Visualização normal

Hoje — 9 de Setembro de 2026Stream principal
  • ✇Security Affairs
  • Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data Pierluigi Paganini
    An exposed Vietnam-linked APIS database contained 220.8 million passenger and crew records, including passport and flight data. Researchers found an exposed Advance Passenger Information System (APIS) database containing 220.8 million passenger and crew records from January 2017 to April 2026. The data includes sensitive details such as passport numbers, identities and flight information, potentially affecting travelers of many nationalities who flew to, from or through Vietnam. Kinryū L
     

Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data

8 de Setembro de 2026, 08:01

An exposed Vietnam-linked APIS database contained 220.8 million passenger and crew records, including passport and flight data.

Researchers found an exposed Advance Passenger Information System (APIS) database containing 220.8 million passenger and crew records from January 2017 to April 2026.

The data includes sensitive details such as passport numbers, identities and flight information, potentially affecting travelers of many nationalities who flew to, from or through Vietnam. Kinryū Labs discovered the Elasticsearch cluster, named “pax-info,” while searching for exposed databases.

It contained 29 indices and about 107 GB of data. The researchers linked the server to IP space assigned to Viettel in Hanoi, but could not confirm which Vietnamese organization operated it.

Researchers found an exposed APIS database linked to Vietnam that contained more than 220 million passenger and crew records from 2017 to 2026. The data included passport numbers, identities and flight details. The Elasticsearch database, discovered by Kinryū Labs, held about 107 GB of data across 29 indices. It was hosted on IP addresses assigned to Viettel in Hanoi, although researchers could not confirm which Vietnamese organization operated the system.

The exposed database contained names, dates of birth, sex, nationalities, passport or travel-document numbers, expiration dates and issuing countries, BleepingComputers reports.

It also included flight numbers and dates, airlines, departure and destination airports, transit airports, seat numbers, baggage references, and scheduled, estimated and actual flight times. The database covered many airlines across Asia-Pacific, Europe and the Middle East, so it could affect people from around the world who traveled to or through Vietnam between 2017 and 2026.

Kinryū Labs confirmed the data was real by matching records with its researchers’ own trips to Vietnam. The total also counts travel records, not unique people, so frequent travelers may appear multiple times.

While the researchers could not provide a complete breakdown by nationality, the data covered numerous international airlines across Asia-Pacific, Europe, and the Middle East. As a result, the exposed records could relate to people from virtually anywhere who visited or transited through Vietnam over the nine-year period.

Kinryū Labs verified that the information was legitimate by matching records in the database against its researchers’ own travel to Vietnam.

The figures represent travel records rather than unique individuals. Passengers and crew members who flew multiple times may therefore appear repeatedly in the database.

Kinryū Labs reached the exposed database by combining two security misconfigurations. Direct internet access returned a 401 error, but another cloud-based path exposed the cluster and accepted default credentials.

FOFA first detected the host in 2022 and identified it as a database in 2023, but researchers could not determine when the passenger data became accessible. The records cover more than nine years, but the actual exposure period remains unknown.

Kinryū Labs reported the issue to Vietnamese authorities, affected airlines and national CERTs on June 3. The database was secured by June 8, with Singapore Airlines helping coordinate the response.

Researchers found no evidence that the listed airlines operated the system or suffered a network breach. They also found no ransom notes or signs that attackers had altered the database.

However, without server logs, they could not determine whether anyone had copied or stolen the data before the system was secured.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, APIS)

  • ✇Firewall Daily – The Cyber Express
  • Exposed Database Left 220Mn Airline Passenger, Crew Records Open to the Internet Mihir Bagwe
    A misconfigured Elasticsearch cluster exposed roughly 220.8 million airline passenger and crew records, including passport numbers and full itineraries, before it was secured in June, researchers at Kinryu Labs disclosed. The records spanned January 2017 through April 2026 and came from an Advance Passenger Information System deployment - the standardized data feed airlines transmit to border authorities before departure, covering traveler identity and flight details. Researchers linked the ser
     

Exposed Database Left 220Mn Airline Passenger, Crew Records Open to the Internet

8 de Setembro de 2026, 11:51

Airline, Data Leak,

A misconfigured Elasticsearch cluster exposed roughly 220.8 million airline passenger and crew records, including passport numbers and full itineraries, before it was secured in June, researchers at Kinryu Labs disclosed.

The records spanned January 2017 through April 2026 and came from an Advance Passenger Information System deployment - the standardized data feed airlines transmit to border authorities before departure, covering traveler identity and flight details. Researchers linked the server to IP address space assigned to Vietnamese telecommunications operator Viettel in Hanoi but said they could not confirm which organization operated it.

What was exposed

As per BleepingComputer, the data set combined identity documents with granular travel history. Exposed fields included names, dates of birth, sex and nationality; passport or travel document numbers, expiration dates and issuing countries; and flight numbers and dates, airline names, departure, destination and transit airports, seat numbers, baggage references, and scheduled, estimated and actual flight times.

