RE: https://infosec.exchange/@douglevin/116771934591550552

I am waiting for a response to a public records request I filed with PA over safe2say PA. They'll likely exempt everything, but we'll see. I will be reporting on some of the sensitive tips involving children.

And yes, there are tips in the dataset involving Canada although I haven't attempted to dive into those. I think it's shameful that entities still haven't been given details on what data of theirs was involved.

#Navigate360 #Crimestoppers #databreach

๐’๐ข๐ง๐œ๐ž ๐–๐ก๐ž๐ง ๐ƒ๐ข๐ ๐€๐ฌ๐ค๐ข๐ง๐  ๐Ÿ๐จ๐ซ ๐„๐ฏ๐ข๐๐ž๐ง๐œ๐ž ๐๐ž๐œ๐จ๐ฆ๐ž โ€œ๐ƒ๐ž๐Ÿ๐ž๐ง๐๐ข๐ง๐  ๐‚๐ซ๐ข๐ฆ๐ข๐ง๐š๐ฅ๐ฌโ€?

Dissent responded harshly to these accusations, firmly rejecting any insinuation of collusion with criminal groups. The journalist pointed out that every time she asks for evidence to support certain claims, she is labeled โ€œcriminal-friendlyโ€ or accused of being a mouthpiece for cybercriminals, simply for refusing to uncritically accept statements lacking public verification.

https://www.suspectfile.com/since-when-did-asking-for-evidence-become-defending-criminals/

#Canvas #Data_Breach #Instructure #Navigate360 #Ransom #ShinyHunters

๐‘๐š๐ง๐ฌ๐จ๐ฆ๐ฐ๐š๐ซ๐ž, ๐“๐ซ๐š๐ง๐ฌ๐ฉ๐š๐ซ๐ž๐ง๐œ๐ฒ, ๐š๐ง๐ ๐ˆ๐ง๐ฏ๐ข๐ฌ๐ข๐›๐ฅ๐ž ๐•๐ข๐œ๐ญ๐ข๐ฆ๐ฌ: ๐ƒ๐ข๐ฌ๐ฌ๐ž๐ง๐ญ ๐‘๐ž๐ฌ๐ฉ๐จ๐ง๐๐ฌ ๐ญ๐จ ๐ญ๐ก๐ž ๐ˆ๐ง๐ฌ๐ญ๐ซ๐ฎ๐œ๐ญ๐ฎ๐ซ๐ž ๐‚๐š๐ฌ๐ž

A recent article published by DataBreaches.net by journalist Dissent addresses one of the most controversial issues in modern cybersecurity: the payment of ransoms following a cyberattack and the consequences such decisions can have not only on the companies involved, but also on the individuals whose data has been compromised.

https://www.suspectfile.com/ransomware-transparency-and-invisible-victims-dissent-responds-to-the-instructure-case/

#Canvas #Data_Breach #Instructure #Navigate360 #Ransom #Ransomware #ShinyHunters

Senators Probe Navigate360 Over Hacked Student Data

Senators Maggie Hassan and Jim Banks are demanding answers from Navigate360 after a cyberattack compromised its anonymous tip line, putting the sensitive data of students, staff, and schools at risk. The breach allegedly exposed 93 gigabytes of data, sparking concerns over the safety and security of those who rely on the company'sโ€ฆ

https://osintsights.com/senators-probe-navigate360-over-hacked-student-data?utm_source=mastodon&utm_medium=social

#StudentDataBreach #Navigate360 #P3GlobalIntel #EmergingThreats #EducationSector

Senators Probe Navigate360 Over Hacked Student Data

Senators investigate Navigate360 data breach, demand answers on hacked student data, learn more about the cyberattack and its impact now.

OSINTSights

NEW by me:

BlueLeaks 2.0: 7,300+ Schools, Referral Systems Reported, and a Breach Navigate360 Still Hasnโ€™t Publicly Confirmed

P3's parent firm responded to me, but only to say they are quite concerned about my reporting data on their breach. They are concerned that partial or incomplete data without context, etc., might upset folks downstream. That would be the same folks they haven't addressed at all, I guess.

My post, with newly reported data (thanks to the incredibly patient and diligent @JayeLTee's help) and my response to #Navigate360:

https://databreaches.net/2026/04/22/blueleaks-2-0-7300-schools-referral-systems-reported-and-a-breach-navigate360-still-hasnt-publicly-confirmed/

Previous coverage by me about this breach that has compromised what were supposed to be anonymous and SECURE tips from and about students:

https://databreaches.net/2026/04/16/p3-advertised-20-years-and-0-security-breaches-you-can-guess-what-happened-next/

#databreach #transparency #incidentresponse #infosec #cybersecurity #P3Tips

@zackwhittaker @jgreig @dangoodin @mkeierleber @ddosecrets

BlueLeaks 2.0: 7,300+ Schools, Referral Systems Reported, and a Breach Navigate360 Still Hasnโ€™t Publicly Confirmed - DataBreaches.Net

Overview and Background This is the first of what will likely be several updates to this site's exclusive reporting on the "BlueLeaks 2.0" incident that exposed

DataBreaches.Net

NEW: My post on the student/k-12 tips exposed in "BlueLeaks 2.0" is now up.

P3 Campus and its partner programs like Safe2Say Something PA, Safe2Tell, and Sandy Hook Promise were supposed to provide secure and anonymous ability to report tips.

Promises of security and anonymity do not appear to have been kept. A hacker claims it was easy to gain access and repeatedly access the database to acquire more than 8 million tips.

There is not much anonymous about what I reviewed in the dataset.

Many of the school-related tips I reviewed reported concerns over named students with suicidal ideation or cutting, students being bullied or bullying others, and drugs (mostly vaping) in school. Some students reported cybercriminal activity.

Navigate360, the parent company of P3, still hasn't publicly acknowledged that it was breached and that sensitive information was involved. Their lack of transparency was noted by @douglevin

The dataset has not been leaked publicly, but the "Internet Yiff Machine" who provided it to #ddosecrets and https://infosec.exchange/@mikaelthalen@mastodon.social -- and then to me -- has listed it for sale.

My focus in this post was on the student/school -related tips, but the 93.51 GB dataset has millions of tips that include adult issues and crimes, including drugs, homicide, assaults, etc. I provide one or two examples from the non-student tips to illustrate how sensitive the tips are in this dataset.

This may be the worst breach I've ever seen involving sensitive student information, and I've seen many student-related data breaches over the past two decades.

Read: "P3 Advertised 20+ Years and 0 Security Breaches. You Can Guess What Happened Next.'" at https://databreaches.net/2026/04/16/p3-advertised-20-years-and-0-security-breaches-you-can-guess-what-happened-next/

#BlueLeaks2 #DDoSecrets #databreach #P3Campus #P3Tips #Navigate360 #CrimeStoppers #Safety #Safe2tell #InternetYiffMachine

@zackwhittaker @campuscodi @jgreig @euroinfosec @funnymonkey @mkeierleber @JayeLTee

Infosec Exchange