<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:content="http://purl.org/rss/1.0/modules/content/"
    xmlns:atom="http://www.w3.org/2005/Atom"
    xmlns:media="http://search.yahoo.com/mrss/">
    <channel><title>Consumer Insights</title><description>News, views and insights from the Bitdefender experts</description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/</link><image><url>https://download.bitdefender.com/resources/images/favicon/favicon-32x32.png</url><title>Consumer Insights</title><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/</link></image><generator>Bitdefender Blog</generator><lastBuildDate>Sun, 14 Jun 2026 06:10:48 GMT</lastBuildDate><atom:link href="https://www.bitdefender.com/nuxt/api/en-us/rss/hotforsecurity/data-breach/" rel="self" type="application/rss+xml"/><ttl>1800</ttl><item><title>Carnival breach exposes data of nearly 6 million people</title><description><![CDATA[Nearly 6 million Carnival customers may face phishing and identity theft risks after attackers stole personal data through a socially engineered employee account.


Carnival confirms stolen customer data

Carnival Corporation has started notifying 5,995,277 people after a cybersecurity incident exposed personal information tied to the cruise operator and its brands. The company says it detected the activity on April 14 after attackers used social engineering to compromise an employee account and]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/carnival-breach-6-million</link><guid isPermaLink="false">6a198bae8beeea9658026014</guid><category><![CDATA[Industry News]]></category><category><![CDATA[Data Breach]]></category><dc:creator>Vlad CONSTANTINESCU</dc:creator><pubDate>Fri, 29 May 2026 12:51:48 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/05/alonso-reyes-LWFdBz4d6nE-unsplash.jpg" medium="image"/><content:encoded><![CDATA[Nearly 6 million Carnival customers may face phishing and identity theft risks after attackers stole personal data through a socially engineered employee account.


Carnival confirms stolen customer data

Carnival Corporation has started notifying 5,995,277 people after a cybersecurity incident exposed personal information tied to the cruise operator and its brands. The company says it detected the activity on April 14 after attackers used social engineering to compromise an employee account and]]></content:encoded></item><item><title>7-Eleven data breach exposes data of 185,000 people</title><description><![CDATA[ShinyHunters claims it stole 7-Eleven records later found to contain names, contact details and dates of birth.]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/7-eleven-data-breach</link><guid isPermaLink="false">6a1578038beeea9658025e34</guid><category><![CDATA[Industry News]]></category><category><![CDATA[Data Breach]]></category><dc:creator>Vlad CONSTANTINESCU</dc:creator><pubDate>Tue, 26 May 2026 10:39:51 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/05/josh-chiodo-F0hD5KVznLQ-unsplash.jpg" medium="image"/><content:encoded><![CDATA[ShinyHunters claims it stole 7-Eleven records later found to contain names, contact details and dates of birth.]]></content:encoded></item><item><title>UK Water Supplier Fined Nearly £1 Million After Hackers Roamed Networks for Almost 2 Years</title><description><![CDATA[A UK water supplier has been fined £945,000 after regulators found cybercriminals had access to its systems, exposing sensitive customer data, for nearly two years before they were discovered.

The UK Information Commissioner’s Office (ICO) announced this week that it had levied the penalty against South Staffordshire Plc and South Staffordshire Water Plc following a 2022 ransomware attack that compromised the personal data of hundreds of thousands of customers.


Key takeaways


 * UK regulator]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/uk-water-1-million-hackers-ransomware</link><guid isPermaLink="false">6a03358f2fa53a9f2eef72c8</guid><category><![CDATA[Industry News]]></category><category><![CDATA[Data Breach]]></category><dc:creator>Filip TRUȚĂ</dc:creator><pubDate>Tue, 12 May 2026 14:22:34 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/05/tap-water.png" medium="image"/><content:encoded><![CDATA[A UK water supplier has been fined £945,000 after regulators found cybercriminals had access to its systems, exposing sensitive customer data, for nearly two years before they were discovered.

