Breach Watch
Written for risk decisions, not headlines.
Breach, ransomware, vulnerability, advisory and threat intelligence, classified by LiveThreat and analysed in an ADTP brief for every item.
Showing 20 of 2,396
BREACH WATCH BRIEF
ASOS Breach Shows Single SaaS Identity Compromise Can Lead to Deep Corporate Network Access
Attackers stole a credential tied to a customer‑facing SaaS platform used by ASOS and used it to move laterally into internal systems, potentially exposing customer data. The incident highlights the need for strong identity governance and continuous control‑assurance to prove protection of privileged SaaS accounts.
BREACH WATCH BRIEF
Asos Claims Hackers Breached Snowflake‑Connected Simon AI, Exfiltrating Customer Data
Hackers claiming to be the Xuanye Group used stolen employee credentials to access Asos’s Snowflake instance through the Simon AI marketing tool, extracting personal data for millions of customers. The breach underscores the need for continuous third‑party oversight and auditable access controls.
BREACH WATCH BRIEF
FBI Personnel Data Stolen by ShinyHunters Extortion Group; Suspect Arrested in Pennsylvania
ShinyHunters exploited a zero‑day flaw in the FBI's Oracle PeopleSoft HR system, exfiltrating over 2 TB of data on 5,000 agents. A suspect was arrested, highlighting the need for robust third‑party patch management and continuous monitoring for audit readiness.
BREACH WATCH BRIEF
ShinyHunters Claims Breach of FBI Jobs Portal, Suspect Arrested
ShinyHunters announced it breached the FBI jobs portal and stole personal data on most agents and applicants; the FBI later arrested another alleged conspirator. The incident underscores the importance of robust access‑control and continuous monitoring for audit readiness.
BREACH WATCH BRIEF
FBI Arrests ShinyHunters Operative After Pentagon Data Center Compromise
Federal investigators arrested a suspected ShinyHunters forum member linked to a breach of a Pentagon‑run data center via stolen credentials. The incident underscores the need for continuous credential monitoring and audit‑ready access logs for compliance readiness.
BREACH WATCH BRIEF
Unpatched AhsayCBS Backup Platform Vulnerabilities Exploited to Deploy Webshells and Crypto Miners
Threat actors chained two unpatched AhsayCBS flaws (CVE‑2026‑105133 and CVE‑2026‑105134) to install web‑shells and XMRig miners on at least five MSP‑hosted environments. The incident underscores the importance of continuous vulnerability management and auditable patch‑deployment evidence for compliance readiness.
BREACH WATCH BRIEF
ShinyHunters Breach Exposes 2‑3 TB of FBI Employee Data via Unpatched Oracle PeopleSoft on Third‑Party Platform
ShinyHunters exploited an Oracle PeopleSoft zero‑day on a vendor‑managed platform, moving into FBI AWS GovCloud and stealing 2–3 TB of employee data. The breach highlights the need for continuous third‑party risk monitoring and verifiable patch‑management evidence for audit readiness.
BREACH WATCH BRIEF
iRhythm Biosensor Firm Breach Exposes Data of 360,000 Patients via Third‑Party Application Compromise
A June cyberattack on iRhythm’s third‑party business applications led to unauthorized access and exfiltration of personal and health data for at least 360,000 individuals. The incident highlights the need for continuous third‑party oversight and defensible audit evidence for compliance readiness.
BREACH WATCH BRIEF
FBI Arrests Another ShinyHunters Member After Data Breach of FBIjobs.gov Linked to Unpatched Contractor System
The FBI detained a further ShinyHunters affiliate after the group compromised the FBIjobs.gov portal, stealing personal data on federal employees. The intrusion was linked to an Accenture contractor who failed to patch a known Oracle vulnerability, highlighting a critical third‑party risk gap.
BREACH WATCH BRIEF
Belarusian Hacktivists Claim 2023 Breach of Russian State Healthcare Network, Gaining Admin Access to Sensitive Medical Data
The Belarusian Cyber Partisans admitted to infiltrating the Moscow Department of Health in 2023, obtaining administrator‑level access and viewing sensitive medical information. The breach underscores the importance of robust privileged‑access controls and continuous monitoring for audit readiness.
