Skip to content
>_ITDITDWeb Security Platform
tag

worldwide

15 articles with this tag

2026-09-30

Your device maker holds your data too: what Medtronic device patients should check after the 2026 breach

On April 24, 2026, medical device maker Medtronic disclosed that an unauthorized party had accessed data in certain of its corporate IT systems. Per its notice letter, the access ran from April 13 to April 19, 2026. The Indiana Attorney General's breach list shows 3,834,294 people affected nationwide, with notices sent on June 29. The information involved: name, contact information, date of birth, Social Security number and health-related information. The company says it has not identified any impact to product security or patient safety, including the ability of any Medtronic device to operate safely and deliver intended therapy. This site's take: device makers hold patient data so that product updates and safety notices can reach you. Don't stop using the device or drop your registration; protect the SSN with a credit freeze and an IRS IP PIN, and verify any call that mentions your device by calling back a number you already have.

2026-09-30

A licence number is still a key somewhere: what AssuranceAmerica customers should do after the 7 million-person breach

On July 10, 2026, US auto insurer AssuranceAmerica notified people that, following malicious activity targeting one of its employees on March 16, an unauthorized third party accessed part of its IT environment and copied certain data files. The Indiana Attorney General's breach list puts the total affected at 6,998,886. Depending on the person, the data included name, contact information, auto policy or account information, driver or vehicle information, claims information and driver's license number, and for a limited number of people a Tax ID or Social Security number. This site's take: in the US a driver's license number is used as an identity field not only on credit applications but also on insurance and public-benefit applications, so a credit freeze alone leaves gaps. Freeze your credit, and also tell your state motor vehicle agency that your number was exposed.

2026-09-30

Correct booking details don't prove a message is real — the Booking.com reservation data access and how to spot fake property messages

In April 2026 Booking.com notified guests that unauthorized third parties may have been able to access certain booking information, updated the PINs of the affected reservations, and said it had contained the issue. According to the notice and the company's spokesperson as reported, the information included booking details, names, email addresses, phone numbers and messages shared with properties; financial information was not accessed. The number affected and the cause were not disclosed. This site's take: what broke here is the habit of trusting anyone who knows the details of your booking. A correct hotel name, date and price no longer prove anything. The only test that still works is whether a request matches the payment policy in the booking you open yourself in the official app. A request to re-enter card details, pay through a link, or make a transfer not in the policy is where you stop.

2026-09-30

Your ID number leaked — you still don't need a new passport: what the Odido data breach in the Netherlands shows

On February 12, 2026, Dutch telecom operator Odido disclosed that customer data had been taken from a customer contact system it uses. Its spokesperson put the scale at about 6.2 million accounts; Odido's later FAQ says about 6.39 million people were affected (current and former customers of Odido and its brand Ben). Depending on the person, the data included name, address, mobile number, customer number, email, IBAN, date of birth, and ID document number and expiry; passwords, call records and ID scans were not included. This site's take: an ID number is more a name tag than a key. The Dutch Central Identity Fraud Reporting Centre (CMI) says this data alone cannot be used to take out a loan, open a bank account, sign a phone contract or apply for a new ID document, and neither replacing passports nor changing account numbers is recommended. The real danger is contact from someone who 'knows' your numbers. And the broader lesson: ID numbers collected for verification leak from the collector.

2026-09-30

The call that already knows your contract is the scam: what to do after the Endesa data breach (DNI and IBAN)

Endesa Energía told customers (around January 12, 2026) that a malicious actor gained unauthorized access to its commercial platform and may have exfiltrated basic identification data, contact details, national ID (DNI) numbers, energy contract data and, in some cases, IBANs; passwords were not affected. Endesa reported the incident to the Spanish Data Protection Agency (AEPD) and has not published how many customers were affected. This site's take: this is exactly the kind of data that makes the long-running energy phone scam ('tariff change', 'supply cut-off') believable: a caller who already knows your DNI and your contract doesn't sound like a scammer. Knowing your details proves nothing, so hang up and call the official number yourself. And because an IBAN can be used for direct debits, check your statements: a debit you never authorized can be refunded for up to 13 months.

2026-09-30

What leaked was not your ID but a list of people with ID paperwork in progress — the France Titres (ANTS) breach and how to spot fake ANTS messages

France Titres, the French national agency for secure documents (ANTS), detected on April 15, 2026 a security incident that may have exposed data from individual and professional accounts on its ants.gouv.fr portal. On April 21 the Interior Ministry said about 11.7 million accounts may be affected. The data includes login ID, title, surname and first names, email address, date of birth and a unique account ID, and for some accounts a postal address, place of birth and phone number. According to the government, attachments submitted with applications and biometric data are not included. The government asked users to change their password at their next login and to be very careful with suspicious texts, calls and emails that appear to come from ANTS. ANTS put its application pages into maintenance from April 24 and says two-step authentication has been in place since April 29. This site's take: what leaked is not the ID documents themselves but the context that a person deals with ID, licence or registration paperwork, which is exactly what a convincing ANTS or 'permis de conduire' scam needs. There is no need to replace your documents; the habit that works is never using a link in a message and opening ants.gouv.fr yourself.

