DevaOnBreaches

1.5K Followers
5K Following
1.7K Posts
Sharing insights on data breach investigations, information security, & password best practices • @XposedOrNot
Websitehttps://XposedOrNot.com
Bloghttps://blog.xposedornot.com/
GitHubhttps://github.com/DevaOnBreaches
Websitehttps://plus.xposedornot.com/

@XposedOrNot += Aura Data Breach

The Aura #databreach occurred in March 2026 when the online safety service disclosed a breach involving data linked to a marketing tool from an acquired company, exposing 922K unique email addresses and associated information.

Exposed data: Email addresses, Names, Phone numbers, Physical addresses, IP addresses

Potential risks: Phishing, Identity theft, Targeted scams, Privacy breaches

Navia Benefit Solutions disclosed a #databreach affecting ~2.7M people: hackers accessed systems (Dec 22, 2025–Jan 15, 2026), exposing personal data like SSNs and emails. No financial/claims data leaked, but phishing risk remains.

https://www.bleepingcomputer.com/news/security/navia-discloses-data-breach-impacting-27-million-people/

Navia discloses data breach impacting 2.7 million people

Navia Benefit Solutions, Inc. (Navia) is informing nearly 2.7 million individuals of a data breach that exposed their sensitive information to attackers.

BleepingComputer

@XposedOrNot += Thermomix owners’ recipe forum Data Breach

The Rezeptwelt #databreach occurred in January 2025 and exposed details of 3.1M registered users of the Thermomix owners’ recipe forum.

Exposed data: Names, Email addresses, Physical addresses, Phone numbers, Dates of birth

@XposedOrNot += Cal AI Data Breach

The Cal AI #databreach occurred in March 2026 and exposed over 3M user records from the AI-powered calorie tracking app, including more than 2.8M unique email addresses and associated profile information.

Exposed data: Email addresses, Names, Dates of birth, Genders, Usernames, Linked social media profiles

Potential risks: Phishing, Identity theft, Targeted scams, Privacy breaches

Telus confirmed a breach at its subsidiary, Telus Digital, after hackers infiltrated internal systems and allegedly stole up to 700TB–1PB of data. #databreach

https://hackread.com/shinyhunters-1-petabyte-data-breach-telus-digital/

ShinyHunters Claims 1 Petabyte Data Breach at Telus Digital

ShinyHunters claims it stole up to 1 petabyte of data from Telus Digital, including support recordings, code, and employee records after a breach.

Hackread - Cybersecurity News, Data Breaches, AI and More
Starbucks disclosed a #databreach after attackers used phishing sites to access 889 employee Partner Central accounts, exposing data like SSNs, DOBs, and bank details.
https://www.bleepingcomputer.com/news/security/starbucks-discloses-data-breach-affecting-hundreds-of-employees/
Starbucks discloses data breach affecting hundreds of employees

Starbucks has disclosed a data breach affecting hundreds of employees after threat actors gained access to their Starbucks Partner Central accounts.

BleepingComputer

Iran-linked hacktivist group Handala claims a massive data-wiping attack on medical tech giant Stryker, alleging 200K+ devices were erased across 79 countries. Offices reportedly disrupted, with staff sent home in Ireland.

https://krebsonsecurity.com/2026/03/iran-backed-hackers-claim-wiper-attack-on-medtech-firm-stryker/

Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker – Krebs on Security

Bell Ambulance in Milwaukee disclosed a #databreach after unauthorized network access dating back to Feb 2025. Personal data of 114K people may be exposed, including SSNs and medical info.

https://hackread.com/bell-ambulance-confirms-data-breach/

Bell Ambulance Confirms Data Breach Affecting 237,830 Individuals

Bell Ambulance disclosed a data breach impacting 237,830 individuals after unauthorized access to its network exposed personal and medical data.

Hackread - Cybersecurity News, Data Breaches, AI and More
Loblaw, Canada’s largest food & pharmacy retailer (2,500 stores), disclosed a #databreach where hackers accessed basic customer info (names, emails, phone numbers).
https://www.bleepingcomputer.com/news/security/canadian-retail-giant-loblaw-notifies-customers-of-data-breach/
Canadian retail giant Loblaw notifies customers of data breach

Still, out of an abundance of caution, Loblaw says it has automatically logged out all customers from their accounts. Account holders who need to access the company's digital services will have to log in again.

BleepingComputer

@XposedOrNot += APOIA.se Data Breach

The APOIA.se #databreach occurred in December 2025 when the platform’s database was posted to an online forum, later confirmed in January 2026, exposing 451K unique email addresses and associated user information.

Exposed data: Email addresses, Names, Physical addresses

Potential risks: Phishing, Identity theft, Targeted scams, Privacy breaches