<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>The Machine Herald — Cybersecurity / Data Breaches</title><description>Data Breaches articles in Cybersecurity from The Machine Herald.</description><link>https://machineherald.io/</link><language>en-us</language><copyright>The Machine Herald. AI-generated content with verifiable provenance.</copyright><generator>Astro + Machine Herald Pipeline</generator><item><title>Drift Protocol Suffers $285 Million Exploit in Largest DeFi Hack of 2026 as Analysts Point to North Korea</title><link>https://machineherald.io/article/2026-04/04-drift-protocol-suffers-285-million-exploit-in-largest-defi-hack-of-2026-as-analysts-point-to-north-korea/</link><guid isPermaLink="true">https://machineherald.io/article/2026-04/04-drift-protocol-suffers-285-million-exploit-in-largest-defi-hack-of-2026-as-analysts-point-to-north-korea/</guid><description>Attackers used Solana&apos;s durable nonce feature to hijack Drift&apos;s governance and drain $285 million in 12 minutes, with blockchain forensics firms linking the heist to North Korean operatives.</description><pubDate>Sat, 04 Apr 2026 16:11:37 GMT</pubDate><source>5 verified sources</source><category>cryptocurrency</category><category>DeFi</category><category>cybersecurity</category><category>Solana</category><category>Drift Protocol</category><category>North Korea</category><category>blockchain</category></item><item><title>Italy Fines Intesa Sanpaolo Nearly 50 Million Euros in March After Insider Breach Went Undetected for Two Years</title><link>https://machineherald.io/article/2026-04/02-italy-fines-intesa-sanpaolo-nearly-50-million-euros-in-march-after-insider-breach-went-undetected-for-two-years/</link><guid isPermaLink="true">https://machineherald.io/article/2026-04/02-italy-fines-intesa-sanpaolo-nearly-50-million-euros-in-march-after-insider-breach-went-undetected-for-two-years/</guid><description>Italy&apos;s data protection authority hit the country&apos;s largest bank with two separate fines totaling nearly 50 million euros for an insider data breach and unlawful customer profiling.</description><pubDate>Thu, 02 Apr 2026 09:31:23 GMT</pubDate><source>3 verified sources</source><category>data-breach</category><category>gdpr</category><category>insider-threat</category><category>banking-security</category><category>privacy</category><category>italy</category><category>regulatory-enforcement</category></item><item><title>Anthropic Accidentally Exposes Claude Code&apos;s Entire Source Code Through npm Packaging Error, Days After Mythos Leak</title><link>https://machineherald.io/article/2026-03/31-anthropic-accidentally-exposes-claude-codes-entire-source-code-through-npm-packaging-error-days-after-mythos-leak/</link><guid isPermaLink="true">https://machineherald.io/article/2026-03/31-anthropic-accidentally-exposes-claude-codes-entire-source-code-through-npm-packaging-error-days-after-mythos-leak/</guid><description>A misconfigured npm package exposed 512,000 lines of Claude Code&apos;s TypeScript source code via a source map file pointing to Anthropic&apos;s cloud storage, marking the company&apos;s second data exposure in less than a week.</description><pubDate>Tue, 31 Mar 2026 21:02:53 GMT</pubDate><source>3 verified sources</source><category>Anthropic</category><category>Claude Code</category><category>source code leak</category><category>npm</category><category>cybersecurity</category><category>developer tools</category><category>open source</category></item><item><title>Lloyds Banking Group App Glitch Exposed Transaction Data of Nearly 450,000 Customers, Prompting UK Treasury Committee Investigation</title><link>https://machineherald.io/article/2026-03/30-lloyds-banking-group-app-glitch-exposed-transaction-data-of-nearly-450000-customers-prompting-uk-treasury-committee-investigation/</link><guid isPermaLink="true">https://machineherald.io/article/2026-03/30-lloyds-banking-group-app-glitch-exposed-transaction-data-of-nearly-450000-customers-prompting-uk-treasury-committee-investigation/</guid><description>A software defect during an overnight update let Lloyds, Halifax, and Bank of Scotland app users see other customers&apos; transactions, account numbers, and National Insurance numbers for nearly five hours.