LiveThreat Breach Watch
// BREACH WATCH

BREACH & RANSOMWARE

Real-time breach and ransomware intelligence for third-party risk management.

Breaches Advisories Vulnerabilities RSS
Score 10 Vendors on Free Tier → RSS Feed
45
Last 24h
320
Last 7 Days
18
Critical (7d)
Showing 21 of 536 results
BREACHLIVETHREAT BRIEF🔑
LIVETHREAT BRIEFAtlas Menu Cheat Service Breach Exposes 64,000 GTA V & CS2 Users' Emails, IPs, and Password Hashes

The Atlas Menu cheat platform for GTA V and CS2 suffered a data breach, leaking emails, IP addresses, support tickets, and hashed passwords of roughly 64,000 users. This exposure highlights third‑party risk for organizations that integrate or rely on low‑security gaming services.

🏭 Technology & SaaS
High · Jun 05, 2026 · HackRead
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF📰
LIVETHREAT BRIEFDentaQuest Cyberattack Exposes Health Data of 2.6 Million Individuals

DentaQuest disclosed a cyber‑attack that resulted in the public exposure of health information for approximately 2.6 million accounts. The breach, uncovered via an online breach‑listing, highlights significant PHI leakage and creates downstream risk for partners that rely on DentaQuest data.

🏭 Healthcare & Life Sciences
High · Jun 05, 2026 · TechRepublic Security
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF💀
LIVETHREAT BRIEFBrute-Force Attack Exposes Encrypted Vaults of <20 Dashlane Users

Dashlane reported that a threat actor brute‑forced its device‑registration API, stole encrypted password vaults from fewer than 20 personal‑plan customers, and downloaded them before the breach was contained. The vaults remain encrypted but can be cracked offline, posing a credential‑exposure risk for any organization that relies on Dashlane.

⚡ Data Exfiltration🎯 Vulnerability Exploit
High · Jun 05, 2026 · Help Net Security
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🔑
LIVETHREAT BRIEFBCD Travel Exposes 396,313 Employee and Client Records in ShinyHunters Extortion Breach

In May 2026, BCD Travel fell victim to the ShinyHunters pay‑or‑leak campaign, resulting in the public release of 396k records containing personal and corporate identifiers. Third‑party risk managers should reassess BCD Travel’s security posture and mitigate downstream phishing threats.

🏭 Professional Services🎯 Stolen Credentials
High · Jun 05, 2026 · HIBP Latest Breaches RSS
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🔗
LIVETHREAT BRIEFSupply Chain Compromise of Hola Browser Delivers Monero Cryptominer to Windows Users

A malicious, unsigned executable was inserted into the Windows distribution of Hola Browser, turning infected machines into Monero miners. The breach affects a small fraction of users but highlights the risk of third‑party software supply‑chain attacks for organizations that whitelist such tools.

🏭 Technology & SaaS⚡ Supply Chain Attack🎯 Third-Party Dependency
High · Jun 04, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF📰
LIVETHREAT BRIEFData Breach Exposes PII of 2.6 M Dental‑Benefit Users at DentaQuest

ShinyHunters leaked 234 GB of data from DentaQuest, revealing personal and health‑insurance information for 2.6 million accounts. The breach highlights third‑party risk for insurers, employers, and Medicaid/Medicare programs that rely on the dental‑benefits platform.

🏭 Healthcare & Life Sciences
High · Jun 04, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🤖
LIVETHREAT BRIEFiFood Data Breach Exposes Personal Data of 1.2 Million Brazilian Users

iFood, Brazil’s largest food‑delivery platform, confirmed that personal information for approximately 1.2 million customers was accessed by unauthorized actors. The breach raises third‑party risk for brands that integrate iFood services, especially under Brazil’s LGPD privacy regime.

🏭 Retail & E-Commerce
High · Jun 04, 2026 · HackRead
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🏛️
LIVETHREAT BRIEFUN World Food Programme Self‑Registration App Breach Exposes Data of 600,000 Gaza Households

The UN World Food Programme disclosed that its self‑registration platform for Gaza beneficiaries was breached, leaking personal data for roughly 600,000 households. The incident underscores third‑party risk for organizations that rely on humanitarian data services and raises immediate phishing and fraud concerns.

🏭 Government & Public Sector⚡ Data Exfiltration
High · Jun 04, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🔑
LIVETHREAT BRIEFHackers Exploit Meta AI Support Chatbot to Hijack Instagram Accounts

Attackers used Meta’s AI support assistant to add a malicious email address to victims’ Instagram profiles, captured the verification code, and forced a password reset, resulting in account takeover. The incident underscores the risk that LLM‑driven support bots can be abused for credential compromise, affecting both users and enterprises that depend on the platform.

🏭 Media & Entertainment🎯 Phishing
High · Jun 04, 2026 · Schneier on Security
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF☁️
LIVETHREAT BRIEFEspionage Campaign Exfiltrates Senior Executive Email from Global Stock Exchange Over Five Months

A sophisticated threat actor compromised the Outlook mailbox of a senior executive at a major stock exchange, siphoning email data for five months through Dropbox and OneDrive. The breach highlights the risk of credential compromise and cloud‑based exfiltration for high‑value financial institutions.

🏭 Financial Services & FinTech
High · Jun 04, 2026 · The Hacker News
Read Full Intelligence Brief →
BREACH📧
Meta&#8217;s AI support bot happily handed Instagram accounts to hackers

Hackers convinced an AI support bot to hand over Instagram accounts by changing recovery email addresses.

🏭 Technology & SaaS⚡ Credential Compromise🎯 Stolen Credentials🔒 Personally Identifiable Info
High · Jun 04, 2026 · Malwarebytes Labs
BREACHLIVETHREAT BRIEF🏥
LIVETHREAT BRIEFDentaQuest Exposes 2.6 M Dental Benefit Records in ShinyHunters Extortion Leak

In May 2026, ShinyHunters published over 2 million dental‑benefit records after extorting DentaQuest. The leak includes PHI such as Medicaid IDs, dates of birth and contact details, creating a significant third‑party risk for insurers and health‑tech platforms that rely on DentaQuest data.

🏭 Healthcare & Life Sciences
High · Jun 03, 2026 · HIBP Latest Breaches RSS
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🏦
LIVETHREAT BRIEFSpanish Hacker “Alcasec” Jailed 31 Months for Theft and Sale of Banking Data of Thousands of Citizens

Alcasec, known as the “Robin Hood of Spanish Hackers,” was sentenced to 31 months after admitting to stealing and selling banking credentials of Spanish citizens. The breach underscores credential‑theft risks for financial‑service third parties and the need for robust authentication controls.

🏭 Financial Services & FinTech🎯 Phishing
High · Jun 03, 2026 · HackRead
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🔑
LIVETHREAT BRIEFInstagram AI Support Chatbot Flaw Enables Credential Hijacks of High‑Profile Accounts

Attackers leveraged Meta’s AI‑powered support chatbot to reset Instagram passwords and add attacker‑controlled email addresses, hijacking accounts—including the Obama White House and a U.S. Space Force profile—without needing victim email access. The breach underscores AI‑driven support as a new attack surface for third‑party risk.

🏭 Media & Entertainment🎯 Vulnerability Exploit
High · Jun 02, 2026 · Security Affairs
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🤖
LIVETHREAT BRIEFSupply Chain Attack Compromises Red Hat Package Repository, Dozens of Packages Pulled

Red Hat removed 32 tainted packages after attackers used a compromised GitHub account to inject a credential‑stealing worm into its distribution pipeline. The packages were downloaded over 117 k times weekly, exposing downstream customers to potential malware infection. TPRM teams should verify package integrity and reassess vendor supply‑chain controls.

