<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:content="http://purl.org/rss/1.0/modules/content/"
    xmlns:atom="http://www.w3.org/2005/Atom"
    xmlns:media="http://search.yahoo.com/mrss/">
    <channel><title>Consumer Insights</title><description>News, views and insights from the Bitdefender experts</description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/</link><image><url>https://download.bitdefender.com/resources/images/favicon/favicon-32x32.png</url><title>Consumer Insights</title><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/</link></image><generator>Bitdefender Blog</generator><lastBuildDate>Sat, 12 Sep 2026 15:35:42 GMT</lastBuildDate><atom:link href="https://www.bitdefender.com/nuxt/api/en-us/rss/hotforsecurity/data-breach/" rel="self" type="application/rss+xml"/><ttl>1800</ttl><item><title>Weverse data breach affects 422,584 user accounts</title><description><![CDATA[Weverse, the global fan platform used by millions of K-pop fans, has disclosed a data breach affecting 422,584 user accounts.

The exposed information includes internal account identifiers and details about purchases, payments and refunds. Affected users should be wary of messages that might be using the breach as a pretext to steal passwords, payment information or money.


Key takeaways

 * The breach affected 422,584 Weverse accounts
 * Exposed data included internal user identifiers and tran]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/weverse-data-breach-422584-users</link><guid isPermaLink="false">6a9ec33e8beeea9658029906</guid><category><![CDATA[Digital Privacy]]></category><category><![CDATA[Data Breach]]></category><dc:creator>Alina BÎZGĂ</dc:creator><pubDate>Mon, 07 Sep 2026 14:15:15 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/09/Weverse-data-breach-affects-422-584-user-accounts.png" medium="image"/><content:encoded><![CDATA[Weverse, the global fan platform used by millions of K-pop fans, has disclosed a data breach affecting 422,584 user accounts.

The exposed information includes internal account identifiers and details about purchases, payments and refunds. Affected users should be wary of messages that might be using the breach as a pretext to steal passwords, payment information or money.


Key takeaways

 * The breach affected 422,584 Weverse accounts
 * Exposed data included internal user identifiers and tran]]></content:encoded></item><item><title>Manchester Airports Group cyberattack exposes data of 8.7 million customers</title><description><![CDATA[Hackers obtained customer contact and booking-related data from Manchester, Stansted and East Midlands airports, creating new phishing risks for travelers.]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/manchester-airports-group-data-breach-8-7-million</link><guid isPermaLink="false">6a9146648beeea965802959b</guid><category><![CDATA[Industry News]]></category><category><![CDATA[Digital Privacy]]></category><category><![CDATA[Data Breach]]></category><dc:creator>Vlad CONSTANTINESCU</dc:creator><pubDate>Fri, 28 Aug 2026 08:28:40 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/08/joel-barwick-7qz6rINHYBw-unsplash.jpg" medium="image"/><content:encoded><![CDATA[Hackers obtained customer contact and booking-related data from Manchester, Stansted and East Midlands airports, creating new phishing risks for travelers.]]></content:encoded></item><item><title>Sakura Internet hack may affect 1.36 million accounts</title><description><![CDATA[Japanese cloud and data center provider Sakura Internet is investigating unauthorized access to a sales management system that may have exposed personal and contract information linked to as many as 1.36 million customer accounts. The company says the final impact is under investigation and large-scale data exfiltration hasn’t been confirmed.


Key takeaways

 * Up to 1,360,563 Sakura Internet accounts potentially fall within the scope of the incident
 * Exposed information may include contact, ]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/sakura-internet-breach-1-36-million-accounts</link><guid isPermaLink="false">6a86ed2b8beeea96580291ab</guid><category><![CDATA[Industry News]]></category><category><![CDATA[Data Breach]]></category><dc:creator>Vlad CONSTANTINESCU</dc:creator><pubDate>Thu, 20 Aug 2026 12:05:06 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/08/david-brooke-martin-lFTtQqVfx6g-unsplash.jpg" medium="image"/><content:encoded><![CDATA[Japanese cloud and data center provider Sakura Internet is investigating unauthorized access to a sales management system that may have exposed personal and contract information linked to as many as 1.36 million customer accounts. The company says the final impact is under investigation and large-scale data exfiltration hasn’t been confirmed.