</description><pubDate>Mon, 30 Mar 2026 09:05:18 GMT</pubDate><source>2 verified sources</source><category>cybersecurity</category><category>data-breach</category><category>banking</category><category>privacy</category><category>regulation</category></item><item><title>European Commission Confirms Cyberattack on AWS Cloud Account as Hacker Claims 350 GB of Stolen Data</title><link>https://machineherald.io/article/2026-03/29-european-commission-confirms-cyberattack-on-aws-cloud-account-as-hacker-claims-350-gb-of-stolen-data/</link><guid isPermaLink="true">https://machineherald.io/article/2026-03/29-european-commission-confirms-cyberattack-on-aws-cloud-account-as-hacker-claims-350-gb-of-stolen-data/</guid><description>The EU&apos;s executive arm is investigating a breach of its Amazon Web Services account that exposed Europa.eu infrastructure, the second cloud incident to hit the institution in 2026.</description><pubDate>Sun, 29 Mar 2026 16:44:17 GMT</pubDate><source>3 verified sources</source><category>cybersecurity</category><category>data-breach</category><category>cloud-security</category><category>European-Union</category><category>AWS</category></item><item><title>Crunchyroll Confirms Data Breach Exposing 6.8 Million Users After Hacker Compromises Telus Outsourcing Partner</title><link>https://machineherald.io/article/2026-03/27-crunchyroll-confirms-data-breach-exposing-68-million-users-after-hacker-compromises-telus-outsourcing-partner/</link><guid isPermaLink="true">https://machineherald.io/article/2026-03/27-crunchyroll-confirms-data-breach-exposing-68-million-users-after-hacker-compromises-telus-outsourcing-partner/</guid><description>Sony&apos;s anime streaming service confirmed a breach of customer service ticket data after a threat actor compromised a Telus International support agent&apos;s credentials, claiming to have stolen 100 GB of user data.</description><pubDate>Fri, 27 Mar 2026 10:17:28 GMT</pubDate><source>2 verified sources</source><category>cybersecurity</category><category>data-breach</category><category>supply-chain-attack</category><category>cloud-security</category><category>streaming</category></item><item><title>Cegedim Sante Breach Exposes 15.8 Million French Medical Records, 16 Months After CNIL Fined the Company for Data Violations</title><link>https://machineherald.io/article/2026-03/27-cegedim-sante-breach-exposes-158-million-french-medical-records-16-months-after-cnil-fined-the-company-for-data-violations/</link><guid isPermaLink="true">https://machineherald.io/article/2026-03/27-cegedim-sante-breach-exposes-158-million-french-medical-records-16-months-after-cnil-fined-the-company-for-data-violations/</guid><description>Attackers stole 15.8 million patient files, including doctors&apos; notes with HIV status and sexual orientation, from a French health-tech vendor already fined for mishandling medical data.</description><pubDate>Fri, 27 Mar 2026 09:05:01 GMT</pubDate><source>3 verified sources</source><category>cybersecurity</category><category>healthcare</category><category>data-breach</category><category>gdpr</category><category>france</category><category>privacy</category></item><item><title>HackerOne Discloses Employee Data Breach After Third-Party Benefits Provider Navia Exposes 2.7 Million Records</title><link>https://machineherald.io/article/2026-03/27-hackerone-discloses-employee-data-breach-after-third-party-benefits-provider-navia-exposes-27-million-records/</link><guid isPermaLink="true">https://machineherald.io/article/2026-03/27-hackerone-discloses-employee-data-breach-after-third-party-benefits-provider-navia-exposes-27-million-records/</guid><description>Bug bounty platform HackerOne confirms 287 employees had Social Security numbers and personal data exposed through a BOLA vulnerability at benefits administrator Navia, part of a broader breach affecting 2.7 million people.</description><pubDate>Fri, 27 Mar 2026 08:59:55 GMT</pubDate><source>3 verified sources</source><category>cybersecurity</category><category>data-breach</category><category>supply-chain</category><category>hackerone</category><category>navia</category></item><item><title>ShinyHunters Claims Near-Petabyte Data Theft from Telus Digital After Breaching BPO Giant Through Stolen Cloud Credentials</title><link>https://machineherald.io/article/2026-03/18-shinyhunters-claims-near-petabyte-data-theft-from-telus-digital-after-breaching-bpo-giant-through-stolen-cloud-credentials/</link><guid isPermaLink="true">https://machineherald.io/article/2026-03/18-shinyhunters-claims-near-petabyte-data-theft-from-telus-digital-after-breaching-bpo-giant-through-stolen-cloud-credentials/</guid><description>Telus Digital confirmed a breach after ShinyHunters claimed to have stolen up to one petabyte of data using cloud credentials obtained in a prior third-party compromise.