That combination is unusually sensitive. Passport numbers are difficult to change and useful for identity fraud and account takeover at travel providers, while the itinerary fields - particularly transit airports and actual flight times - allow reconstruction of an individual's movements over nine years. Security researchers have long flagged APIS-style data as a surveillance risk precisely because it maps people to places at fixed times.

Also read: Why Airline Data Breaches Matter – And Why Qantas Could Have Been Worse

Two misconfigurations

According to Kinryu Labs, the cluster was protected inconsistently. Direct access over the internet returned an HTTP 401 authentication error, which would give a casual scanner the impression the system was locked down. An alternative cloud-based access path, however, reached the same cluster and accepted default credentials.

The exposure appears to have been long-lived. Internet scanning service FOFA detected the host in 2022 and identified it as a database in 2023. Kinryu Labs reported the issue on June 3, 2026, and the cluster was secured by June 8. Singapore Airlines assisted in coordinating the response, the researchers said. There is no indication any airline was itself breached or operated the server.

Researchers said they found no evidence the data was stolen, but noted that without server logs they could not determine whether anyone copied it during the years it was reachable — a distinction that matters more than it may appear, because notification obligations in several jurisdictions turn on whether unauthorized access can be ruled out.

Compliance exposure

Vietnam's Personal Data Protection Law, Law No. 91/2025/QH15, took effect Jan. 1, 2026 - before the exposure was reported and remediated. The statute requires notification within 72 hours of detecting a violation, rather than from the time it occurred, and expands notification duties to affected individuals in defined circumstances. Its penalty ceiling for general violations is 3 billion Vietnamese dong, with cross-border transfer breaches exposed to fines of up to 5% of prior-year revenue.

Because the records cover international flights, EU and UK residents are almost certainly represented, which brings GDPR and UK GDPR into scope for any controller established in or targeting those markets. Passport numbers and travel history fall squarely within personal data, and passenger data processing has drawn repeated scrutiny from European data protection authorities.

Antes de ontemStream principal
  • ✇Cybersecurity News
  • Trezor Data Breach at ShipMonk Grows to 80,000 Customers Do Son
    The Trezor data breach at shipping partner ShipMonk exposed about 80,000 customers' order data. Wallets are safe, but phishing risk is high. Related Posts: Massive IDScan Data Breach Reported Independent Investigation Reveals 1,200 OpenAI Agents Breached Isolation in Hugging Face Attack JetBrains Cadence Server Compromised The post Trezor Data Breach at ShipMonk Grows to 80,000 Customers appeared first on Daily CyberSecurity.
     
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 1, September 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 1, September 2026           ZaWoo Data Extortion Attacks Against Multiple Organizations Worldwide Black X Ransomware Attack on a South Korean Automotive Parts Manufacturer Internal Data of a South Korean Asset Management and Investment Firm Offered for Sale
     

Ransom & Dark Web Issues Week 1, September 2026

Por:ATCP
2 de Setembro de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 1, September 2026           ZaWoo Data Extortion Attacks Against Multiple Organizations Worldwide Black X Ransomware Attack on a South Korean Automotive Parts Manufacturer Internal Data of a South Korean Asset Management and Investment Firm Offered for Sale
  • ✇Cybersecurity News
  • JetBrains Cadence Server Compromised Do Son
    An unpatched JetBrains Cadence server exposed cloud infrastructure, AWS credentials, and critical developer secrets. Discover the details of this severe breach. Related Posts: Meta Settles Child Privacy Lawsuit Rapidly Mercor Data Breach Targets AI Supply Chain Exposed Git Repositories Leak Critical Cloud Secrets The post JetBrains Cadence Server Compromised appeared first on Daily CyberSecurity.
     

JetBrains Cadence Server Compromised

Por:Do Son
30 de Agosto de 2026, 23:50

An unpatched JetBrains Cadence server exposed cloud infrastructure, AWS credentials, and critical developer secrets. Discover the details of this severe breach.

Related Posts:

The post JetBrains Cadence Server Compromised appeared first on Daily CyberSecurity.

  • ✇Cybersecurity News
  • Meta Settles Child Privacy Lawsuit Rapidly Do Son
    Discover the details of Meta's massive $18 billion child privacy lawsuit settlement. Learn how new platform restrictions will impact young users worldwide. Related Posts: Mercor Data Breach Targets AI Supply Chain Exposed Git Repositories Leak Critical Cloud Secrets Take-Two Subpoenas Microsoft and Discord Over GTA VI "Cyberleek" Leaks The post Meta Settles Child Privacy Lawsuit Rapidly appeared first on Daily CyberSecurity.
     

Meta Settles Child Privacy Lawsuit Rapidly

Por:Do Son
27 de Agosto de 2026, 05:30

Discover the details of Meta's massive $18 billion child privacy lawsuit settlement. Learn how new platform restrictions will impact young users worldwide.

