Skip to content

Incidents from

2025

OtherUnknown

Leak at 123 casting

240,000 users name, first name MD5-hashed password (so effectively in plaintext…) date of birth, gender postal address email address phone number height, weight, eye and hair color, measurements ethnic origin distinctive features photo & video book private message history payment data

Victim
123 casting
OtherUnknown

Leak at MΓ©decin Direct

first and last name, date of birth, email address, postal address, social security number, subject of the teleconsultation, pre-consultation questionnaire, data exchanged with the practitioner

Victim
MΓ©decin Direct
OtherUnknown

Leak at Murfy

294,075 customers: first and last name, email address, postal address, phone number, account balance, exchanged messages, comments, reason for visits, technician

Victim
Murfy
OtherUnknown

Leak at Eurofiber

3,600 companies (BPCE, Auchan, CGI, Thales, SFR, Orange…) sensitive network infrastructure data VPN access credentials source code certificates emails SQL backups

Victim
Eurofiber
OtherUnknown

Leak at Pajemploi

1.2 million people last name, first name social security number postal address date and place of birth name of bank Pajemploi number and accreditation number IBAN

Victim
Pajemploi
OtherUnknown

Leak at MYM

5 million customers: username, first and last name, company, postal address, date of birth, password (MD5 hashed), email, phone number, IP address, social networks (Instagram, Facebook, Twitter, Snapchat), date of registration and last login

Victim
MYM
OtherUnknown

Leak at France Travail

16,479 people authentication data in plaintext civil status address, phone number, email ID card RIB employment contracts tax notices Social Security attestation training certificate work authorization

Victim
France Travail
OtherUnknown

Leak at Discord

name, username payment information last 4 digits of payment card transaction history IP address messages exchanged with support ID card age verification documents

Victim
Discord
Social engineeringContained

C&M Software Pix heist (Brazil, 2025)

A junior developer at C&M Software β€” a Central Bank-authorized provider of Pix instant-payment connectivity β€” was paid roughly R$5,000 to hand over credentials. Attackers used the access to drain approximately R$800 million ($148 million) from reserve accounts at six Brazilian financial institutions in 2.5 hours.

Victim
C&M Software (Pix payment infrastructure provider)
Loss
$148.0M
OtherUnknown

Leak at Intersport

3.4 million transaction number invoice number PayPal reference number transaction code start date / end date of the transaction debited or credited transaction gross amount of the transaction payer account number buyer's username delivery and billing address user ID first and last name, payment source loyalty card number

Victim
Intersport
Data breachContained

Yale New Haven Health data breach (2025)

Suspicious network activity at Yale New Haven Health led to the largest U.S. healthcare data breach of 2025: 5.5 million patients had names, contact details, dates of birth, medical record numbers, and Social Security numbers stolen. The health system later agreed to an $18 million class-action settlement.

Victim
Yale New Haven Health System
Loss
$18.0M
Records
5.6M
OtherUnknown

Leak at Nord Emploi

last name, first name phone address recipient number referring organisation RSA & CAF form CV rights opening date deregistration date personalised project notification support arrangements illiteracy status ability to use computer tools childcare solution support from a professional network number of applications professional life associative and professional experience training, skills targeted occupations interests language certification office tools proficiency driving licence

Victim
Nord Emploi
Data breachContained

TelefΓ³nica Hellcat infostealer-to-Jira breach (Spain, 2025)

Infostealer malware on the endpoints of 15+ TelefΓ³nica employees gave the Hellcat ransomware group credentials into the company's internal Jira ticketing system. Social-engineering escalated the access to SSH. The group did not extort β€” it publicly published 2.3 GB including 24,000 employee emails, 470,000 internal Jira tickets, and 5,000 internal documents.

Victim
TelefΓ³nica
Records
500.0K