The UK Information Commissioner’s Office (ICO) announced this week that it had levied the penalty against South Staffordshire Plc and South Staffordshire Water Plc following a 2022 ransomware attack that compromised the personal data of hundreds of thousands of customers.


Key takeaways


 * UK regulator]]></content:encoded></item><item><title>DAEMON Tools Lite breach prompts urgent update after malware-laced installer</title><description><![CDATA[DAEMON Tools Lite malware breach: Disc Soft releases clean 12.6 build after trojanized installers exposed users to backdoor risk.]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/daemon-tools-breach-malware</link><guid isPermaLink="false">69fc6c632fa53a9f2eef6ed1</guid><category><![CDATA[Industry News]]></category><category><![CDATA[Data Breach]]></category><dc:creator>Vlad CONSTANTINESCU</dc:creator><pubDate>Thu, 07 May 2026 10:50:56 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/05/DAEMON-Tools-Lite-installer-compromised-in-supply-chain-attack.jpg" medium="image"/><content:encoded><![CDATA[DAEMON Tools Lite malware breach: Disc Soft releases clean 12.6 build after trojanized installers exposed users to backdoor risk.]]></content:encoded></item><item><title>Instructure confirms breach; millions of Canvas users potentially impacted</title><description><![CDATA[Instructure, the company behind the Canvas learning management system, has confirmed a data breach after a well-known cybercrime group claimed responsibility for stealing data linked to hundreds of millions of users.


Key takeaways

 * Canvas owner Instructure confirmed a security incident after the ShinyHunters group claimed responsibility
 * Up to 275 million users may be affected, with exposed data including names, emails, IDs, and messages
 * Users should watch for scams and suspicious mess]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/canvas-data-breach-2026</link><guid isPermaLink="false">69fa10e92fa53a9f2eef6d23</guid><category><![CDATA[Data Breach]]></category><category><![CDATA[Digital Privacy]]></category><dc:creator>Alina BÎZGĂ</dc:creator><pubDate>Tue, 05 May 2026 15:56:05 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/05/Instructure-confirms-breach--millions-of-Canvas-users-potentially-impacted.png" medium="image"/><content:encoded><![CDATA[Instructure, the company behind the Canvas learning management system, has confirmed a data breach after a well-known cybercrime group claimed responsibility for stealing data linked to hundreds of millions of users.


Key takeaways

 * Canvas owner Instructure confirmed a security incident after the ShinyHunters group claimed responsibility
 * Up to 275 million users may be affected, with exposed data including names, emails, IDs, and messages
 * Users should watch for scams and suspicious mess]]></content:encoded></item><item><title>Stalkerware data leak exposes private screenshots linked to celebrities and influencers</title><description><![CDATA[A recent discovery by cybersecurity researcher Jeremiah Fowler shows how quickly a single compromised device can fuel a much larger exposure.

An unsecured database containing tens of thousands of screenshots, reportedly collected through stalkerware, was found openly accessible online. While the data traces back to a single infected device, the screenshots reveal interactions with celebrities, influencers, and media figures, highlighting how a breach can ripple outward.


Key takeaways

 * An e]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/stalkerware-data-leak-screenshots-celebrities-exposed</link><guid isPermaLink="false">69f870982fa53a9f2eef6b84</guid><category><![CDATA[Data Breach]]></category><category><![CDATA[Digital Privacy]]></category><dc:creator>Alina BÎZGĂ</dc:creator><pubDate>Mon, 04 May 2026 10:28:18 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/05/Stalkerware-data-leak-exposes-private-screenshots-linked-to-celebrities-and-influencers.png" medium="image"/><content:encoded><![CDATA[A recent discovery by cybersecurity researcher Jeremiah Fowler shows how quickly a single compromised device can fuel a much larger exposure.

An unsecured database containing tens of thousands of screenshots, reportedly collected through stalkerware, was found openly accessible online. While the data traces back to a single infected device, the screenshots reveal interactions with celebrities, influencers, and media figures, highlighting how a breach can ripple outward.