Related Posts:

The post Meta Settles Child Privacy Lawsuit Rapidly appeared first on Daily CyberSecurity.

  • ✇Cybersecurity News
  • Mercor Data Breach Targets AI Supply Chain Do Son
    Discover the details of the massive Mercor data breach exposing 4TB of recruiting data for OpenAI, Google, Meta, and Microsoft. Related Posts: Meta Settles Child Privacy Lawsuit Rapidly Exposed Git Repositories Leak Critical Cloud Secrets Take-Two Subpoenas Microsoft and Discord Over GTA VI "Cyberleek" Leaks The post Mercor Data Breach Targets AI Supply Chain appeared first on Daily CyberSecurity.
     
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 4, August 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 4, August2026           Saudi Arabian Digital Entertainment Streaming Service User Data Offered for Sale SAFEPAY Ransomware Attack on a South Korean Industrial Gas Manufacturer and Supplier NoName057(16) and BD Anonymous Claim DDoS Attacks Against Major Japanese Organizations and Companies [1] [2] [3] […]
     

Ransom & Dark Web Issues Week 4, August 2026

Por:ATCP
26 de Agosto de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 4, August2026           Saudi Arabian Digital Entertainment Streaming Service User Data Offered for Sale SAFEPAY Ransomware Attack on a South Korean Industrial Gas Manufacturer and Supplier NoName057(16) and BD Anonymous Claim DDoS Attacks Against Major Japanese Organizations and Companies [1] [2] [3] […]
  • ✇Security Affairs
  • Cybercriminals Turn GTA VI Leaks Into Malware Bait Pierluigi Paganini
    A fake 113GB GTA VI build is packed with malware, using massive empty files to hide a tiny malicious payload. GTA VI hype has reached the point where people are volunteering to infect their own computers just to check if a leak is real. Someone on X asked their followers to “take one for the team” and test a 113GB file claiming to be a playable Grand Theft Auto VI build, according to Tom’s Hardware’s reporting. Someone did, and the results were exactly what you’d expect. A user that goes
     

Cybercriminals Turn GTA VI Leaks Into Malware Bait

24 de Agosto de 2026, 14:27

A fake 113GB GTA VI build is packed with malware, using massive empty files to hide a tiny malicious payload.

GTA VI hype has reached the point where people are volunteering to infect their own computers just to check if a leak is real. Someone on X asked their followers to “take one for the team” and test a 113GB file claiming to be a playable Grand Theft Auto VI build, according to Tom’s Hardware’s reporting. Someone did, and the results were exactly what you’d expect.

A user that goes online with the handler @Aidas29506493 analyzed the file and found that it was completely fake and contained malware. Almost all of its 113GB consisted of empty data, with a tiny malicious payload hidden inside.

did some reverse engineering.
it is fully fake and full of viruses pic.twitter.com/An6VnSNTkd

— Aidas (@Aidas29506493) August 22, 2026

“The decompiled bytecode literally contains commands to whitelist the entire C:\ drive in Windows Defender (powershell Add-MpPreference -ExclusionPath %SystemDrive%\) and kill security software (taskkill -f),” The researcher added in a post on X. They also added in another response, “It’s not 100 GB of actual code—it’s just a tiny 50 KB virus padded with 99.99% empty junk (literally endless zeroes).”

It’s not 100 GB of actual code—it’s just a tiny 50 KB virus padded with 99.99% empty junk (literally endless zeroes).

— Aidas (@Aidas29506493) August 22, 2026

The malware became obvious when researchers examined its code. It included commands to exclude the entire C: drive from Windows Defender and shut down other security software. Anyone who ran it could effectively disable their antivirus before the malware launched its next stage. This was not an accidental side effect, it was a deliberate step to prepare the system for further attacks.

This particular fake didn’t appear in a vacuum. According to to the website IGN, that fake GTA 6 downloads have flooded piracy and torrent sites throughout the recent leak wave, riding genuine momentum from a leaker going by CyberLeek, who’s been releasing real gameplay clips and map footage in protest of Rockstar’s digital pre-order plans. That real leak activity is exactly what makes the fake downloads believable, since fans searching for CyberLeek’s actual content are primed to trust whatever else shows up alongside it.

Every time GTA 6 appears in the news because of leaked footage, people quickly share it across Discord, mirror sites and other platforms. This creates the perfect conditions to trick users with fake downloads and phishing pages. With real and fake content mixed together, it becomes harder for users to tell what is safe.

The scams go beyond huge fake game files. Researchers have found fake GTA 6 websites offering Windows installers that use DLL side-loading to run malware. They also found a fake “GTA 6 Mobile” app that redirects users to a domain linked to infostealers and ransomware. Other fake Rockstar Social Club login pages try to steal users’ account credentials.

