Another detail emerges about Instructure’s agreement with ShinyHunters; Debate continues about whether to pay

Media outlets have been understandably eager to learn whether Instructure paid ShinyHunters after the latter attacked them for a second time on May 7. Considering that they pledged to be more transparent, DataBreaches doesn’t fully understand why… Continue reading Another detail emerges about Instructure’s agreement with ShinyHunters; Debate continues about whether to pay

Welcome to BlackFile: Inside a Vishing Extortion Operation

Google’s Threat Intelligence Group writes: Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the “BlackFile” brand, that targets organizations via… Continue reading Welcome to BlackFile: Inside a Vishing Extortion Operation

Michigan Nurse Convicted in $1.6M Medicare Fraud Scheme Using Stolen Patient Records

Scott McClallen reports: A federal jury in the Eastern District of Michigan convicted a Michigan nurse and home health care agency owner yesterday for operating a $1.6 million scheme to defraud Medicare. Court documents say that Ruby Scott, 55, of Farm… Continue reading Michigan Nurse Convicted in $1.6M Medicare Fraud Scheme Using Stolen Patient Records

UK: Hospital workers inappropriately accessed details of Southport victims, investigation finds

On the Spot News reports: An investigation has revealed than nearly 50 staff at a Merseyside hospital group accessed horrific details of the condition of those attacked in Southport. The investigation has only just come to light, with victims finding o… Continue reading UK: Hospital workers inappropriately accessed details of Southport victims, investigation finds

No need to hack when it’s leaking: Dalbir Singh & Associates law firm edition

Dalbir Singh & Associates ignored multiple attempts at responsible disclosure but finally locked down its misconfigured Amazon bucket, only to expose it again. Now the data is in the hands of criminals trying to extort them.  On April 6, DataBreach… Continue reading No need to hack when it’s leaking: Dalbir Singh & Associates law firm edition

NL: Dutch watchdog says healthcare lab failed data security rules before cyberattack affecting 850,000

In August 2025, research agency Bevolkingsonderzoek Nederland revealed that half a million women who had undergone cervical cancer screening had their data stolen. The research agency paid Nova ransomware gang’s demand, which Nova confirmed, but … Continue reading NL: Dutch watchdog says healthcare lab failed data security rules before cyberattack affecting 850,000