
Sev 4TargetCharter CommunicationsActorShinyHunters
26-0515
File

Breached in 2024, Found in 2025, Disclosed in 2026

Two years between the intrusion and the notification, on identity documents. Small organisations produce long intervals, and mostly go unrecorded.

UnattributedRetailDetection
Sev 3TargetVacation Myrtle BeachActorUnattributed
26-0420
File

Eleven Million Identity Records, and a Suspect in School

About 11.7 million accounts on France’s national identity portal, and a detained fifteen-year-old. The age is the least useful fact in the file.

Single operatorPortal compromisePublic sectorPublic sector
Sev 4TargetFrance Titres (ANTS)ActorSingle operatorFrance
26-0413
File

You Outsourced the Help Desk and Kept the Consequences

The contract moves the work, the staffing and the cost. It does not move the consequence of resetting the wrong person’s credential.

Scattered SpiderHelp-desk social engineeringMultipleIdentity
Sev 4TargetOutsourced IT service desksActorScattered Spider
26-0227
File

youX Breach Affected 444,500 Borrowers and 229,200 Driver's Licence Records

229,200 driver’s licences at a lending platform, plus data for 797 broker firms. The licence is the KYC document other institutions trust.

UnattributedUnder reviewFinanceIdentity
Sev 4TargetyouXActorUnattributed
26-0224
File

Employee Compromise at Figure Technology Solutions Affected 967,000 Accounts

967,000 accounts at a lending platform. Underwriting assembles identity, income and obligations — including for people who were declined.

ShinyHuntersEmployee social engineeringFinanceIdentity
Sev 4TargetFigure Technology SolutionsActorShinyHunters
26-0219
File

Three Billion Identity Records, and No Attacker Required

Around three billion records in an unsecured database, including a billion KYC entries. No intrusion, no actor, and no way to say who read it.

ExposureUnsecured databaseFinanceExposure
Sev 4TargetIDMeritActorExposure
26-0217
File

Identity Card Issuance Stopped While the Claim Was Assessed

A 139 TB claim against a national identity register, and issuance halted. A biometric register has no reissue path.

Green BloodServer compromisePublic sectorPublic sector
Sev 4TargetSenegal national ID systemActorGreen Blood
26-0205
File

The Phone Number Became National Identity Infrastructure by Accident

A number identifies a billing relationship. It now secures banking and government access, and the depending services cannot see a port request.

MultipleNumber portability abuseTelecomInfrastructure
Sev 4TargetAccount recovery infrastructureActorMultiple
26-0120
File

FBI Recorded Almost $26 Million in SIM Swap Losses in a Single Year

Most victims had no opportunity to behave differently. The failure was entirely at the carrier, and awareness training addresses none of it.

MultipleSIM swapTelecomIdentity
Sev 4TargetMobile subscribersActorMultipleUSA
25-1217
File

Government Data, Taken in Bulk

In many countries these are the most complete identity datasets in existence, and the state’s dataset is not one you can leave.

MultipleVariousPublic sectorPublic sector
Sev 4TargetLatin American government bodiesActorMultipleUSA
25-1105
File

Prosper Marketplace Breach Affected More Than 10 Million Customers

A credit application is the densest identity document an ordinary person produces. Most of the people in the database were declined.

UnattributedFinanceFinance
Sev 4TargetProsper MarketplaceActorUnattributed
25-1104
File

US Identity Fraud Losses Put at $27.3 Billion for 2025

Three hundred files describe organisations losing data. This is the other end — and there is no bridge between them.

MultipleVariousMultipleVictims
Sev 4TargetUS consumersActorMultipleUSA
25-1013
File

FTC Identity Theft Reports Passed the 2024 Total by September 2025

The harms that get counted are the ones somebody already had a process for. Biometrics and medical history generate no report at all.

MultipleIdentity theftMultipleVictims
Sev 3TargetUS consumersActorMultipleUSA
25-1011b
File

Self-service Moved the Identity Boundary Onto the Employee

Self-service is not a convenience feature with a security cost. It is a decision about who holds authority.

MultipleDelegated authority abuseMultipleMethod
Sev 4TargetSelf-service estatesActorMultiple
25-0806b
File

Attackers Posing as HR and IT Staff Phoned Workday Employees

An HR pretext works everywhere. Employees are conditioned not to question it, because the topics are personal and the consequences are employment-related.

