PrivacySignal
Breach

No Need to Hack When It’s Leaking: Click to Pray edition

DataBreaches.net · · International · Data Breaches

Click to Pray, a papal-endorsed prayer app with hundreds of thousands of users globally, exposed users' names and email addresses for an extended period — potentially months or longer. An ethical hacker discovered and reported the leak.

Why this matters: People downloading a faith app are not thinking about their data footprint. They are trying to pray. That trust makes the exposure worse. Names and emails tied to a religious app can reveal something personal — belief, practice, community — that users never meant to share with anyone. No sophisticated attack was needed here. The data was just sitting out. That is not bad luck. That is a failure to do the basics, and the people who got hurt had no way to know it was happening.

Who should care: Cybersecurity · Privacy officers · Administrators

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Related stories

Breach
DataBreaches.net · · International

AU: Sydney nurse accused of downloading patients’ data in alleged ‘breach of trust’

A registered nurse in northern Sydney has been charged after allegedly accessing and downloading patient records from NSW Health without authorisation. Police formed a dedicated strike force and conducted a home search following a report made in late July.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

#breach#enforcement#healthcare Read original →
Breach
BleepingComputer · · International

ShinyHunters data leaks fuel $2,000 sextortion email scam

Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
WIRED — AI · · International

The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days

OpenAI models used in an attack on Hugging Face, a major AI model-sharing platform, were reportedly active on the internet for several days before the intrusion was detected or stopped. The incident adds to growing scrutiny of how AI systems can be weaponized against the infrastructure that supports AI development itself.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
F Fox Business · · International

AI innovation is outpacing governance, leaving companies exposed, EqualAI warns

EqualAI, an AI governance nonprofit, has warned that the rapid pace of AI development is moving faster than the policies and oversight structures companies have in place to manage it, leaving organizations legally and reputationally vulnerable.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
Breach
CyberScoop · · US Federal

Despite multiple takedowns, botnets continue to grow

New research from Lumen's Black Lotus Labs shows that botnets are recovering quickly from law enforcement takedowns and in some cases growing larger than before disruption. About one in four of the compromised IP addresses involved are located in the United States.

Who should care: Cybersecurity · Privacy officers · Administrators