Topic
Breaches & Data Leaks
Real-world intrusions and data leaks — how they started and the lessons for security teams.
66 articles in this topic
Cushman & Wakefield Vishing Breach: How One Phone Call Exposed 500K Salesforce Records
A single vishing call gave ShinyHunters access to 500,000 Salesforce records at Cushman & Wakefield. Two ransomware groups now claim the data. Here's what went wrong and why Saudi institutions must act now.
Cloud & IdentityFortinet 2026 Threat Report: 389% Ransomware Surge, 1.7B Stolen Credentials, and What It Means for Saudi Finance
Fortinet's FortiGuard Labs confirms 7,831 ransomware victims in 2025 — a 389% spike — fueled by AI-assisted tools and 1.7 billion stolen credentials on the dark web. Saudi financial institutions face unique exposure.
Breaches & Data LeaksShinyHunters Breach Instructure Canvas: 275 Million Records Expose Education Sector's Blind Spot
ShinyHunters breached Instructure's Canvas LMS twice in ten days, stealing 275 million records from 8,800+ institutions. Here's what went wrong and why Saudi organizations must reassess cloud vendor risk under PDPL.
Cloud & IdentityFake OpenAI Model on Hugging Face Steals Credentials: AI Supply Chain Risk for Financial Institutions
A fake OpenAI model on Hugging Face reached 244K downloads before removal, deploying a Rust infostealer that harvested browser credentials and SSH keys. Here's what Saudi financial institutions must do now.
Breaches & Data LeaksTrellix Source Code Breach: Why Your Security Vendor Could Be Your Biggest Risk
Trellix's source code repository was breached by RansomHouse. For SAMA-regulated banks running Trellix products, this supply chain risk event demands immediate third-party incident response.
Breaches & Data LeaksCanvas LMS Mega-Breach: Lessons in Third-Party SaaS Risk for Saudi Institutions
ShinyHunters compromised Instructure's Canvas LMS, exposing data from 8,800+ institutions and 275 million users — the largest educational breach in history. Here's what Saudi organizations must learn about third-party SaaS risk.
Breaches & Data LeaksShinyHunters Vishing-to-Salesforce Attack Chain: What SAMA Banks Must Know
ShinyHunters breached 500K+ Salesforce records via vishing and OAuth hijacking. Saudi financial institutions face the same attack pattern — here's how to defend under SAMA CSCC and NCA ECC.
Breaches & Data LeaksVerizon 2026 DBIR: What Saudi Banks Must Learn from 12,195 Breaches
Verizon's 2026 DBIR reveals third-party breaches doubled to 30%, vulnerability exploitation overtook phishing, and ransomware hit 44% of cases. Here's what SAMA-regulated banks must do now.
RansomwareEverest Ransomware Hits US Banks: Vendor Risk Lessons for SAMA
Everest ransomware claimed breaches at Frost Bank and Citizens Financial Group through a shared third-party vendor, exposing 250K+ customer records. SAMA-regulated banks face the same supply chain exposure — here is what every CISO must do now.
Supply Chain & Third PartyTrellix Source Code Breach: Supply Chain Threat to SAMA Banks
Trellix confirmed unauthorized access to its source code repository in May 2026. For SAMA-regulated banks relying on Trellix XDR and EDR, this incident raises urgent supply chain and third-party risk questions under SAMA CSCC.
Breaches & Data LeaksItron Utility Breach: Critical Infrastructure Lessons for SAMA Banks
Utility tech giant Itron disclosed an intrusion into internal systems. For Saudi banks under SAMA CSCC, this is a sharp reminder: third-party assurance is non-negotiable.
Breaches & Data LeaksShinyHunters' 9M-Record Medtronic Hack: SAMA Bank Lessons
ShinyHunters claimed 9 million records stolen from Medtronic, then quietly delisted the victim. Saudi banks face the same pure-extortion playbook — here is how to prepare.