ShinyHuntersVoice and SMS phishingCloudIdentity
Sev 3TargetWorkdayActorShinyHunters
25-0813
File

Attackers Registered Their Own MFA Device After Phishing an SSO Code

A stolen code is worth one authentication. An enrolled device is worth all of them, and a password reset does not remove it.

ShinyHuntersMFA enrolmentCloudIdentity
Sev 4TargetEnterprise SSO accountsActorShinyHunters
25-0806
File

Operators Posing as IT Staff Had Employees Authorise a Connected App

Every anti-phishing control is looking for a fake site. There was no fake site — the employee consented on the real one.

ShinyHuntersConsent phishingCloudIdentity
Sev 4TargetEnterprise SaaS tenantsActorShinyHunters
25-0720
File

Telecom Operators Hold Payment and Identity Data Without Financial Regulation

The data followed the obligation and the supervision did not follow the data.

MultipleVariousTelecomAnalysis
Sev 3TargetTelecom subscribersActorMultiple
25-0621
File

Adults Aged 30 to 39 Filed 32% of US Identity Theft Reports

Credit monitoring is a product designed for the population that files the most reports — and useless against a persuasive phone call about savings.

MultipleIdentity theftMultipleVictims
Sev 3TargetUS consumersActorMultipleUSA
25-0220
File

Black Basta's Email-Bombing and Teams Impersonation Outlived the Group

The second move works because the first one is real. The employee has a genuine problem, and internal IT has arrived unprompted to solve it.

Black Basta and successorsSocial engineeringMultipleIdentity
Sev 4TargetEnterprise staffActorBlack Basta and successors
25-0109
File

Ivanti Connect Secure Flaw CVE-2025-0282 Exploited From January 2025

The identity boundary expressed as hardware. And a vendor exploited recently is more likely, not less, to be exploited again.

MultipleZero-day exploitationCloudExploitation
Sev 4TargetIvanti Connect Secure estatesActorMultiple
24-0905
File

TfL Required Every Employee to Attend in Person for a Password Reset

Once identity is compromised, a reset performed over the phone is exactly the mechanism it is trying to undo. The only remaining verifier is a face.

Scattered SpiderPublic sectorFallback
Sev 4TargetTransport for LondonActorScattered SpiderUnited Kingdom
24-0901
File

Transport for London Penetrated Over Three Days in August 2024

The case where the availability cost is documented and the confidentiality count is the footnote.

Scattered SpiderPublic sectorIdentity
Sev 4TargetTransport for LondonActorScattered SpiderUnited Kingdom
24-0710
File

Squarespace Migration Dropped Two-Factor, Crypto Domains Hijacked

Whatever does not survive a migration is removed silently, and nobody is told.

UnattributedAccount takeover after migrationTechnologyIdentity
Sev 4TargetSquarespace domain customersActorUnattributedUSA
24-0703
File

Twilio Confirmed 33 Million Authy Phone Numbers Through an Open Endpoint

The factor held. Being known to use it became the attack surface.

UnattributedUnauthenticated API enumerationTechnologyIdentity
Sev 4TargetTwilio AuthyActorUnattributedUSA
24-0602
File

Snowflake Campaign Reached 165 Customer Environments Without MFA

165 separate failures with one shape, and a platform that was never itself breached.

UNC5537Stolen credentials, no MFAMultipleIdentity
Sev 5TargetSnowflake customer environmentsActorUNC5537USA
24-0530
File

Attackers Logged Into Snowflake Customer Environments With Working Credentials

The platform behaved correctly at every step and 165 organisations lost data anyway. There was no CVE to index it under.

UNC5537Valid credentials, no MFAMultipleIdentity
Sev 5TargetSnowflake tenantsActorUNC5537
24-0527
File

Christie’s Breach Exposed Client ID Document Numbers Over Two Days in May

A rule to collect identity documents, and no matching rule to dispose of them.

UnattributedRetailIdentity
Sev 3TargetChristie’sActorUnattributedUnited Kingdom
24-0509
File

Ascension Traced Its Intrusion to an Employee Downloading a Malicious File

A hundred and forty hospitals losing their record system is not a proportionate consequence of one download. What sits between is everything it was allowed to reach.

Black BastaMalicious file downloadHealthcareIdentity
Sev 5TargetAscensionActorBlack BastaUSA
24-0212
File

Change Healthcare Intruders Used a Citrix Portal With No Second Factor

A written requirement that MFA be enabled everywhere is not a control. It is intent somebody then has to enforce against an estate nobody has fully inventoried.