None of this should be surprising given the numbers involved. Kaspersky separately documented over 19 million attempted downloads of malware disguised as popular game titles across a single year, with GTA, Minecraft, and Call of Duty topping the list of abused brands specifically because of their large, dedicated communities. Big anticipated titles are a magnet for this stuff regardless of whether there’s an active leak cycle happening, and GTA VI right now has both the hype and the leak chaos simultaneously.

There is no legitimate playable build of GTA VI circulating anywhere, full stop. The game launches November 19 on consoles, with a PC version to follow, and the only responsible move for anyone tempted by a torrent claiming otherwise is to close the tab. If the file looks too good to be true and it’s a hundred gigabytes of an unreleased AAA game showing up on a torrent site months early, it’s not a leak, it’s bait.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, GTA VI Leaks)

  • ✇Firewall Daily – The Cyber Express
  • 678,000 People Hit in French Tax Authority Data Breach Samiksha Jain
    A DGFiP cyberattack has exposed sensitive tax and cadastral information after attackers allegedly used stolen credentials to access systems belonging to France's Directorate General of Public Finances. The French Public Finances Directorate said investigations found that data linked to 678,000 individuals and professionals had been consulted and extracted during intrusions in June and July 2026. The DGFiP cyberattack incidents were identified after a malicious actor claimed illegitimate acces
     

678,000 People Hit in French Tax Authority Data Breach

18 de Agosto de 2026, 03:57

DGFiP cyberattack

A DGFiP cyberattack has exposed sensitive tax and cadastral information after attackers allegedly used stolen credentials to access systems belonging to France's Directorate General of Public Finances. The French Public Finances Directorate said investigations found that data linked to 678,000 individuals and professionals had been consulted and extracted during intrusions in June and July 2026. The DGFiP cyberattack incidents were identified after a malicious actor claimed illegitimate access to the French tax authority's information system on August 12 and 13. DGFiP said the intrusions involved the usurpation of identifiers belonging to a DGFiP agent and an authorized third party.

DGFiP Cyberattack Exposed Taxpayer Information

After detecting the intrusions, DGFiP immediately suspended access to the accounts involved. Initial access controls did not identify data theft, which the authority attributed to the sophistication of the attack. A subsequent investigation established that the compromised access points had been used to consult and extract information concerning 678,000 individuals and professionals. The exposed information included reference tax income, family quotient and withholding tax rate for individuals. For businesses, the accessed information included company names and SIREN numbers. Cadastral data, including addresses and property sizes, was also accessed. DGFiP said online accounts belonging to individual and professional users were not compromised, and user IDs and passwords were not affected. The authority notified France's data protection regulator, CNIL, after identifying the data breaches.

Cadastral Data Leak Claim Targets DGFiP

Separately, a hacker using the alias ZeroBytes claimed an attack against DGFiP's Professional Cadastral Data Server (SPDC). According to the claim cited by FrenchBreaches, the alleged extraction contains 252,149 lines of data representing 2,041,778 people, with multiple holders potentially associated with the same property plot. The claimed dataset reportedly includes names, surnames, sex, dates and places of birth, addresses, land identifiers, cadastral sections and parcel numbers, as well as information about rights held on properties. The claim would therefore link individuals to personal information and real estate assets. However, the figures and technical details in this second claim remain allegations by the cybercriminal. The claim that the system could contain information relating to approximately 20 million citizens is also an estimate made by ZeroBytes and does not establish that this number of people was affected.

Investigation Into French Tax Authority Attack Continues

DGFiP said additional security measures were implemented after investigators uncovered new information. These included preventative shutdowns of access to sensitive information systems. Investigations remain underway to determine the precise nature and volume of data extracted and the number of users affected. DGFiP teams are working with France's economic and financial ministries, the High Official for Defence and Security and the National Agency for Information Systems Security, ANSSI. The authority said it will contact affected individuals and professionals directly from the following week by email or letter. Those notifications will identify the information that may have been accessed or extracted and outline any precautionary measures where applicable. DGFiP also said it will file a complaint and provide further information as the investigation progresses. The separate cadastral data breach claim remains subject to confirmation, including the alleged number of affected people, duration of access, methods used to bypass authentication, the full scope of extracted information and whether access remained active when the claim was published. The confirmed DGFiP investigation and the separate ZeroBytes claim therefore present different sets of figures and allegations, with the full scope of the incidents still being determined.
  • ✇Security Affairs
  • Chess.com Leak Exposes 7.3 Million Users – Evidence Points to Scraping Pierluigi Paganini
    7.3 million Chess.com profiles leaked online: the data is genuine, but evidence points to large-scale scraping, not a server breach. Free is a strange price for stolen data, and that’s exactly what makes this listing worth a second look. A 15.5 GB file containing over 7.3 million chess.com user records showed up on two data-leak forums this week, no cost, no ransom demand, just handed out. Ransomnews’s technical analysis confirms the data is real and recent. What it isn’t, on the evidence, i
     

Chess.com Leak Exposes 7.3 Million Users – Evidence Points to Scraping

14 de Agosto de 2026, 05:24

7.3 million Chess.com profiles leaked online: the data is genuine, but evidence points to large-scale scraping, not a server breach.