Key takeaways

 * An e]]></content:encoded></item><item><title>Hackers claim to have breached Udemy, stealing 1.4 million user records</title><description><![CDATA[Notorious hacking group ShinyHunters recently announced they had breached Udemy’s systems and exfiltrated a large dataset of user information.


Key takeaways:

 * Hackers claim to have stolen 1.4 million Udemy user records
 * The company has not confirmed the breach
 * Stolen information may include personal and internal data
 * Attackers are using a “pay or leak” extortion tactic
 * Users should update passwords, enable 2FA, and watch out for scams


What happened?

On April 24, 2026, the cybe]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/hackers-claim-to-have-breached-udemy</link><guid isPermaLink="false">69ef689f2fa53a9f2eef67e1</guid><category><![CDATA[Data Breach]]></category><category><![CDATA[Digital Privacy]]></category><dc:creator>Alina BÎZGĂ</dc:creator><pubDate>Mon, 27 Apr 2026 13:52:11 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/04/Hackers-claim-to-have-breached-Udemy--stealing-1.4-million-user-records--2-.jpg" medium="image"/><content:encoded><![CDATA[Notorious hacking group ShinyHunters recently announced they had breached Udemy’s systems and exfiltrated a large dataset of user information.


Key takeaways:

 * Hackers claim to have stolen 1.4 million Udemy user records
 * The company has not confirmed the breach
 * Stolen information may include personal and internal data
 * Attackers are using a “pay or leak” extortion tactic
 * Users should update passwords, enable 2FA, and watch out for scams


What happened?

On April 24, 2026, the cybe]]></content:encoded></item><item><title>Rituals data breach exposes customer details</title><description><![CDATA[Dutch cosmetics brand Rituals has confirmed customer membership records were affected in a data breach. While no passwords or payment details were exposed, the type of data involved raises a different kind of risk that many users underestimate.


Key takeaways

 * Dutch cosmetics giant Rituals suffered a data breach in April 2026 affecting customer membership records
 * Exposed data may include names, emails, phone numbers, birth dates, and home addresses
 * No passwords or payment details were ]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/rituals-cosmetics-data-breach-2026</link><guid isPermaLink="false">69ea01cf2fa53a9f2eef6651</guid><category><![CDATA[Data Breach]]></category><category><![CDATA[Digital Privacy]]></category><dc:creator>Alina BÎZGĂ</dc:creator><pubDate>Thu, 23 Apr 2026 11:36:22 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/04/Rituals-data-breach-exposes-customer-details.jpg" medium="image"/><content:encoded><![CDATA[Dutch cosmetics brand Rituals has confirmed customer membership records were affected in a data breach. While no passwords or payment details were exposed, the type of data involved raises a different kind of risk that many users underestimate.


Key takeaways

 * Dutch cosmetics giant Rituals suffered a data breach in April 2026 affecting customer membership records
 * Exposed data may include names, emails, phone numbers, birth dates, and home addresses
 * No passwords or payment details were ]]></content:encoded></item><item><title>Booking.com says breach exposed travelers’ data</title><description><![CDATA[Planning a trip soon? You may want to take a closer look at any messages related to your reservation.

Booking.com has confirmed a security incident involving unauthorized access to customer data.


Key takeaways

 * Booking.com confirmed a data breach: Unauthorized parties accessed customer booking information
 * Sensitive travel data may be exposed: Names, contact details, and reservation info could be affected
 * Users have been notified: Customers received alerts and reservation PINs were re]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/booking-com-breach-april-2026</link><guid isPermaLink="false">69e0e15d2fa53a9f2eef6067</guid><category><![CDATA[Data Breach]]></category><dc:creator>Alina BÎZGĂ</dc:creator><pubDate>Thu, 16 Apr 2026 13:25:14 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/04/booking.png" medium="image"/><content:encoded><![CDATA[Planning a trip soon? You may want to take a closer look at any messages related to your reservation.

