PayPal's loan application system was compromised between July and December 2025 due to a coding error that compromised sensitive information such as names, contact information, social security numbers, and dates of birth for a small number of users.PayPal subsequently remedied the vulnerability, enhanced security, refunded unauthorized transactions, and provided two years of free credit monitoring and identity restoration services to affected users....
The French national bank account database, FICOBA, was breached at the end of January 2026, resulting in unauthorized access to approximately 1.2 million bank accounts due to the misuse of civil servants' login credentials, which revealed account information, identities, addresses, and tax ID numbers. The intrusion was stopped immediately, the affected individuals were notified, and the data protection authority was notified to alert the public against identity theft and financial fraud....
Jaguar Land Rover (JLR) was hacked in early September this year, halting production for more than a month. The UK's Cyber Monitoring Center estimated the loss to be as high as £1.9 billion, making it the most serious information security incident in UK history and affecting more than 5,000 organizations. The hackers used phishing and leaked credentials to break into the system, and related organizations even claimed to have initiated the attack. The incident is a Level 3 systemic incident, which has severely impacted the production and supply chain....
In July 2025, Qantas Airways was hit by a massive cyber-attack, which resulted in the leakage of 5.7 million customers' names, emails, addresses, and other personal information, making it one of the most serious cyber-security incidents in Australia in recent years. The incident is suspected to be related to the social engineering and voice phishing tactics of the Scattered Spider organization, exposing the vulnerabilities of large-scale corporate security and bringing important warnings to enterprises to strengthen their cybersecurity....
In August 2024, the state government of Nevada was hit by a ransomware attack triggered by malicious advertisements that disrupted services in more than 60 government departments. IT staff clicked on the malicious advertisements to download a tool that contained a backdoor, and the password vault was breached. The authorities refused to pay the ransom, and in-house staff worked overtime for 28 days to repair 90% of the critical systems, at a much lower cost than outsourcing, which has brought important information security revelations to both public and private organizations....
Conduent, a business services provider, has suffered a massive data breach affecting 25 million people and nearly 17,000 employees in North America. Hackers breached the system between October 2024 and January 2025, stealing personal, medical, and social security information, and the incident was caused by...

