pwndr.
pwndrpwndr.
NewsSign in
See Demo

Cybersecurity news

Cyberattacks, mass data leaks and law enforcement takedowns. We summarise what matters and always link back to the outlet that published it.

Latest story: 2 August 2026

Cyberattack

25M

Salesforce records

2 August 2026·DeXpose

ShinyHunters claims 25 million Alcon Salesforce records

The extortion group listed Swiss pharmaceutical company Alcon on its leak portal on 2 August, claiming more than 25 million Salesforce records containing personal data. It gave the company until 4 August to respond before publishing. Same playbook as the CRM-targeting campaign that has hit dozens of major brands this year.

Read at the source
Report

392

attacks in a year

28 July 2026·Que.es

Ransomware doubles in Spain: from 176 to 392 attacks in a year

Recorded cases went from 176 to 392 in twelve months, according to INCIBE, CCN-CERT and ESET data. Inditex and Endesa are among the 2026 victims, both breached through an external technology supplier. The most common way in hasn't changed: stolen credentials and VPNs without two-factor authentication.

Read at the source
Law enforcement

£29M

in losses for Transport for London

16 July 2026·The Hacker News

Five and a half years in prison for two Scattered Spider members

Owen Flowers (18) and Thalha Jubair (20) were sentenced on 16 July at Woolwich Crown Court over the 2024 Transport for London attack, which knocked out 148 systems and forced 27,000 staff to reset passwords in person. The incident cost £29 million in losses and recovery. They are the first people convicted under Section 3ZA of the Computer Misuse Act.

Read at the source
Law enforcement

$300M

in ransoms attributed to 'Stern'

14 July 2026·Chainalysis

EU, US and UK sanction 'Stern', the Trickbot administrator

Vitaly Nikolayevich Kovalev, alias 'Stern', ran Trickbot with CEO-like authority: wallets tied to him received more than $300 million in ransom payments. The coordinated 14 July action also hit the developers of the LummaC2 infostealer, bulletproof host Media Land and a VPN used by ransomware operators.

Read at the source
Law enforcement

27M

stolen credentials recovered

19 June 2026·Paubox

Operation Endgame: 326 servers seized, 27 million credentials recovered

Between 15 and 19 June, Europol and police forces from seven countries dismantled the infrastructure behind Amadey, StealC and SocGholish: 326 servers seized, 142 domains taken down and $46 million in cryptocurrency frozen. The operation recovered 27 million stolen credentials and cleaned up nearly 15,000 infected websites.

Read at the source
Data leak

8.3 TB

of credentials left in the open

17 June 2026·Malwarebytes

24 billion stolen records left exposed on a passwordless server

Cybernews researchers found 8.3 TB of data on an Elasticsearch cluster open to the internet, pulled together from 36 different sources. Inside were infostealer logs with usernames, emails and plaintext passwords, plus session cookies, tokens and browser autofill data. The server was taken offline shortly after the discovery.

Read at the source
Law enforcement

€336m

laundered since 2022

10 June 2026·Infosecurity Magazine

AudiA6 taken down: the service that laundered €336m for ransomware gangs

On 10 June the FBI, Europol and the US Secret Service dismantled AudiA6, a platform charging commissions of up to 10% and tied to laundering for at least 15 ransomware operations between 2022 and 2025. Two administrators, Ukrainian and Russian nationals, were arrested in Georgia; more than 30 servers and 25 domains were seized.

Read at the source
Data leak

5,995,277

people affected

31 May 2026·Malwarebytes

Carnival confirms a breach affecting nearly 6 million travellers

It started with social engineering against a single employee account; the security team flagged the activity on 14 April. Exposed data includes names, addresses, phone numbers, dates of birth and government ID numbers such as passports and driving licences. ShinyHunters claimed the attack and said it held 8.7 million records.

Read at the source
Law enforcement

16

years old, the suspect

27 May 2026·Euronews

Minor arrested in Motril for leaking data on police, prosecutors and INCIBE

On 27 May Spain's National Police arrested a 16-year-old identified as the author of a doxing campaign against members of sensitive state institutions: INCIBE, the Attorney General's Office, the National Security Council, the Guardia Civil and the Tax Agency. He faces a charge of revealing secrets, and officers seized all of his computer equipment for analysis.

Read at the source
Cyberattack

290

stores in the chain

5 May 2026·Bit Life Media

Qilin hits Spanish grocer Ahorramás and publishes accounts and ID numbers

On 5 May the Qilin group announced an attack on the supermarket chain, which runs more than 290 stores across Madrid, Castilla-La Mancha and Castilla y León. It used double extortion and posted proof of the theft on the dark web: accounting documents, store floor plans and personal data. Ahorramás notified INCIBE and the Spanish data protection agency and kept its stores running.

Read at the source

Almost all of them start the same way: a stolen credential

A VPN without two-factor, an employee whose password leaked, a compromised supplier. Scan your domain and see how many of yours are already circulating.

Scan my domain
pwndr.

Real-time leaked credential detection for organizations that can't afford to be compromised.

Solutions

  • Enterprise
  • SMBs
  • Governments

Legal

  • Legal notice
  • Privacy
  • Cookie policy
  • Terms of use

Company

  • Pricing
  • Contact
  • Sign in

© 2026 pwndr · All rights reserved.