Free is a strange price for stolen data, and that’s exactly what makes this listing worth a second look. A 15.5 GB file containing over 7.3 million chess.com user records showed up on two data-leak forums this week, no cost, no ransom demand, just handed out. Ransomnews’s technical analysis confirms the data is real and recent. What it isn’t, on the evidence, is a hack.

“The archive is a single 744 MB 7-Zip file that expands to a 15.5 GB tab-separated table: one header row and 7,337,395 records, each with 38 fields. The schema is chess.com-specific throughout. Alongside the obvious identifiers, email, partial email, username, user ID, UUID, first and last name, country, location and locale, it carries platform state: chess title, points, skill level, premium status and label, verification and activation flags, best rating and rating type, official rating, member-since and last-login timestamps.” reads the report published by Ransomnew. “Two fields at the end are the interesting ones. Every record has gam_audiences and audiences_member_of populated, Google Ad Manager audience segments, with values like coach-nudge experiment groups, trial eligibility, lapsed-user cohorts and rating-band targeting. Those are marketing-stack fields, not profile data. They do not appear in chess.com’s public API.”

The file carries email addresses, usernames, real names, countries, chess ratings, subscription tiers, and something odder: internal Google Ad Manager audience tags, the kind of marketing segmentation data that never shows up in chess.com’s public API. Roughly three-quarters of records include an email address. There are no passwords, no password hashes, and no payment data anywhere in the file, which matters a lot for how seriously affected users need to react.

Proving this data is genuine didn’t require touching chess.com’s servers at all. Every account UUID in the file is a version-1 identifier, the kind that embeds the exact timestamp it was generated, and researchers decoded that hidden timestamp across 200,000 sample records to compare it against each account’s registration date. The match rate came back at 100%, which isn’t something anyone could fake without possessing actual chess.com-issued identifiers down to the millisecond.

Three separate details point toward scraping rather than an actual system breach. The data wasn’t captured in one moment, it was stamped across nine consecutive days in daily batches, the pattern of a scheduled collection job rather than a single database dump. About 7.4% of user records appear twice, the same accounts revisited on different days, something that simply doesn’t happen inside a genuine database export.

This has happened to chess.com before, and the company was blunt about it at the time. Back in 2023, a similar leak of 828,000 records surfaced with a nearly identical field structure, and chess.com stated plainly,

“In November 2023 a threat actor published 828,000 chess.com records with a near-identical field set. Chess.com’s response then was unambiguous: as it told Hackread, “This was NOT a data breach.” continues the report. “Our infrastructure, member accounts, and data such as passwords are secure.” The data had been pulled by abusing the platform’s find-friends feature, feeding in externally sourced email addresses to resolve them against accounts. A second scrape affecting roughly 476,000 users followed. This 2026 file is the same technique at roughly nine times the scale.”

That earlier incident came from abusing the platform’s find-friends feature to resolve external email lists against real accounts; this new file looks like the same technique running at roughly nine times the scale.

One detail doesn’t fit a purely public-facing scrape, though. Advertising-audience segment data isn’t something chess.com’s open API exposes, and it appears on every single row in this file, which suggests whoever built this had access to an authenticated or internal-facing endpoint rather than just the public developer tools. That’s the specific question chess.com is best positioned to answer, and it’s the one that actually matters for understanding how this happened.

The account distributing the file, going by V0idix, isn’t monetizing anything here. The same handle has posted dozens of free database dumps across other unrelated companies, building reputation through volume rather than through sales, which fits a collector who harvests and republishes data rather than someone selling access to a fresh intrusion.

None of this means chess.com users should shrug it off just because passwords weren’t exposed. A verified email sitting next to a real name, country, skill rating, and subscription tier is more than enough raw material for a convincing phishing message about a membership renewal or a fair-play dispute. The right response isn’t panicking about a hacked account, it’s treating unexpected chess.com emails with more suspicion than usual and checking whether that same email address has turned up anywhere else, since reused credentials remain the far more dangerous exposure than anything sitting in this particular file.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Chess.com)

  • ✇ASEC BLOG
  • July 2026 Dark Web Breach Incident Trend Report ATCP
    Note The July 2026 Dark Web Breach Incident Trend Report was compiled based on data breach cases posted on deep web and dark web forums. Due to the nature of some posts, it is difficult to fully verify their accuracy; some posts related to South Korea included AI-generated false data or cases where it could […]
     
  • ✇Security Affairs
  • Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance Records Pierluigi Paganini
    An exposed SISVISA database leaked 102,215 Brazilian health records, exposing IDs, tax data, and regulatory documents without authentication. Researcher Jeremiah Fowler found a publicly accessible database that turned out to belong to SISVISA, Brazil’s Health Surveillance Information System, and alerted ExpressVPN, which later shared the findings with Hackread. The exposed instance held exactly 102,215 files, roughly 79 GB of data, tied to a platform regulators use to track health rules,
     

Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance Records

6 de Agosto de 2026, 13:44

An exposed SISVISA database leaked 102,215 Brazilian health records, exposing IDs, tax data, and regulatory documents without authentication.