Key takeaways

 * Up to 1,360,563 Sakura Internet accounts potentially fall within the scope of the incident
 * Exposed information may include contact, ]]></content:encoded></item><item><title>French tax authority breach exposes data of 678,000 people and businesses</title><description><![CDATA[France's tax authority has confirmed a major data breach affecting 678,000 individuals and professionals after cybercriminals gained access to systems of the Direction générale des Finances publiques (DGFiP).

The disclosure came after a threat actor publicly claimed responsibility for the attack and advertised allegedly stolen DGFiP information on a cybercrime forum.


Key takeaways

 * 678,000 individuals and professionals are confirmed to have been affected
 * Attackers accessed tax and prope]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/france-dgfip-data-breach-678000-affected</link><guid isPermaLink="false">6a84658d8beeea9658028f40</guid><category><![CDATA[Data Breach]]></category><category><![CDATA[Digital Privacy]]></category><dc:creator>Alina BÎZGĂ</dc:creator><pubDate>Tue, 18 Aug 2026 14:55:10 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/08/French-tax-authority-breach-exposes-data-of-678-000-people-and-businesses.png" medium="image"/><content:encoded><![CDATA[France's tax authority has confirmed a major data breach affecting 678,000 individuals and professionals after cybercriminals gained access to systems of the Direction générale des Finances publiques (DGFiP).

The disclosure came after a threat actor publicly claimed responsibility for the attack and advertised allegedly stolen DGFiP information on a cybercrime forum.


Key takeaways

 * 678,000 individuals and professionals are confirmed to have been affected
 * Attackers accessed tax and prope]]></content:encoded></item><item><title>Phone number leaked in the Bloctel breach? Here’s what to do.</title><description><![CDATA[If you’re a French citizen who registered your phone number with Bloctel to avoid unwanted marketing calls, you may want to be extra careful about unexpected calls and messages.

France's Directorate General for Competition Policy, Consumer Affairs and Fraud Control (DGCCRF) has warned that a cybercriminal obtained files containing 3 million phone numbers, including 600,000 registered with Bloctel.


Key takeaways

 * 3 million phone numbers were exposed, including around 600,000 registered with]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/bloctel-data-breach-phone-numbers-leaked</link><guid isPermaLink="false">6a8462c18beeea9658028f25</guid><category><![CDATA[Data Breach]]></category><category><![CDATA[Digital Privacy]]></category><dc:creator>Alina BÎZGĂ</dc:creator><pubDate>Tue, 18 Aug 2026 13:56:31 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/08/Phone-number-leaked-in-the-Bloctel-breach-Here-s-what-to-do..png" medium="image"/><content:encoded><![CDATA[If you’re a French citizen who registered your phone number with Bloctel to avoid unwanted marketing calls, you may want to be extra careful about unexpected calls and messages.

France's Directorate General for Competition Policy, Consumer Affairs and Fraud Control (DGCCRF) has warned that a cybercriminal obtained files containing 3 million phone numbers, including 600,000 registered with Bloctel.


Key takeaways

 * 3 million phone numbers were exposed, including around 600,000 registered with]]></content:encoded></item><item><title>SplitVPN breach reveals 58 million hidden connection logs</title><description><![CDATA[A leaked database attributed to SplitVPN, formerly NotVPN, allegedly exposed user, device, payment and VPN connection metadata despite the service’s no-logs promise.


Key takeaways

 * Researchers analyzed a 17 GB SQL database allegedly stolen from SplitVPN.
 * The dump reportedly contains 23.4 million user records, 13.6 million device records and 2.6 million payment records.
 * Nearly 58 million entries record when specific devices connected to VPN servers, but not the websites users visited.
]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/splitvpn-breach-58-million-connection-logs</link><guid isPermaLink="false">6a6b35c38beeea96580283f7</guid><category><![CDATA[Industry News]]></category><category><![CDATA[Data Breach]]></category><dc:creator>Vlad CONSTANTINESCU</dc:creator><pubDate>Thu, 30 Jul 2026 11:33:47 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/07/matthew-henry-fPxOowbR6ls-unsplash.jpg" medium="image"/><content:encoded><![CDATA[A leaked database attributed to SplitVPN, formerly NotVPN, allegedly exposed user, device, payment and VPN connection metadata despite the service’s no-logs promise.