2026-09-30

A breach notice from a company you've never heard of: the Aesto Health breach affecting 9.5 million people and the problem with medical record archives

US healthcare data migration and archiving vendor Aesto, LLC (Aesto Health) says that from on or about December 2 to December 18, 2025, protected health information belonging to patients of its healthcare provider clients, stored in part of its cloud environment, may have been accessed and/or acquired by an unauthorized actor. The HHS Office for Civil Rights breach portal lists 9,540,683 people affected. The information includes names, dates of birth, medical information, driver's license numbers, financial account numbers, health insurance information, and government ID numbers such as ITINs; Social Security numbers were potentially involved for a limited number of people. This site's take: you don't recognize the sender because your provider handed old records to an archiving vendor. First confirm whether your provider is on the list, then protect SSNs and ITINs with a credit freeze and an IRS IP PIN, and medical information by reading your benefit statements. Providers need an inventory of every vendor holding patient data and an end date for archived records.

2026-09-30

Your passport number leaked, not your passport — what Carnival Corporation's data breach means for travelers

Carnival Corporation, the parent of Carnival Cruise Line, says that on April 14, 2026 its IT security team identified unauthorized activity involving an employee's account: an unauthorized actor used social engineering to deceive an employee and gained access to a limited portion of its IT system. On April 22 the company determined that personal information had been copied. Its filing with the Maine Attorney General lists 5,995,277 people affected. The data varies by person and includes name, address, email address, phone number, date of birth and government-issued ID numbers such as driver's license and passport numbers. This site's take: what leaked is a passport number, not the passport. The official lost-or-stolen process in the US (and in Japan) cancels the document itself and is meant for passports that are actually lost or stolen. The real risk is messages from people who seem to know your trip and your ID; the defenses are a credit freeze for US residents, ignoring links in look-alike emails, and knowing when a passport really does need to be reported.

2026-09-30

One vendor, 15 million patients — the Cegedim Santé (MLM) breach in France and why the free-text box mattered most

Cegedim Santé, the Cegedim Group subsidiary that publishes software for healthcare professionals in France, said on February 26, 2026 that at the end of 2025 it identified abnormal application request behaviour on the accounts of doctors using its MLM (MonLogicielMedical.com) software. Of the 3,800 doctors using MLM, 1,500 were affected, and personal data of patients in the MLM database was illegally accessed or extracted. The data comes from the patient's administrative file (name, gender, date of birth, phone number, address, email) and administrative comments written in free text at the doctor's discretion; for a very limited number of patients those comments may have contained the doctor's personal notes about sensitive information. The company says structured medical records remained intact. France's Ministry of Health was reported to put the number of patients who may be concerned at about 15 million, with about 1% involving sensitive notes. This site's take: when one cloud vendor holds the patient lists of thousands of practices, a breach happens at the scale of the vendor's whole user base, not of a single clinic; and the most sensitive data sat in a field whose label said only 'administrative comment'. Patients should prepare for impersonation and pressure messages; clinics should check what goes into free-text fields and who watches for unusual activity on each account.

2026-09-30

Cards with CVV among the leaked data: what Quest Apartment Hotels guests (including overseas travellers) should do after the 2 million-customer breach

Australian serviced-apartment chain Quest Apartment Hotels identified unauthorised access to a database system on August 17, 2026, arising from a vulnerability through a third-party service provider, and disclosed it on August 19. Its September 16 update says information on approximately 1,991,613 customers (records from before June 2025) was affected, including 46,727 credit card numbers with CVV and 297,739 without CVV (both including expired cards), 104,268 passport and/or driver licence numbers, 225,300 vehicle registration numbers, 271 NDIS numbers and 46 Medicare card numbers. This site's take: if you were told a card with its CVV was affected, ask your card issuer about a replacement. The card industry standard PCI DSS does not allow card verification codes to be kept after authorization. Quest has not said why CVVs were in these records, and we make no judgment about compliance, but guests should know that a hotel's records can end up holding them.