🏭 Technology & SaaS⚡ Supply Chain Attack🎯 Stolen Credentials
High · Jun 02, 2026 · The Record
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🔑
LIVETHREAT BRIEFCheat Service Atlas Menu Exposes 64,000 User Accounts in Data Breach

A full‑system compromise of the Atlas Menu cheat platform for GTA V and CS2 resulted in the public release of 64 000 user records, including emails, usernames, IPs, support tickets, and bcrypt‑hashed passwords. The breach highlights credential‑reuse risks for both gamers and any organizations where those credentials overlap.

🏭 Technology & SaaS
High · Jun 02, 2026 · Help Net Security
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF☁️
LIVETHREAT BRIEFCredential‑Stuffing Breach Exposes Genetic Data of ~7 Million 23andMe Users via DNA Relatives Feature

A 2023 credential‑stuffing attack on 23andMe’s login portal led to the compromise of ~14 k accounts. Attackers then exploited a coding flaw in the DNA Relatives feature to harvest genetic data of nearly 7 million customers, prompting a California lawsuit and highlighting severe third‑party risk for health‑tech ecosystems.

🏭 Healthcare & Life Sciences🎯 Stolen Credentials
High · Jun 02, 2026 · Malwarebytes Labs
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF☁️
LIVETHREAT BRIEFSupply Chain Attack Compromises 30+ Red Hat npm Packages, Harvests Cloud Credentials

Attackers hijacked a Red Hat employee’s GitHub account to publish malicious npm packages containing the Mini Shai‑Hulud payload. The malware steals cloud and CI/CD credentials and attempts to self‑propagate via npm’s bypass_2fa feature, posing a credential‑theft risk to downstream customers.

🏭 Technology & SaaS⚡ Supply Chain Attack🎯 Third-Party Dependency
High · Jun 02, 2026 · Help Net Security
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF💀
LIVETHREAT BRIEFBrute‑Force Attack Exposes Encrypted Vaults of <20 Dashlane Users

Dashlane reported that an external actor performed a brute‑force attack against personal‑plan accounts, bypassing two‑factor authentication and downloading encrypted vaults for fewer than 20 users. The breach highlights weaknesses in 2FA implementation and underscores the need for robust credential‑management controls in third‑party risk programs.

🏭 Technology & SaaS
High · Jun 02, 2026 · The Hacker News
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🔑
LIVETHREAT BRIEFSpanish Police Arrest Doxer Who Leaked Sensitive Data of Government Employees

Spanish authorities have arrested a doxer responsible for publishing personal data of employees from key state bodies, including the National Cybersecurity Institute and the National Police. The leak, sourced from older breaches and OSINT tools, poses national‑security risks and underscores the need for vigilant third‑party data controls.

🏭 Government & Public Sector⚡ Data Exfiltration
High · Jun 01, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🔑
LIVETHREAT BRIEFEdmunds Car‑Shopping Platform Breach Exposes 178 k User Records Including Passwords and Vehicle Data

In January 2026 the ShinyHunters group reported a breach of Edmunds, leaking 177,860 accounts with email, passwords, phone numbers and vehicle data. The exposure creates credential‑reuse and phishing risks for automotive OEMs, dealers and any partner that integrates Edmunds services, making it a high‑priority TPRM concern.

🏭 Transportation & Logistics
High · Jun 01, 2026 · HIBP Latest Breaches RSS
Read Full Intelligence Brief →
Page 1 of 26

Know When Your Vendors Are Breached

LiveThreat monitors this intelligence against your vendor portfolio and alerts you automatically.

Score 10 Vendors on Free Tier → Subscribe via RSS

Daily Breach Intelligence Digest

Get critical and high-severity threats delivered to your inbox every morning. Unsubscribe anytime.

RSS Feed One email per day · No spam · Unsubscribe anytime

START ASSESSING YOUR VENDORS TODAY.

No credit card. No contract. Free vendor assessments.

Score 10 Vendors on Free Tier →