Key takeaways

 * Researchers analyzed a 17 GB SQL database allegedly stolen from SplitVPN.
 * The dump reportedly contains 23.4 million user records, 13.6 million device records and 2.6 million payment records.
 * Nearly 58 million entries record when specific devices connected to VPN servers, but not the websites users visited.
]]></content:encoded></item><item><title>South Korea diplomatic academy hack exposes diplomat data</title><description><![CDATA[An intrusion lasting nearly 10 months exposed names, emails and encrypted passwords associated with thousands of South Korean officials.


Key takeaways

 * Hackers maintained access to the Korea National Diplomatic Academy’s online education system between April 2025 and February 2026.
 * The breach exposed names, user IDs, email addresses and encrypted passwords of current and former Foreign Ministry personnel.
 * Reports estimate that roughly 6,000 people were affected, while the compromised ]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/south-korea-diplomatic-academy-breach</link><guid isPermaLink="false">6a61e5258beeea965802809c</guid><category><![CDATA[Industry News]]></category><category><![CDATA[Data Breach]]></category><dc:creator>Vlad CONSTANTINESCU</dc:creator><pubDate>Thu, 23 Jul 2026 09:57:28 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/07/daniel-bernard-qjsmpf0aO48-unsplash.jpg" medium="image"/><content:encoded><![CDATA[An intrusion lasting nearly 10 months exposed names, emails and encrypted passwords associated with thousands of South Korean officials.


Key takeaways

 * Hackers maintained access to the Korea National Diplomatic Academy’s online education system between April 2025 and February 2026.
 * The breach exposed names, user IDs, email addresses and encrypted passwords of current and former Foreign Ministry personnel.
 * Reports estimate that roughly 6,000 people were affected, while the compromised ]]></content:encoded></item><item><title>Credential stuffing attack at Chick-fil-A comes with data breach notice for customers</title><description><![CDATA[Chick-fil-A is notifying customers after cybercriminals gained access to some Chick-fil-A One loyalty accounts in a credential stuffing attack last month.


Key takeaways

 * Chick-fil-A is notifying customers after attackers accessed some Chick-fil-A One accounts in a credential stuffing attack.
 * Criminals used usernames and passwords stolen from previous breaches rather than hack Chick-fil-A directly.
 * Exposed information may include names, email addresses, membership details, rewards bala]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/chick-fil-a-credential-stuffing-data-breach-account-takeover</link><guid isPermaLink="false">6a60cff28beeea9658028079</guid><category><![CDATA[Data Breach]]></category><category><![CDATA[Digital Privacy]]></category><dc:creator>Alina BÎZGĂ</dc:creator><pubDate>Wed, 22 Jul 2026 14:24:09 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/07/_Credential-stuffing-attack-at-Chick-fil-A-comes-with-data-breach-notice-for-customers.png" medium="image"/><content:encoded><![CDATA[Chick-fil-A is notifying customers after cybercriminals gained access to some Chick-fil-A One loyalty accounts in a credential stuffing attack last month.


