Topic
Breaches & Data Leaks
Real-world intrusions and data leaks — how they started and the lessons for security teams.
66 articles in this topic
Marquis Breach Expands to 80 Banks: SonicWall Lessons for SAMA Third-Party Risk
The Marquis ransomware breach has expanded to 80 banks and 824,000 customers — exploited through a SonicWall firewall flaw. Here's what SAMA-regulated banks must do now to harden third-party and perimeter controls.
Cloud & IdentityVercel-Context AI OAuth Breach: Shadow AI Risk Lessons for SAMA Banks
A single Shadow AI tool installed by one Vercel employee triggered an OAuth supply-chain breach exposing API keys, source code, and customer credentials — a textbook warning for SAMA-regulated banks tightening third-party governance under CSCC and ECC.
Breaches & Data LeaksMarquis Breach Hits 80 Banks: SAMA Vendor Risk Lessons for Saudi CISOs
The Marquis Software ransomware breach exposed 824,000 customers across 80 US banks via a single SonicWall CVE. Here is the SAMA CSCC 3.4 vendor-risk playbook every Saudi CISO must apply now.
Breaches & Data LeaksVercel-Context AI OAuth Breach: SaaS Supply Chain Lessons for SAMA Banks
A single employee-installed AI plugin gave attackers OAuth access to Vercel's corporate Google environment. The blast radius reached hundreds of downstream organizations — and exposes a control gap that SAMA-regulated banks routinely overlook.
RansomwareDragonForce Hits Conrad Capital: 74GB Breach Lessons for SAMA Banks
DragonForce ransomware breached US investment advisor Conrad Capital, exfiltrating 74.23GB and demanding negotiations within five days. We unpack the attack and what SAMA-regulated Saudi institutions must harden in CSCC controls today.
Breaches & Data LeaksShinyHunters Hits Ameriprise: 200GB SaaS Breach Lessons for SAMA Banks
ShinyHunters claimed 200GB of Ameriprise data, hitting nearly 48,000 customers via Salesforce and SharePoint. What SAMA-regulated Saudi banks must learn about SaaS supply chain risk and detection gaps.
Compliance & RegulationTrellix Source Code Breach: SAMA CSCC TPRM Lessons for Saudi Banks
Trellix, a major endpoint security vendor used across Saudi banking, disclosed unauthorized access to a portion of its source code repository. Here is what SAMA-regulated institutions must do now under CSCC TPRM controls.
RansomwareDragonForce Hits Conrad Capital: SAMA TPRM Lessons for Saudi Banks
DragonForce ransomware claims 74.23 GB of stolen data from US investment firm Conrad Capital Management. The breach delivers an urgent SAMA CSCC and TPRM wake-up call for Saudi financial institutions.
Breaches & Data LeaksMarquis Software Breach: 80 Banks Hit — A SAMA TPRM Reckoning
When one fintech vendor breach cascades into 80 US banks, regulators take notice. The Marquis ransomware incident shows why SAMA-regulated CISOs must overhaul their third-party risk programs in 2026.
Breaches & Data LeaksShinyHunters Salesforce Heist Threatens Saudi Bank SaaS Security
The ShinyHunters extortion group has exfiltrated 1.5 billion records from 760 Salesforce tenants through OAuth abuse and vishing—exposing critical TPRM gaps for Saudi SAMA-regulated financial institutions.
Breaches & Data LeaksPyTorch Lightning PyPI Hack: Shai-Hulud Worm Hits Saudi Bank AI
On April 30, 2026, PyTorch Lightning 2.6.2 and 2.6.3 were compromised by a Mini Shai-Hulud worm stealing credentials and poisoning GitHub. Saudi banks running AI/ML workloads face an urgent SAMA CSCC TPRM event.
Breaches & Data Leaks824,000 Customers Exposed: Marquis-SonicWall Lessons for Saudi Banks
An unpatched SonicWall firewall at a trusted banking vendor cascaded into an Akira ransomware breach affecting 80 banks and 824,000 customers. Saudi financial institutions face the same third-party exposure under SAMA CSCC.