Date
|
Org / Sector
|
Incident / Impact
|
URL
|
| 01/11/2025 |
OnSolve (Emergency alert software vendor, US) |
Software / Public-Safety |
Ransom-gang claims breach: from Nov 1 hacked, encrypted Nov 10; data (including emails & clear-text passwords) allegedly stolen and offered for sale. BleepingComputer |
| 03/11/2025 |
University of Pennsylvania |
Data breach; FBI contacted; 1.2M alumni/donor records impacted. |
https://www.reuters.com/world/us/university-pennsylvania-says-it-has-called-fbi-over-data-breach-2025-11-03/ |
| 06/11/2025 |
Nikkei (Media, JP) |
Stolen credentials from infostealer used to access internal Slack; 17k+ staff/partner records exposed. |
https://www.theregister.com/2025/11/06/nikkeis_private_chats_go_public/ |
| 06/11/2025 |
US Congressional Budget Office |
Suspected foreign actor breach; congressional communications may be accessed. |
https://www.reuters.com/world/us/us-congressional-budget-office-hacked-by-suspected-foreign-actor-washington-post-2025-11-06/ |
| 06/11/2025 |
The Washington Post |
Oracle EBS zero‚Äëday breach; staff/contractor data exposed. |
https://www.computing.co.uk/news/2025/security/washington-post-confirms-data-breach |
| 09/11/2025 |
Mixpanel / OpenAI (Analytics / AI) |
Analytics / SaaS |
Hackers breached Mixpanel via smishing; some analytics-user data exposed (names, emails, coarse location, browser/OS metadata). OpenAI says ChatGPT users unaffected. BleepingComputer+1 |
| 11/11/2025 |
GlobalLogic |
Oracle EBS breach; 10k+ employees’ HR/personal data stolen. |
https://www.bleepingcomputer.com/news/security/globallogic-warns-10-000-employees-of-data-theft-after-oracle-breach/ |
| 11/11/2025 |
Synnovis (NHS) |
Follow‚Äëup: patient & organisational data confirmed exfiltrated. |
https://www.bleepingcomputer.com/news/security/synnovis-notifies-of-data-breach-after-2024-ransomware-attack/ |
| 14/11/2025 |
Logitech |
Oracle EBS exploited; internal data exfiltrated. |
https://www.bleepingcomputer.com/news/security/logitech-confirms-data-breach-after-clop-extortion-attack/ |
| 14/11/2025 |
Anthropic (AI) / Multiple targets |
AI / Financial / Govt |
Anthropic detected a state-sponsored “AI-orchestrated” cyber-espionage campaign using its tool; attackers reportedly infiltrated ~30 targets (global financial firms, gov agencies) with at least a few successful intrusions. The Guardian |
| 19/11/2025 |
Gainsight / Salesforce ecosystem |
200+ Salesforce customers impacted by third‚Äëparty vendor breach. |
https://www.bleepingcomputer.com/news/security/salesforce-investigates-customer-data-theft-via-gainsight-breach/ |
| 20/11/2025 |
FS Italiane / Almaviva |
Hacker claims 2.3TB of rail-related data stolen. |
https://www.bleepingcomputer.com/news/security/hacker-claims-to-steal-23tb-data-from-italian-rail-group-almaviva/ |
| 22/11/2025 |
Cox Enterprises |
Oracle EBS exploit led to theft of financial + SSN data. |
https://www.bleepingcomputer.com/news/security/cox-enterprises-discloses-oracle-e-business-suite-data-breach/ |
| 23/11/2025 |
SitusAMC + Major Banks |
Vendor breach exposed mortgage/legal data for JPMorgan, Citi, MS. |
https://www.bleepingcomputer.com/news/security/real-estate-finance-services-giant-situsamc-breach-exposes-client-data/ |
| 23/11/2025 |
Iberia (Airline, Spain / Global) |
Transport / Retail-Travel |
Vendor-supplier breach triggered customer data leak: airline began notifying customers of exposure after supplier hack (claims ~77 GB stolen). BleepingComputer |
| 24/11/2025 |
Dartmouth College |
Clop publishes stolen data; institution confirms breach. |
https://www.bleepingcomputer.com/news/security/dartmouth-college-confirms-data-breach-after-clop-extortion-attack/ |
| 24/11/2025 |
Harvard University – Alumni Affairs |
Vishing compromise exposed alumni/donor information. |
https://www.bleepingcomputer.com/news/security/harvard-university-discloses-data-breach-affecting-alumni-donors/ |
| 24/11/2025 |
Comcast (via FBCS vendor) |
FCC fines $1.5m; vendor breach exposed 237k customer records. |
https://www.bleepingcomputer.com/news/security/comcast-to-pay-15-million-fine-after-a-vendor-data-breach-affecting-270-000-customers/ |