Booking.com has confirmed a security incident involving unauthorized access to customer data.


Key takeaways

 * Booking.com confirmed a data breach: Unauthorized parties accessed customer booking information
 * Sensitive travel data may be exposed: Names, contact details, and reservation info could be affected
 * Users have been notified: Customers received alerts and reservation PINs were re]]></content:encoded></item><item><title>Basic-Fit data breach exposes member information across Europe</title><description><![CDATA[Basic-Fit, one of Europe’s largest fitness chains, has confirmed a cyber incident involving unauthorized access to a system containing member data.


Key takeaways

 * Basic-Fit detected and stopped the breach quickly, but some data was downloaded
 * Around 200,000 members in the Netherlands alone are affected, with impact in multiple countries
 * Exposed data includes personal and financial details
 * No passwords or ID documents were compromised, according to the company


What happened in the]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/basic-fit-data-breach</link><guid isPermaLink="false">69df636b2fa53a9f2eef600e</guid><category><![CDATA[Data Breach]]></category><category><![CDATA[Digital Privacy]]></category><dc:creator>Alina BÎZGĂ</dc:creator><pubDate>Wed, 15 Apr 2026 10:12:55 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/04/Basic-Fit-data-breach-exposes-member-information-across-Europe.jpg" medium="image"/><content:encoded><![CDATA[Basic-Fit, one of Europe’s largest fitness chains, has confirmed a cyber incident involving unauthorized access to a system containing member data.


Key takeaways

 * Basic-Fit detected and stopped the breach quickly, but some data was downloaded
 * Around 200,000 members in the Netherlands alone are affected, with impact in multiple countries
 * Exposed data includes personal and financial details
 * No passwords or ID documents were compromised, according to the company


What happened in the]]></content:encoded></item><item><title>Rockstar Games confirms breach after ShinyHunters leaks stolen analytics data</title><description><![CDATA[Rockstar Games says a third-party breach exposed internal analytics data after ShinyHunters linked the incident to Anodot and Snowflake.]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/rockstar-games-data-breach</link><guid isPermaLink="false">69de05b62fa53a9f2eef5f71</guid><category><![CDATA[Industry News]]></category><category><![CDATA[Data Breach]]></category><dc:creator>Vlad CONSTANTINESCU</dc:creator><pubDate>Tue, 14 Apr 2026 09:23:44 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/04/Rockstar-Games-confirms-data-breach.jpg" medium="image"/><content:encoded><![CDATA[Rockstar Games says a third-party breach exposed internal analytics data after ShinyHunters linked the incident to Anodot and Snowflake.]]></content:encoded></item><item><title>Lapsus$ claims AstraZeneca breach exposes code and credentials</title><description><![CDATA[Alleged AstraZenea data leak raises concerns over internal access, source code exposure and follow-on cyber risks.


Dark web post sparks breach concerns

The cybercrime group LAPSUS$ claims it hacked AstraZeneca and stole roughly 3 GB of internal data, according to recent cybersecurity reporting. The alleged archive includes credentials, tokens, employee information and source code tied to internal development environments.

The claim surfaced on dark web channels and a leak site linked to the ]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/lapsus-astrazeneca-breach</link><guid isPermaLink="false">69c6389d2fa53a9f2eef5638</guid><category><![CDATA[Industry News]]></category><category><![CDATA[Data Breach]]></category><dc:creator>Vlad CONSTANTINESCU</dc:creator><pubDate>Thu, 26 Mar 2026 08:00:00 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/03/AstraZeneca-data-breach.jpg" medium="image"/><content:encoded><![CDATA[Alleged AstraZenea data leak raises concerns over internal access, source code exposure and follow-on cyber risks.


Dark web post sparks breach concerns

The cybercrime group LAPSUS$ claims it hacked AstraZeneca and stole roughly 3 GB of internal data, according to recent cybersecurity reporting. The alleged archive includes credentials, tokens, employee information and source code tied to internal development environments.