Researcher Jeremiah Fowler found a publicly accessible database that turned out to belong to SISVISA, Brazil’s Health Surveillance Information System, and alerted ExpressVPN, which later shared the findings with Hackread.

The exposed instance held exactly 102,215 files, roughly 79 GB of data, tied to a platform regulators use to track health rules, issue licences and manage inspections for hospitals, restaurants and pharmacies. In other words, it wasn’t some forgotten test box in a corner; it was wired into how the state does its job.

“Over 102,000 private records belonging to Brazil’s health surveillance system were left online without passwords or basic encryption.  Security researcher Jeremiah Fowler found this publicly accessible database and alerted cybersecurity firm ExpressVPN, which later shared the details with Hackread.com.” reads the report published by Hackread. “According to Fowler, this open database stored exactly 102,215 files (around 79GB). Further probing revealed that these records belong to Brazil’s Health Surveillance Information System (SISVISA). For your information, this is a crucial platform used by Brazilian health authorities to track public health rules, issue business permits, and manage inspections for hospitals, restaurants, and pharmacies.”

Once inside, Fowler didn’t need exploits or clever tricks. Anyone who knew the URL could browse folders called “backups”, “imports”, “documents” and “uploads” with no login at all. Inside there were full names, home addresses, phone numbers, CPF and CNPJ tax IDs, scans of driver’s licences and federal doctor ID cards, photos of faces and fingerprints, inspection reports, complaint records and compressed backup archives.

This is the kind of data that doesn’t just identify you; it lets someone convincingly pretend to be you. With that in hand, attackers can run phishing and impersonation campaigns, open lines of credit, or plug tax IDs into other breached datasets until something cracks. They can also weaponise the files themselves by adding malware to documents and re-uploading them, or by locking the whole thing and asking for ransom.

During the investigation, Fowler found that the exposed server could be accessed without login credentials, revealing sensitive personal and government documents, including IDs, tax records, photos, and regulatory files.

“Scammers can get quick access to sensitive data like tax numbers or photos of driver’s licenses and trick people or steal funds. They may also download the files, add viruses to them, and put them back online or even lock the whole system and demand ransom to return access.” continues the report.

If you’ve spent years pushing “go digital” inside a public body, this is the flip side. SISVISA replaced slow, paper-based workflows in 2015 and made it much easier to approve applications and track compliance. That speed gain is real, but paper stored in a filing cabinet doesn’t show up in a Shodan scan or get scraped at scale in a weekend.

It’s still not clear whether this instance was run directly by a government team or handed off to a third-party provider. Fowler sent urgent notices to several agencies; public access went away shortly afterwards, but no one ever replied, and there’s no public timeline for how long the data was exposed or who else may have pulled it. That silence is a finding in sé, and not il migliore.

“However, Fowler clarified that it is still unclear if government staff ran this database themselves or hired a third party to do it.” concludes the report. “The researcher sent quick warnings to several government offices after finding the exposed data, and public access was turned off shortly after that. However, no official ever replied to the warnings, so no one knows how long the files were left open or if anyone accessed them already.”

From a defender’s point of view, the scenario is depressingly familiar: a critical system, no authentication, no encryption, and no clear owner who feels personally responsible. The twist here is the domain: health surveillance, with fingerprints and medical regulators in the mix, not just another marketing list. That raises the stakes for fraud and for long-term abuse of identity data.

If you suspect you or your organisation might be in that dataset, you can’t retroactively make it private. What you can do is watch financial accounts more closely, treat unexpected calls and emails that reference tax IDs or licences as hostile by default, and turn on multi-factor authentication wherever it’s available.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, SISVISA)

  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 1, August 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 1, August 2026           South Korean Automotive Parts Manufacturer’s Internal Server Access and Database Offered for Sale Data of a Turkish HR Consulting Company Offered for Sale Gunra Ransomware Attack on a South Korean Heavy Equipment Parts and Advanced Materials Manufacturer
     

Ransom & Dark Web Issues Week 1, August 2026

Por:ATCP
5 de Agosto de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 1, August 2026           South Korean Automotive Parts Manufacturer’s Internal Server Access and Database Offered for Sale Data of a Turkish HR Consulting Company Offered for Sale Gunra Ransomware Attack on a South Korean Heavy Equipment Parts and Advanced Materials Manufacturer
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 5, July 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 5, July 2026           Termite Ransomware Attack on a U.S. Nonprofit Healthcare Provider ShinyHunters Claims Data Leak Involving a Global Accounting and Consulting Firm The Gentlemen Ransomware Attack on a South Korean IT Software Distributor and Infrastructure Service Provider
     