BREACH WATCH BRIEF
ASOS Breach: Attackers Use Stolen Employee Credentials to Exfiltrate Customer Profiles and Search History
ASOS confirmed that attackers obtained employee login credentials and accessed its Simon AI personalization platform, stealing names, addresses, dates of birth and shopping‑search histories. The incident underscores the need for strong credential controls and auditable monitoring to satisfy trust and control‑assurance requirements.
BREACH WATCH BRIEF
AI‑Powered ARTEX Tool Used to Breach South Korean Financial Institutions
CrowdStrike reports that attackers leveraged the open‑source ARTEX AI pentesting framework together with large language models to infiltrate multiple South Korean banks, exfiltrating loan‑progress and mobile‑work data. The incident highlights the need for AI governance controls and continuous evidence collection for audit readiness.
BREACH WATCH BRIEF
Neogen Exposes 436K Corporate Contacts in ShinyHunters Extortion Breach
In August 2026 ShinyHunters extorted Neogen and released a dataset of 436 000 corporate contacts. The breach highlights gaps in access‑control monitoring and the need for auditable evidence of data‑handling controls.
BREACH WATCH BRIEF
Chinese‑Linked Hackers Ran Public Portal Giving Third Parties Access to Stolen Emails from Government, Health, and Religious Entities
State‑linked actors stole email archives from multiple Southeast Asian sectors and exposed them via an open portal. The breach highlights the need for continuous third‑party risk monitoring and audit‑ready evidence of vendor oversight.
BREACH WATCH BRIEF
Convicted Consultant Exploits Smart‑Contract Flaws to Steal $54 M from Uranium Finance Exchange
A cybersecurity consultant was convicted after abusing vulnerabilities in Uranium Finance’s smart contracts to siphon $54 million, forcing the exchange to shut down. The incident underscores the need for auditable secure‑development controls to satisfy trust and control‑assurance requirements.
BREACH WATCH BRIEF
Hackers Compromised an ASOS Employee Account to Send a Rogue Push Notification, Exposing Limited Customer Data
ASOS disclosed that attackers impersonated a trusted contact to gain an employee’s credentials, allowing them to push a fraudulent notification to customers and view limited personal information. The incident highlights the need for robust identity controls and security‑awareness programs to meet audit and trust requirements.
BREACH WATCH BRIEF
Hackers Breach Two South Korean Megachurches, Exposing Data of Up to 850,000 Members
Two of South Korea's largest Protestant churches suffered cyberattacks that led to the theft of personal, financial, and internal records for hundreds of thousands of congregants. The breach highlights gaps in access control and privileged account management, underscoring the need for continuous control assurance.
BREACH WATCH BRIEF
ASOS Data Breach Linked to Social Engineering Credential Theft Exposes Customer Personal Info
ASOS confirmed that a social‑engineering attack stole an employee’s login credentials, allowing attackers to access third‑party platforms and expose names and contact details. The incident underscores the need for continuous identity‑access monitoring and third‑party oversight for audit readiness.
BREACH WATCH BRIEF
MonsterCloud Owner Charged with $19 M Fraud After Secretly Paying Ransomware Decryptors
The DOJ has indicted MonsterCloud’s owner for billing ransomware victims while covertly paying attackers to obtain decryption keys, exposing a critical gap in third‑party oversight. Organizations must tighten vendor risk controls to maintain audit‑ready evidence of due diligence.
BREACH WATCH BRIEF
Oracle Health’s Cerner EHR Breach Affects 20 Million Patients After Stolen‑Credential Attack on Legacy Servers
An unknown actor used stolen credentials to breach legacy Cerner EHR servers, exposing the health data of about 20 million patients. The breach underscores the need for continuous third‑party risk monitoring and documented migration controls to satisfy audit and compliance expectations.
Breach Watch intelligence is provided by LiveThreat, a product of a founding sponsor of the association. Every ADTP brief carries LiveThreat's analysis and links the original source.
Practitioner briefings
Written by the association: what the week's intelligence means for the controls you run.
Reading a vendor's breach notice for what it does not say
A practitioner checklist for turning a supplier notification into an evidence request and a monitoring change.
Where AI inventory efforts stall, and the control that unblocks them
Findings from practitioner roundtables on AI governance programs in their first year.
Evidence reuse across customer diligence and audit
How practitioners are organizing one evidence base to serve buyers and auditors at the same time.
Global Privacy Control signals and state opt-out obligations
What a site must do when it sees a GPC signal, and how to evidence it.
Get the digest
No membership required. Confirm by email; unsubscribe in one click.