Key takeaways

 * Chick-fil-A is notifying customers after attackers accessed some Chick-fil-A One accounts in a credential stuffing attack.
 * Criminals used usernames and passwords stolen from previous breaches rather than hack Chick-fil-A directly.
 * Exposed information may include names, email addresses, membership details, rewards bala]]></content:encoded></item><item><title>Coca-Cola halts Fairlife production across US after ransomware attack</title><description><![CDATA[Coca-Cola has paused production of Fairlife dairy products in the US after ransomware disrupted systems supporting manufacturing operations.]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/coca-cola-fairlife-ransomware-attack</link><guid isPermaLink="false">6a5a109e8beeea9658027dca</guid><category><![CDATA[Industry News]]></category><category><![CDATA[Data Breach]]></category><dc:creator>Vlad CONSTANTINESCU</dc:creator><pubDate>Fri, 17 Jul 2026 11:24:41 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/07/anita-jankovic-c7PT4PZMcNA-unsplash.jpg" medium="image"/><content:encoded><![CDATA[Coca-Cola has paused production of Fairlife dairy products in the US after ransomware disrupted systems supporting manufacturing operations.]]></content:encoded></item><item><title>Qantas data breach started with a fake IT support call</title><description><![CDATA[A vishing attack on an overseas contact center exposed 5.67 million Qantas customer records in 2025, Australia’s privacy regulator says.]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/qantas-data-breach-vishing-scam</link><guid isPermaLink="false">6a58ad7f8beeea9658027d47</guid><category><![CDATA[Industry News]]></category><category><![CDATA[Data Breach]]></category><category><![CDATA[Scam]]></category><dc:creator>Vlad CONSTANTINESCU</dc:creator><pubDate>Thu, 16 Jul 2026 10:10:28 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/07/towfiqu-barbhuiya-FnA5pAzqhMM-unsplash.jpg" medium="image"/><content:encoded><![CDATA[A vishing attack on an overseas contact center exposed 5.67 million Qantas customer records in 2025, Australia’s privacy regulator says.]]></content:encoded></item><item><title>Lidl warns customers after data breach</title><description><![CDATA[German retailer Lidl is notifying customers of a data breach after cybercriminals gained unauthorized access to customer information via one of its third-party service providers.


Key takeaways

 * Lidl has disclosed a data breach affecting customers of its online shop in Germany, Belgium, and the Netherlands after one of its IT service providers was compromised.
 * Stolen data includes customer identifiers and other account details. The retailer says customer accounts and its online shop syste]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/lidl-data-breach-2026</link><guid isPermaLink="false">6a579cf68beeea9658027cd3</guid><category><![CDATA[Data Breach]]></category><category><![CDATA[Industry News]]></category><category><![CDATA[Digital Privacy]]></category><dc:creator>Alina BÎZGĂ</dc:creator><pubDate>Wed, 15 Jul 2026 14:55:55 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/07/Lidl-warns-customers-after-data-breach.png" medium="image"/><content:encoded><![CDATA[German retailer Lidl is notifying customers of a data breach after cybercriminals gained unauthorized access to customer information via one of its third-party service providers.


Key takeaways

 * Lidl has disclosed a data breach affecting customers of its online shop in Germany, Belgium, and the Netherlands after one of its IT service providers was compromised.
 * Stolen data includes customer identifiers and other account details. The retailer says customer accounts and its online shop syste]]></content:encoded></item><item><title>How to find out if your identity has been exposed by infostealers</title><description><![CDATA[You don't have to fall for a phishing email or have one of your favorite websites suffer a data breach to become an identity theft victim. Sometimes, it just takes a piece of malware known as an infostealer to quietly steal your data in the background.


Key takeaways

 * Infostealers silently collect passwords, browser cookies, session tokens, and other sensitive information from infected devices.
 * Cybercriminals increasingly target session tokens because they can provide access to accounts w]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/how-to-check-if-an-infostealer-stole-your-data</link><guid isPermaLink="false">6a4d4c968beeea96580276fb</guid><category><![CDATA[Digital Privacy]]></category><category><![CDATA[Data Breach]]></category><dc:creator>Alina BÎZGĂ</dc:creator><pubDate>Wed, 08 Jul 2026 08:21:56 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/07/How-to-find-out-if-your-identity-has-been-exposed-by-infostealers.png" medium="image"/><content:encoded><![CDATA[You don't have to fall for a phishing email or have one of your favorite websites suffer a data breach to become an identity theft victim. Sometimes, it just takes a piece of malware known as an infostealer to quietly steal your data in the background.