Ransom & Dark Web Issues Week 5, July 2026

Por:ATCP
29 de Julho de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 5, July 2026           Termite Ransomware Attack on a U.S. Nonprofit Healthcare Provider ShinyHunters Claims Data Leak Involving a Global Accounting and Consulting Firm The Gentlemen Ransomware Attack on a South Korean IT Software Distributor and Infrastructure Service Provider
  • ✇Security Affairs
  • VPN Breach Exposes 58 Million Connection Logs Despite “No-Logs” Claims Pierluigi Paganini
    A breached “no-logs” VPN exposed 58 million connection logs and millions of user, device, and payment records, contradicting its privacy claims. A threat actor on the Altenen cybercrime forum is distributing a 17 GB SQL database claimed to have been stolen from SplitVPN, formerly known as NotVPN, a Russian VPN marketed for bypassing internet censorship. Mysterium’s research team obtained a copy, verified it against the raw dump, and confirmed the numbers: roughly 23.4 million user records, 1
     

VPN Breach Exposes 58 Million Connection Logs Despite “No-Logs” Claims

29 de Julho de 2026, 05:28

A breached “no-logs” VPN exposed 58 million connection logs and millions of user, device, and payment records, contradicting its privacy claims.

A threat actor on the Altenen cybercrime forum is distributing a 17 GB SQL database claimed to have been stolen from SplitVPN, formerly known as NotVPN, a Russian VPN marketed for bypassing internet censorship. Mysterium’s research team obtained a copy, verified it against the raw dump, and confirmed the numbers: roughly 23.4 million user records, 13.6 million device records, 2.6 million payment records, and 58 million connection logs. A VPN that promised zero logs kept tens of millions of them.

“NotVPN’s own marketing promises “No logs or history: We never store your activity or connection logs. 100% privacy guaranteed.” The database contains a table (deviceProxy) that records which device connected to which server, and exactly when — nearly 58 million times, right up to the day of the breach.” states Mysterium’s research team. “No full credit-card numbers were exposed (card data is masked to BIN + last four). But emails, IP addresses, device identifiers, approximate location, subscription status, and recurring-billing tokens were.”

VPN

The timestamps run continuously from June 2025 to July 21, 2026, the day of the dump. These aren’t stale test records. The service was still writing connection logs as it was being breached.

The deviceProxy table structure is simple: which device, which server, what time. That’s a connection log. Cross-referenced with the users table, which holds account emails and last-seen IP addresses, and the device table, which holds hardware identifiers, those 58 million rows are enough to reconstruct who connected, from where, to which server, and when, for tens of millions of people.

“A VPN’s single most important promise is that it doesn’t keep the records that would let anyone reconstruct your activity. NotVPN kept them by the tens of millions.” continues the report.

To be precise: the logs record server connections, not destination websites visited. This is metadata, not full browsing history. But metadata is exactly what “we never store your connection logs” promises not to keep.

The seller lists the user base as concentrated in Russia, Iran, India, and Myanmar. That’s not an arbitrary demographic detail.

“The seller lists the user base as concentrated in Russia, Iran, India, and Myanmar. Look at that list again. These are places where people reach for a VPN specifically to get around state censorship: to read independent news, to use blocked messaging apps, to speak freely. For those users, a leaked email-plus-IP-plus-timestamp record isn’t an abstract privacy nuisance.” continues the report. “It’s a document that ties a real person to the act of evading state controls, sitting in a file now circulating on a criminal forum.”

The payment records include masked card numbers, expiry dates, and recurring billing tokens from the Tinkoff payment gateway. Full card numbers aren’t present, but the linkage between a person’s email, their payment history, and a recurring billing token is enough to cause problems.

The admin table exposes five operator accounts, pavel, valerii, maria, andrei, vladislav, with bcrypt password hashes, roles, and a complete admin action log. Account creation dates run from January to June 2026. The database also contains tables pointing to back-office infrastructure for provisioning App Store accounts, which is the plumbing behind distributing a VPN that Russia has been actively removing from app stores.