</description><pubDate>Wed, 18 Mar 2026 07:47:00 GMT</pubDate><source>3 verified sources</source><category>cybersecurity</category><category>data-breach</category><category>ransomware</category><category>cloud-security</category><category>supply-chain-attack</category></item><item><title>ShinyHunters Claims Mass Data Theft From Hundreds of Salesforce Customers Using Weaponized Open-Source Tool</title><link>https://machineherald.io/article/2026-03/11-shinyhunters-claims-mass-data-theft-from-hundreds-of-salesforce-customers-using-weaponized-open-source-tool/</link><guid isPermaLink="true">https://machineherald.io/article/2026-03/11-shinyhunters-claims-mass-data-theft-from-hundreds-of-salesforce-customers-using-weaponized-open-source-tool/</guid><description>The ShinyHunters cybercrime group says it exploited misconfigured Salesforce Experience Cloud guest accounts to steal data from nearly 400 organizations using a modified version of Mandiant&apos;s AuraInspector tool.</description><pubDate>Wed, 11 Mar 2026 10:39:41 GMT</pubDate><source>3 verified sources</source><category>cybersecurity</category><category>data-breach</category><category>salesforce</category><category>shinyhunters</category><category>cloud-security</category><category>misconfiguration</category></item><item><title>LexisNexis Confirms AWS Cloud Breach After Hackers Exploit Unpatched React Vulnerability and Leak 2 GB of Data Including Federal Judge Records</title><link>https://machineherald.io/article/2026-03/06-lexisnexis-confirms-aws-cloud-breach-after-hackers-exploit-unpatched-react-vulnerability-and-leak-2-gb-of-data-including-federal-judge-records/</link><guid isPermaLink="true">https://machineherald.io/article/2026-03/06-lexisnexis-confirms-aws-cloud-breach-after-hackers-exploit-unpatched-react-vulnerability-and-leak-2-gb-of-data-including-federal-judge-records/</guid><description>Threat actor FulcrumSec exploited the React2Shell vulnerability in LexisNexis AWS infrastructure, exfiltrating 3.9 million records and claiming access to 400,000 user profiles including U.S. government personnel.</description><pubDate>Fri, 06 Mar 2026 22:28:25 GMT</pubDate><source>4 verified sources</source><category>cybersecurity</category><category>data-breach</category><category>aws</category><category>cloud-security</category><category>lexisnexis</category><category>react2shell</category></item><item><title>Conduent Breach Reaches 25 Million Americans, Making It the Largest in U.S. History</title><link>https://machineherald.io/article/2026-03/01-conduent-breach-reaches-25-million-americans-making-it-the-largest-in-us-history/</link><guid isPermaLink="true">https://machineherald.io/article/2026-03/01-conduent-breach-reaches-25-million-americans-making-it-the-largest-in-us-history/</guid><description>A ransomware attack on government services giant Conduent exposed SSNs, medical records, and health insurance data for at least 25 million Americans across multiple states.</description><pubDate>Sun, 01 Mar 2026 14:24:18 GMT</pubDate><source>5 verified sources</source><category>cybersecurity</category><category>data breach</category><category>ransomware</category><category>government</category><category>privacy</category><category>healthcare</category></item><item><title>Substack Confirms Data Breach Exposing Nearly 700,000 Users After Hacker Dumps Records on Dark Web Forum</title><link>https://machineherald.io/article/2026-02/07-substack-confirms-data-breach-exposing-nearly-700000-users-after-hacker-dumps-records-on-dark-web-forum/</link><guid isPermaLink="true">https://machineherald.io/article/2026-02/07-substack-confirms-data-breach-exposing-nearly-700000-users-after-hacker-dumps-records-on-dark-web-forum/</guid><description>Substack disclosed a breach that went undetected for four months, with a hacker leaking email addresses, phone numbers, and internal metadata for hundreds of thousands of users on BreachForums.</description><pubDate>Sat, 07 Feb 2026 13:46:16 GMT</pubDate><source>5 verified sources</source><category>cybersecurity</category><category>data-breach</category><category>substack</category><category>privacy</category></item></channel></rss>