Key takeaways

 * Infostealers silently collect passwords, browser cookies, session tokens, and other sensitive information from infected devices.
 * Cybercriminals increasingly target session tokens because they can provide access to accounts w]]></content:encoded></item><item><title>Texas breach exposes PII of 3 million hunting and fishing license customers</title><description><![CDATA[More than 3.1 million people may have had sensitive personal information exposed following a data security incident involving a third-party vendor used by the Texas Parks and Wildlife Department (TPWD).


Key takeaways

 * The Texas Parks and Wildlife Department (TPWD) disclosed a data security incident affecting some 3.1 million customers.
 * The breach occurred through a third-party vendor that manages the agency's licensing system.
 * Exposed data may include driver's license numbers, passpor]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/texas-data-breach-exposes-3-1-million-license-records</link><guid isPermaLink="false">6a3a26e98beeea9658026c82</guid><category><![CDATA[Data Breach]]></category><category><![CDATA[Digital Privacy]]></category><dc:creator>Alina BÎZGĂ</dc:creator><pubDate>Tue, 23 Jun 2026 06:34:48 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/06/texas-data-breach.jpg" medium="image"/><content:encoded><![CDATA[More than 3.1 million people may have had sensitive personal information exposed following a data security incident involving a third-party vendor used by the Texas Parks and Wildlife Department (TPWD).


Key takeaways

 * The Texas Parks and Wildlife Department (TPWD) disclosed a data security incident affecting some 3.1 million customers.
 * The breach occurred through a third-party vendor that manages the agency's licensing system.
 * Exposed data may include driver's license numbers, passpor]]></content:encoded></item><item><title>Maine forced to take down data breach portal after fake notices filed with authorities</title><description><![CDATA[The US state of Maine has taken its public data breach notification portal offline after someone submitted fraudulent breach disclosures impersonating two well-known technology companies.

As Bleeping Computer reported last week, fraudulent data breach disclosures were submitted to Maine's official breach portal and publicly posted before their legitimacy could be verified, prompting the named companies to deny the claims.

The first fake notification targeted the popular messaging platform Disc]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/maine-take-down-data-breach-portal</link><guid isPermaLink="false">6a2ff8958beeea9658026872</guid><category><![CDATA[Industry News]]></category><category><![CDATA[Data Breach]]></category><dc:creator>Graham CLULEY</dc:creator><pubDate>Mon, 15 Jun 2026 13:06:15 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/06/fake-data-breach-notice.jpeg" medium="image"/><content:encoded><![CDATA[The US state of Maine has taken its public data breach notification portal offline after someone submitted fraudulent breach disclosures impersonating two well-known technology companies.

As Bleeping Computer reported last week, fraudulent data breach disclosures were submitted to Maine's official breach portal and publicly posted before their legitimacy could be verified, prompting the named companies to deny the claims.

The first fake notification targeted the popular messaging platform Disc]]></content:encoded></item><item><title>Carnival breach exposes data of nearly 6 million people</title><description><![CDATA[Nearly 6 million Carnival customers may face phishing and identity theft risks after attackers stole personal data through a socially engineered employee account.


Carnival confirms stolen customer data

Carnival Corporation has started notifying 5,995,277 people after a cybersecurity incident exposed personal information tied to the cruise operator and its brands. The company says it detected the activity on April 14 after attackers used social engineering to compromise an employee account and]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/carnival-breach-6-million</link><guid isPermaLink="false">6a198bae8beeea9658026014</guid><category><![CDATA[Industry News]]></category><category><![CDATA[Data Breach]]></category><dc:creator>Vlad CONSTANTINESCU</dc:creator><pubDate>Fri, 29 May 2026 12:51:48 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/05/alonso-reyes-LWFdBz4d6nE-unsplash.jpg" medium="image"/><content:encoded><![CDATA[Nearly 6 million Carnival customers may face phishing and identity theft risks after attackers stole personal data through a socially engineered employee account.


Carnival confirms stolen customer data

Carnival Corporation has started notifying 5,995,277 people after a cybersecurity incident exposed personal information tied to the cruise operator and its brands. The company says it detected the activity on April 14 after attackers used social engineering to compromise an employee account and]]></content:encoded></item></channel>
        </rss>