Mysterium frames the structural lesson clearly: a conventional VPN is a centralized intermediary where the provider, not the user, decides what gets logged. “No-logs” is an unauditable marketing claim backed by nothing the user can verify. When the provider logs anyway, for billing, anti-fraud, capacity planning, or less benign reasons, the user has no way to know until a 17 GB file with their email shows up on a forum. If you used NotVPN or SplitVPN, treat the associated email address and IP as compromised, change passwords everywhere that email was reused, enable two-factor authentication, and factor into your threat model that connection metadata records now exist outside the operator’s control.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, data leak)

  • ✇Firewall Daily – The Cyber Express
  • Tanaka Dominates Data Leak Landscape With 25 Leak Posts Ashish Khaitan
    Ransomware often dominates cybersecurity headlines, but stolen data has become an equally valuable commodity in the cybercrime economy. In the first half of 2026, one threat actor stood out in the data leak ecosystem: Tanaka, a prolific data leak broker responsible for more publicized leak activity than any other actor tracked by Cyble.  Cyble researchers recorded 367 data breach and leak incidents worldwide between January and June 2026. While dozens of actors participated in selling or publ
     

Tanaka Dominates Data Leak Landscape With 25 Leak Posts

Tanaka

Ransomware often dominates cybersecurity headlines, but stolen data has become an equally valuable commodity in the cybercrime economy. In the first half of 2026, one threat actor stood out in the data leak ecosystem: Tanaka, a prolific data leak broker responsible for more publicized leak activity than any other actor tracked by Cyble.  Cyble researchers recorded 367 data breach and leak incidents worldwide between January and June 2026. While dozens of actors participated in selling or publishing stolen information, Tanaka emerged as the most active, accounting for 25 distinct leak posts — more than double the activity of several other major actors. 

A Data Leak Operation Without Industry Boundaries 

Unlike threat actors that specialize in a single vertical, Tanaka followed a broad targeting approach across multiple industries and regions. The actor’s campaigns showed no strict preference for a specific sector, instead focusing on organizations where stolen information could hold financial or strategic value.  The Banking, Financial Services, and Insurance (BFSI) sector remained the most targeted industry globally, accounting for 38 breach incidents during the reporting period. Financial organizations continue to attract attackers due to the value of customer information, account data, and personally identifiable information (PII).  Government and Technology organizations were also frequent targets, reflecting the wider value of sensitive records, intellectual property, and institutional data. 

Regional Presence Across Major Markets 

Tanaka’s activity was visible across multiple regions. In North America, the actor was responsible for seven leak posts, making it the most active data leak actor in the region alongside other prominent sellers.  Europe and the UK also saw significant activity, with Tanaka linked to six leak posts during H1 2026. The region’s BFSI, Telecommunications, and Retail sectors faced heightened exposure due to the amount of valuable customer and financial data they hold.  The actor’s global footprint demonstrates how modern data leak operations can function independently of geography. Instead of focusing on a single country or industry, operators like Tanaka exploit opportunities wherever valuable information becomes available. 

The Rise of the Data Leak Marketplace 

Tanaka’s activity reflects a broader shift in the cybercrime ecosystem. Data leaks are no longer only a byproduct of ransomware attacks; they have become a standalone business model.  Threat actors monetize stolen information through underground marketplaces, using leaked databases for fraud, extortion, intelligence gathering, or resale. This specialization mirrors other parts of the cybercrime economy, where access brokers, ransomware affiliates, and data sellers perform separate roles.  For organizations, this means a breach does not always begin with a ransomware demand. A stolen database appearing in underground channels may indicate an earlier compromise that requires immediate investigation. 

Staying Ahead of Data Exposure Risks 

Security teams must treat underground data exposure monitoring as part of their broader defense strategy. Identifying leaked credentials, compromised databases, or mentions in cybercrime marketplaces can provide early warning before stolen information is weaponized.  To understand the 2026 data breach landscape, including the most active threat actors, targeted industries, and regional trends, access the full Cyble H1 2026 Cyber Threat Landscape Report. 
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 4, July 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 4, July 2026           Source Code Collection of a South Korean Autonomous Robot Manufacturer Shared on a Cybercrime Forum Qilin Ransomware Attack on a Spanish Public Wastewater Management Organization RansomHouse Ransomware Attack on a Japanese Frozen Food and Logistics Company
     

Ransom & Dark Web Issues Week 4, July 2026

Por:ATCP
22 de Julho de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 4, July 2026           Source Code Collection of a South Korean Autonomous Robot Manufacturer Shared on a Cybercrime Forum Qilin Ransomware Attack on a Spanish Public Wastewater Management Organization RansomHouse Ransomware Attack on a Japanese Frozen Food and Logistics Company
  • ✇ASEC BLOG
  • June 2026 Security Issues in Korean & Global Financial Sector ATCP
    Statistics on Malware Distributed to the Financial Sector In the June threat analysis for the financial sector, phishing was the most prevalent attack method in Attack Stage 1, while droppers/downloaders (distribution tools that download additional malware) were the most prevalent in Attack Stage 2. Infostealers were identified in the third attack stage, indicating that multi-stage […]
     

June 2026 Security Issues in Korean & Global Financial Sector

Por:ATCP
15 de Julho de 2026, 12:00
Statistics on Malware Distributed to the Financial Sector In the June threat analysis for the financial sector, phishing was the most prevalent attack method in Attack Stage 1, while droppers/downloaders (distribution tools that download additional malware) were the most prevalent in Attack Stage 2. Infostealers were identified in the third attack stage, indicating that multi-stage […]
❌
❌