BleepingComputer reports that U.S. blockchain-based fintech firm Figure Technology Solutions was noted by data breach notification service Have I Been Pwned to have had data from 967,200 accounts exfiltrated following a ShinyHunters social engineering attack against an employee that was initially reported by the company to have only affected a "limited number of files."
Data-only extortion surged dramatically in 2025, highlighting a shift in attacker tactics toward theft and coercion rather than encryption, according to new findings from Arctic Wolf, according to IT Brief Australia.
The breach, which occurred when threat actors gained unauthorized access to Eurail's customer database, potentially exposed sensitive information including full names, passport details, ID numbers, bank account IBANs, health information, and contact details.
Security Affairs reports that well known Japanese sex toy manufacturer Tenga has confirmed being impacted by a data breach following the compromise of an employee's email account.
South Korea's Ministry of Justice has announced that U.S. investment firms Foxhaven Asset Management, Abrams Capital, and Durable Capital Partners have joined a lawsuit alleging the South Korean government's lack of impartiality in handling its investigation into the massive data breach at leading South Korean e-commerce firm Coupang, according to TechCrunch.