Topic

Breaches & Data Leaks

Real-world intrusions and data leaks — how they started and the lessons for security teams.

66 articles in this topic

Breaches & Data Leaks

REF6598 & PHANTOMPULSE: How Hackers Are Weaponizing Obsidian's Plugin Ecosystem to Breach Financial Sector Employees

A sophisticated threat actor is abusing the Obsidian note-taking app's community plugin ecosystem to silently install a new RAT on financial employees' machines — no CVE, no exploit, just trusted software turned weapon.

19 Apr 2026 6 min
Cloud & Identity

McGraw-Hill's 13.5M-Record Salesforce Breach: Why Cloud Misconfiguration Is the Silent SAMA CSCC Compliance Failure

A Salesforce misconfiguration exposed 13.5 million records at McGraw-Hill. With 31% of cloud breaches sharing this same root cause, Saudi financial institutions must audit their SaaS posture before their next SAMA review.

19 Apr 2026 6 min
Breaches & Data Leaks

ShinyHunters Breach Anodot to Compromise Dozens of Snowflake Accounts: A Supply Chain Wake-Up Call for Saudi Financial Institutions

On April 7, 2026, the ShinyHunters gang breached AI analytics firm Anodot and weaponized stolen Snowflake authentication tokens against dozens of companies. Saudi financial institutions using cloud data platforms face direct SAMA CSCC third-party risk exposure — here's what you must do now.

19 Apr 2026 5 min
Supply Chain & Third Party

Booking.com's ClickFix Supply Chain Breach: The Third-Party Vendor Risk Every Saudi Financial CISO Must Address Now

Booking.com confirmed a breach exposing millions of customers' reservation data — attackers never touched Booking.com directly. They compromised hotel partners using ClickFix malware. Saudi financial institutions face identical third-party exposure under SAMA CSCC.

18 Apr 2026 6 min
Breaches & Data Leaks

ShinyHunters Hits McGraw-Hill via Salesforce Misconfiguration: 13.5M Records and a Warning Saudi Financial CISOs Must Heed

No malware, no CVE, no phishing — just a Salesforce misconfiguration. ShinyHunters walked out with 13.5 million McGraw-Hill records. Saudi banks running Salesforce or Dynamics 365 hold far more sensitive data and face identical exposure under PDPL and SAMA CSCC.

18 Apr 2026 7 min
Compliance & Regulation

Booking.com Breach Forces Global PIN Resets — Third-Party Platform Risk Is Now a SAMA Compliance Issue for Saudi Financial Institutions

Booking.com confirmed hackers accessed customer reservation data on April 13, 2026. Saudi financial CISOs must review third-party risk registers, PDPL obligations, and phishing defences immediately.

16 Apr 2026 5 min
Vulnerabilities

EngageLab SDK Intent Redirection Flaw Exposed 50 Million Android Users — A Third-Party SDK Risk Alarm for Saudi Financial Mobile Apps

Microsoft uncovered an intent redirection vulnerability in EngageLab SDK that silently put 50 million Android users — including 30 million cryptocurrency wallet installs — at risk of private key theft. Saudi financial institutions relying on third-party mobile SDKs need to act now.

16 Apr 2026 6 min
Breaches & Data Leaks

North Korean Hackers Drain $285M from Drift Protocol in 12 Minutes: What Saudi Financial Institutions Must Know

North Korean hackers drained $285M from Drift Protocol in just 12 minutes on April 1, 2026 using fake CVT tokens as collateral. Saudi CISOs must understand what this means for digital asset risk under SAMA's evolving framework.

16 Apr 2026 5 min
Breaches & Data Leaks

ShinyHunters Breach Rockstar via Anodot: Saudi CISO Third-Party Alert

ShinyHunters extracted 78M records from Rockstar via Anodot, a third-party analytics vendor. SAMA CSCC mandates strict third-party risk controls — is your institution compliant?

16 Apr 2026 4 min
Supply Chain & Third Party

Fake Ledger Live on Apple's App Store Stole $9.5M in 7 Days — App Supply Chain Risk Is Now a Board-Level Issue for Saudi Financial Institutions

A fraudulent Ledger Live app slipped through Apple's review process and stole $9.5 million from 50+ victims in a single week. Here's what this means for your institution's third-party and app supply chain risk posture.

15 Apr 2026 5 min
Malware & Threat Actors

Adobe's BPO Backdoor: How 'Mr. Raccoon' Stole 13M Support Tickets — and What Saudi Financial Institutions Must Learn About Vendor Risk

A threat actor called "Mr. Raccoon" compromised an Indian BPO contractor via RAT malware, exfiltrating 13M Adobe support tickets, 15K employee records, and unpublished HackerOne vulnerability reports — a masterclass in third-party risk gone wrong.

15 Apr 2026 5 min
Breaches & Data Leaks

Booking.com Breach Fuels Spear-Phishing Against Saudi Bank Employees

Booking.com confirmed hackers accessed customer reservation data. Saudi bank employees are now prime spear-phishing targets — here's your SAMA CSCC-aligned response.

14 Apr 2026 5 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality