Revolut
2026-09-14 · United Kingdom · Finance / Insurance
Limited number of customers, suspected high-net-worth targetingPassports, KYC selfies, IBAN statements, and full transaction history (including Bitcoin) disclosed to an attacker posing as an official agency.
Cause : Government agency impersonation request via email with valid domain authentication credentials.
Read the full analysis →Brevo (Trezor email provider)
2026-09-09 · France · Tech / Software
120 Brevo accounts, 347,000 Trezor emailsFake security alerts sent from the genuine help@trezor.io address after the French Brevo platform was compromised; 2,500 clicks before the domain was cut in 20 minutes.
Cause : Unauthorized access to the sending system, used to dispatch phishing from legitimate senders.
Read the full analysis →Liquid Network (Blockstream)
2026-09-06 · International · Finance / Insurance
~4,000 BTC (~$320M, 95% of reserves)3,400 BTC returned after an on-chain negotiation; about 598 BTC ($47M) remain with the attackers despite the "white hat" label.
Cause : Bug in the Elements software allowing creation of unbacked L-BTC and triggering a peg-out.
Read the full analysis →Florida DMV (DAVID database)
2026-09-04 · United States · Public sector
200,000+ driver records claimed (ShinyHunters)The ShinyHunters gang claims over 200,000 driver records stolen via a compromised institutional account, with proof of the breach.
Cause : Police department user's credentials stored on a personal device (official version); password reset flaw claimed by attackers.
Read the full analysis →DGFiP (impots.gouv.fr)
2026-08-20 · France · Public sector
2+ million people potentially affectedFrance's tax authority confirms illegitimate access to its systems, reviving the debate over public-sector security.
Cause : Impersonated agent credentials and lack of widespread MFA across the tax administration's information system.
Read the full analysis →CEVA Logistics (CMA CGM)
2026-07-29 · France / International · Other
Customers of 8 European warehouses (Valve, Bol.com, ING, Ajax Amsterdam...)The logistics arm of French shipping group CMA CGM had major clients' orders blocked and their data exfiltrated, triggering class-action lawsuits in the US.
Cause : Ransomware attack paralyzing eight European warehouses; the CoinbaseCartel group is named in ongoing legal proceedings.
Read the full analysis →ANTS / France Titres
2026-04-15 · France · Public sector
11.7 million accounts (up to 19 million claimed)The portal handling vehicle registration, driving licences and ID cards exposed millions of French residents' data through an authorization flaw that was trivial to fix.
Cause : Elementary IDOR vulnerability on the portal: changing an identifier in an API request granted access to other users' accounts.
Read the full analysis →Michelin
2026-03-12 · France · Other
300+ GB of internal files (manufacturing, HR, finance)The French tire manufacturer had internal manufacturing, engineering and HR files claimed by Cl0p, part of a MOVEit-style campaign targeting Oracle's ERP suite.
Cause : Pre-authentication zero-day in Oracle E-Business Suite (CVE-2025-61882), exploited by the Cl0p group in an extortion campaign hitting 100+ organizations.
Read the full analysis →