The claim surfaced on dark web channels and a leak site linked to the ]]></content:encoded></item><item><title>Aura data breach exposes 900,000 records after phishing attack</title><description><![CDATA[Aura says a phishing attack led to a data breach affecting nearly 900,000 records, including names, emails, addresses and phone numbers.]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/aura-data-breach</link><guid isPermaLink="false">69bbda722fa53a9f2eef51ab</guid><category><![CDATA[Industry News]]></category><category><![CDATA[Data Breach]]></category><dc:creator>Vlad CONSTANTINESCU</dc:creator><pubDate>Thu, 19 Mar 2026 11:17:55 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/03/Aura-data-breach.jpg" medium="image"/><content:encoded><![CDATA[Aura says a phishing attack led to a data breach affecting nearly 900,000 records, including names, emails, addresses and phone numbers.]]></content:encoded></item><item><title>Telus Digital data breach confirmed after ShinyHunters claims 1PB theft</title><description><![CDATA[Telus Digital is probing a confirmed breach as ShinyHunters  claims petabyte-scale data theft tied to compromised cloud credentials.


Telus Digital confirms breach and launches investigation

Telus Digital says it is investigating a cybercrime involving unauthorized access to a limited number of systems after a threat actor claimed it stole nearly 1 petabyte of data.

The company said operations remain fully functional and it has brought in external forensics support and police, adding it will ]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/telus-digital-data-breach</link><guid isPermaLink="false">69b40b602fa53a9f2eef4d60</guid><category><![CDATA[Industry News]]></category><category><![CDATA[Data Breach]]></category><dc:creator>Vlad CONSTANTINESCU</dc:creator><pubDate>Fri, 13 Mar 2026 13:06:06 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/03/towfiqu-barbhuiya-em5w9_xj3uU-unsplash.jpg" medium="image"/><content:encoded><![CDATA[Telus Digital is probing a confirmed breach as ShinyHunters  claims petabyte-scale data theft tied to compromised cloud credentials.


Telus Digital confirms breach and launches investigation

Telus Digital says it is investigating a cybercrime involving unauthorized access to a limited number of systems after a threat actor claimed it stole nearly 1 petabyte of data.

The company said operations remain fully functional and it has brought in external forensics support and police, adding it will ]]></content:encoded></item><item><title>Was Your Data Exposed in the Latest Under Armour Breach? Here’s What You Should Do</title><description><![CDATA[The latest Under Armour breach is a reminder that exposed personal data can still create serious risk even when passwords and payment details are not confirmed as part of the leak. Names, email addresses, birth dates, location data, and purchase-related information may be enough for scammers to launch convincing phishing attacks, account lures, and identity-focused fraud.


Key Takeaways

 * A dataset allegedly linked to Under Armour was posted online after the Everest ransomware group claimed i]]></description><link>https://www.bitdefender.com/en-us/blog/hotforsecurity/was-your-data-exposed-in-the-latest-under-armour-breach-heres-what-you-should-do</link><guid isPermaLink="false">698089112fa53a9f2eef30e3</guid><category><![CDATA[Data Breach]]></category><category><![CDATA[Digital Privacy]]></category><dc:creator>Alina BÎZGĂ</dc:creator><pubDate>Mon, 02 Feb 2026 11:27:25 GMT</pubDate><media:content url="https://blogapp.bitdefender.com/hotforsecurity/content/images/2026/02/Was-Your-Data-Exposed-in-the-Latest-Under-Armour-Breach-Here-s-What-You-Should-Do.png" medium="image"/><content:encoded><![CDATA[The latest Under Armour breach is a reminder that exposed personal data can still create serious risk even when passwords and payment details are not confirmed as part of the leak. Names, email addresses, birth dates, location data, and purchase-related information may be enough for scammers to launch convincing phishing attacks, account lures, and identity-focused fraud.


Key Takeaways

 * A dataset allegedly linked to Under Armour was posted online after the Everest ransomware group claimed i]]></content:encoded></item></channel>
        </rss>