Abbott confirmed unauthorised access to a limited number of systems. ShinyHunters claims thirty million rows. Almost everything in between is unestablished.
Three documented routes into the same object. Closing one is not closing the campaign, and the map arrived after the territory.
A claimed 2.2 million records. Long-lived brands hold data collected across decades, terms and regulatory regimes nobody has reconciled.
A claimed 8.8 TB from legacy patient archives. Every property that makes a legacy system low priority makes it high value.
Extortion refused, 234 GB published, 2.6 million addresses verified. The refusal produced a record that payment never does.
Most of 1.4 million customers, advisers and employees. A CRM accumulates every population an organisation tracks, and so does its blast radius.
1.4 million addresses, and instructor payout methods. A card can be reissued; a bank account configured to receive money cannot.
A vishing call against an employee’s Entra account, then customer records in a connected CRM. The reported total has moved from 4.9 million upward.
455,000 addresses across decades of cohorts. An alumni relationship has no end date and no opt-out.
No intrusion of its own — a dependency with a deadline, hitting the one week in the academic year with no slack in it.
The group claimed 3.65 TB across ~8,800 institutions, defaced hundreds of login portals, then settled. The proof of deletion was a log file it wrote itself.
A nine-million-record claim against corporate IT, with device manufacturing reported untouched. The separation is the finding.
More than a thousand organisations through device code phishing. There is nothing to patch, which is why the campaign has no natural ceiling.
Ten million claimed, 5.5 million verified. A leak-site figure is an advertisement written by the seller.
Separate houses, one platform. A luxury purchase history is a map of where valuable objects live.
600,000 claimed, 185,300 verified — and a franchise structure where the brand, the data holder and the notifier are three parties.
13.5 million accounts reachable because the environment was configured to permit it. Nobody had to be clever.
Hundreds of organisations claimed through public portals working exactly as configured. The guest user profile is a permission set nobody designed.
967,000 accounts at a lending platform. Underwriting assembles identity, income and obligations — including for people who were declined.
5.1 million loyalty accounts. Nothing sensitive by field name; a good deal sensitive by implication.
There is no version of “monitor your accounts” that helps somebody who has already taken the call.
What concentrated was not the data but the method. Every tenant presents the same consent screen and the same vocabulary for a caller to use.
A regulator receiving a dozen filings describing the same technique could warn the market. That is not a new obligation — it is a use of filings that already exist.
A boundary between corporate systems and customer tenants held under live attack. This corpus rarely gets to observe that.
An HR pretext works everywhere. Employees are conditioned not to question it, because the topics are personal and the consequences are employment-related.
A stolen code is worth one authentication. An enrolled device is worth all of them, and a password reset does not remove it.
Whatever the constraint was, it was not budget, headcount, expertise or tooling.
Every anti-phishing control is looking for a fake site. There was no fake site — the employee consented on the real one.
The bureau’s customers are lenders. The people in the database are its product.
Reachable, taken, and published are three populations. Almost every affected count in this database is one of them without saying which.
A service desk supporting agents and brokers is supporting people it does not know by sight.
The peer-warning argument only helps organisations that are not first. Hindsight makes May look like August.
Voice phishing into identity providers, then leak-site extortion. Active since 2020.