Another security breach involving US telecom companies has come to light, with a third-party contractor that interfaces between some of the industry's big names reporting discovery of unauthorized access to their systems by nation-state hackers that began in late 2024 and continued through much of 2025.
Snack giant Mondelēz International has suffered a third-party law firm data breach from its legal services provider, Bryan Cave Leighton Paisner LLP, leaking sensitive personal information of over 50,000 current and former employees.
A third-party data breach at the online DIY platform ManoMano has affected nearly 38 million customers after attackers breached its subcontractor’s Zendesk instance.
Spanish multinational fashion retailer MANGO has recently experienced a third-party data breach that exposed customer information from a marketing partner.
A third-party breach on a reputable service provider has leaked OpenSea API keys, exposing NFT holders’ accounts to exploitation by unauthorized external parties.
Harrods has disclosed a third-party data breach after cybercriminals claimed to have stolen over 430,000 customer records. The luxury department learned of the breach after the attackers approached the company and demanded a ransom to avoid leaking the stolen data online.
A data breach on a third-party cloud-based SaaS application has hit luxury fashion retailers Chanel and Pandora, leaking the personal information of customers.
Thomson Reuters database leak exposed 3TB of platform information and customer data after the media company left three databases unsecured and publicly accessible for days.
GitHub users leaked their login cookies by committing cookies.sqlite database to their public projects from their Linux home directory, exposing their accounts to potential compromise.
The problem stems from developers failing to remove the Twitter API keys they use for authentication from the app before they release it to the public. This creates the possibility of account hijacking.