2026-09-30

A one-time code can be handed over — what the DentaQuest breach teaches about MFA, and what members should do

DentaQuest, a US dental and vision benefits administrator, says unauthorized individuals accessed data on its network between May 17 and May 20, 2026. Its filing with the Washington State Attorney General says a social engineering attack tricked a single employee into providing credentials and a multifactor authentication code. The data includes names, addresses, dates of birth, Social Security numbers, member and health plan numbers, Medicaid and Medicare numbers, and dental or vision health information. The company told the Washington AG on August 3, 2026 that it was aware of more than 27.4 million people nationwide. This site's take: an SSN cannot be changed, so members should freeze their credit at all three bureaus, get an IRS IP PIN and watch benefit statements. For organizations, the lesson is that any MFA a person can read out or type in can also be handed over; phishing-resistant MFA (passkeys, FIDO2 security keys) and a help desk that verifies callers are what close that gap.

2026-09-30

Not a hack from outside, but logged-in users seeing other companies — the Companies House WebFiling flaw and what directors and developers should do

On March 13, 2026, UK Companies House became aware of an issue that meant a logged-in registered user of its WebFiling service could potentially view and change another company's details after a specific set of actions. It closed WebFiling at 1:30pm that day and reopened it at 9am on March 16. According to Companies House, the cause was a defect introduced during a major system update on October 11, 2025, and it was not a cyber-attack. Data that may have been visible includes the day of the date of birth and residential addresses of directors and people with significant control (PSCs), and company registered email addresses; unauthorised filings such as new accounts or changes of director were also technically possible. Passwords, identity verification data and existing filed documents were not affected. An April 8 update said a very small number of instances of unauthorised access or attempted changes had been identified. This site's take: this was an authorization failure, not an intrusion. The login check worked; the check on whether this user may handle this company did not. Directors should review their filing history and turn on Follow alerts; developers should test, on every release, that requesting someone else's data is refused.

2026-09-30

The appliance you bought years ago left your address with the distributor: what to do after the Shun Hing Group data breach

Hong Kong's Office of the Privacy Commissioner for Personal Data (PCPD) received a data breach notification from Shun Hing Group on 23 March 2026 and has opened an investigation. On 2 July 2026, citing the latest information provided by the organisation, the PCPD said the personal data of more than 921,000 people may have been leaked, including about 920,000 customers' names/titles, addresses, phone numbers and email addresses, and about 1,000 staff and service/product/supplier personnel whose data also included identity document numbers, bank account numbers and salaries. About 1,050,000 people's data may have been maliciously encrypted. On 9 July, Shun Hing Group said there was no evidence the data had been misused and that its PanaClub system had been suspended. This site's take: this is after-sales data, the address and phone number you left years ago to get an appliance delivered, installed or registered for warranty. A caller who knows your address and what you bought proves nothing, and since PanaClub is suspended, any message asking you to reset a PanaClub password is suspect.

2026-09-30

A caller who knows your ID and account number is not the bank: what to do after the Standard Bank data breach

On 23 March 2026, The Standard Bank of South Africa said it had identified unauthorised access to select data. By its 14 April update, the bank said the affected information includes names, ID numbers or company registration numbers, contact details (phone numbers, physical and/or email addresses) and account numbers, later adding B-BBEE categorisation and VAT registration numbers, and that the data 'now appears to have been published'. The bank says its transactional banking and core operating systems were not accessed and client funds are not affected. It has not published how many clients were affected. This site's take: the danger is not someone logging in with this data. It is someone calling you as 'Standard Bank' while reading out your real ID and account number. Knowing those numbers proves nothing, and the bank says it will never ask for your passwords, PINs or OTPs. Hang up, call the number on your card, register with SAFPS, and check your credit report.

2026-09-30

What leaked is when you travel and on which train — the Trenitalia data breach and how to spot fake delay-refund messages

Italian rail operator Trenitalia sent customers a notice under Article 34 of the GDPR saying a cybersecurity incident caused by unidentified external parties led to unauthorised access to some personal data linked to travel tickets (titoli di viaggio). Follow-up notices for jointly controlled tickets describe it as the same event Trenitalia communicated on June 26, 2026. The data may include name, date and place of birth, email and phone number, itinerary details such as route, date, time and ticket number, loyalty card code, employer, and identity document details; the notice for UnicoCampania regional tickets also lists the Italian tax code (codice fiscale) and gender. Trenitalia says account login data, passwords and payment information were not involved. It notified the Italian data protection authority (Garante) and CSIRT Italia and filed a criminal complaint with the Rome prosecutor. This site's take: what leaked is an itinerary — when, where and on which train — and that is exactly what makes a fake 'your train was delayed, claim your refund' message convincing. Real delay compensation is either requested by you through Trenitalia's own channels or, for regional digital tickets, paid automatically to the card you bought with. No genuine refund asks you to type your card number into a link from a text message.