ALPHVValid credentials, no MFAHealthcareIdentity
Sev 5TargetChange HealthcareActorALPHVUSA
23-1220
File

MongoDB Says Phishing Reached Support Systems but Not Customer Clusters

No lookalike domain and no spoofed sender. The message came from a real colleague’s real account.

UnattributedPhishingTechnologyIdentity
Sev 2TargetMongoDBActorUnattributed
23-1204
File

23andMe Says 14,000 Accounts Were Stuffed, Reaching 6.9 Million Profiles

14,000 accounts to 6.9 million people. The multiplier was a feature, working as designed.

UnattributedCredential stuffingHealthcareIdentity
Sev 4Target23andMeActorUnattributedUSA
23-1020
File

Okta Support System Breach Exposed HAR Files Belonging to 134 Customers

A HAR file does its job by capturing exactly the material an attacker needs.

UnattributedStolen credentialsTechnologyIdentity
Sev 4TargetOktaActorUnattributed
23-0913
File

A Synced Authenticator Turned Retool’s Second Factor Into No Factor

Once the seeds live in an account protected by the same identity, there is one factor wearing two names.

UnattributedSMS phishingTechnologyIdentity
Sev 4TargetRetoolActorUnattributed
23-0317
File

A Decommissioned ABA Server Gave up Credentials for 1.4 Million Members

Decommissioning is an intention. Switching something off is an action.

UnattributedDecommissioned systemLegalIdentity
Sev 3TargetAmerican Bar AssociationActorUnattributedUSA
23-0316
File

Latitude Financial Breach Grew From 328,000 Records to 14 Million

A reader comparing incidents by their first published figure is comparing almost nothing.

UnattributedStolen credentialsFinanceIdentity
Sev 5TargetLatitude FinancialActorUnattributedAustralia
23-0227
File

LastPass Says a Keylogger on an Engineer’s Home Computer Reached Its Vault Backups

The corporate boundary turned out to run through a domestic living room.

UnattributedKeylogger on personal deviceTechnologyIdentity
Sev 5TargetLastPassActorUnattributed
22-0922
File

An API That Asked for Nothing, and 9.8 Million Customer Records

There was no exploit. The endpoint answered anyone who asked, because nothing asked who was calling.

UnattributedUnauthenticated APITelecommunicationsIdentity
Sev 5TargetOptusActorUnattributedAustralia
22-0915
File

The Contractor Approved the Eighteenth Prompt

The second factor was not bypassed. It was delivered to the right person, who said yes.

Lapsus$MFA fatigue → social engineeringTechnologyIdentity
Sev 4TargetUberActorLapsus$USA
22-0808
File

Same Phish, Same Week, Two Companies, Two Outcomes

Three Cloudflare employees typed their password into the attacker’s page. Nothing happened.

0ktapusSMS phishing → credential relayTechnologyIdentity
Sev 4TargetTwilioActor0ktapusUSA
22-0721
File

Twitter Flaw Exposed 5.4 Million Accounts Despite Privacy Settings

For a pseudonymous account, a phone number is not contact data. It is the link to the person.

UnattributedUnauthenticated API lookupTechnologyIdentity
Sev 3TargetTwitterActorUnattributedUSA
22-0720
File

Neopets Database of 69 Million Accounts Offered for Four Bitcoin

Collected from a child, retained past the relationship, past the product, past recognition.

UnattributedTechnologyIdentity
Sev 3TargetNeopetsActorUnattributedUSA
22-0524
File

Cisco Breach Began With Corporate Credentials Synced to a Personal Google Account

The browser did nothing wrong. It carried a work password into a personal account, exactly as designed.

YanluowangSynced credentials → vishing → MFA pushTechnologyIdentity
Sev 3TargetCiscoActorYanluowangUSA
22-0120
File

The Identity Provider Was Reached Through Its Outsourced Support Desk

The alert fired on day one. The customers heard on day sixty-one, from the attackers.

Lapsus$Contractor remote accessTechnologyThird party
Sev 4TargetOktaActorLapsus$USA
22-0118
File

The Register of People Trying to Find Their Families

The harm is not identity theft. For a person on this list, the harm is being found.

UnattributedKnown CVE — unpatchedNon-profitHumanitarian
Sev 5TargetInternational Committee of the Red CrossActorUnattributedSwitzerland
ACT-004
Actor

ShinyHunters

Voice phishing into identity providers, then leak-site extortion. Active since 2020.

VishingSSOLeak siteData theft
Profile
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging