Close Menu
TechBrunchTechBrunch
  • Home
  • AI
  • Apps
  • Crypto
  • Security
  • Startups
  • TechCrunch
  • Venture

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Crafton raises stakes in India with new $670 million funding

December 19, 2025

Hacking, theft and destruction: 2025's worst data breaches

December 19, 2025

UK NHS technology provider confirms data breach

December 18, 2025
Facebook X (Twitter) Instagram
TechBrunchTechBrunch
  • Home
  • AI

    OpenAI seeks to extend human lifespans with the help of longevity startups

    January 17, 2025

    Farewell to the $200 million woolly mammoth and TikTok

    January 17, 2025

    Nord Security founder launches Nexos.ai to help enterprises move AI projects from pilot to production

    January 17, 2025

    Data proves it remains difficult for startups to raise capital, even though VCs invested $75 billion in the fourth quarter

    January 16, 2025

    Apple suspends AI notification summaries for news after generating false alerts

    January 16, 2025
  • Apps

    Google brings Pixel 6 and new devices to Material3 Expressive, along with other features, to the Pixel 6 and new devices

    September 3, 2025

    Google's NoteBookLM now allows you to customize the tone of your AI podcasts

    September 3, 2025

    Roblox expands the use of age estimation techniques and introduces standardized assessments

    September 3, 2025

    Instagram finally launches the iPad app

    September 3, 2025

    Complete the 2025 Confusion Builder Stage Agenda with the Maximum Scaling Voice

    September 3, 2025
  • Crypto

    Coinbase resumes user onboarding in India, plans to introduce fiat currency next year

    December 7, 2025

    New report examines how David Sachs benefits from Trump administration role

    November 30, 2025

    Why Benchmark made a rare crypto bet on trading app Fomo with $17 million Series A

    November 6, 2025

    Coinbase CEO Brian Armstrong trolls prediction markets

    November 1, 2025

    Solana co-founder Anatoly Yakovenko is a big fan of agent coding

    October 29, 2025
  • Security

    Hacking, theft and destruction: 2025's worst data breaches

    December 19, 2025

    UK NHS technology provider confirms data breach

    December 18, 2025

    Cisco announces Chinese hackers are exploiting customers with new zero-day attack

    December 17, 2025

    Hacking group says it's blackmailing Pornhub after stealing users' viewing data

    December 16, 2025

    Google and Apple release emergency security updates after zero-day attack

    December 12, 2025
  • Startups

    7 days left: Founders and VCs save over $300 on all stage passes

    March 24, 2025

    AI chip startup Furiosaai reportedly rejecting $800 million acquisition offer from Meta

    March 24, 2025

    20 Hottest Open Source Startups of 2024

    March 22, 2025

    Andrill may build a weapons factory in the UK

    March 21, 2025

    Startup Weekly: Wiz bets paid off at M&A Rich Week

    March 21, 2025
  • TechCrunch

    OpenSea takes a long-term view with a focus on UX despite NFT sales remaining low

    February 8, 2024

    AI will save software companies' growth dreams

    February 8, 2024

    B2B and B2C are not about who buys, but how you sell

    February 5, 2024

    It's time for venture capital to break away from fast fashion

    February 3, 2024

    a16z's Chris Dixon believes it's time to focus on blockchain use cases rather than speculation

    February 2, 2024
  • Venture

    Crafton raises stakes in India with new $670 million funding

    December 19, 2025

    Why this year's best tech talks took place over cocktails at StrictlyVC

    December 18, 2025

    Private VC and beloved investor Neil Murray raises third Nordic-focused fund

    December 16, 2025

    Lightspeed raises record $9 billion in new capital

    December 15, 2025

    A comprehensive list of 2025 tech layoffs

    December 13, 2025
TechBrunchTechBrunch

Hacking, theft and destruction: 2025's worst data breaches

TechBrunchBy TechBrunchDecember 19, 20255 Mins Read
Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
Share
Facebook Twitter LinkedIn Pinterest Telegram Email


Every year, TechCrunch looks back at the cybersecurity horror shows of the past 12 months, from the biggest data breaches to hacks that left weeks of chaos, to see what we can learn. This year's data breaches were unlike anything we've seen before.

Let's take a look back at some of the biggest security incidents of 2025. First of all:

The US government remained one of the top targets in cyberspace. This year began with a brazen cyber attack on the U.S. Treasury by Chinese hackers, followed by a security flaw in SharePoint that compromised several federal agencies, including the agency tasked with protecting the U.S. nuclear arsenal.

All the while, Russian hackers were stealing sealed records from U.S. court filing systems, sounding alarm throughout the federal judiciary.

But nothing came close to that, as DOGE breached federal departments and databases in what became the largest U.S. government data raid in history.

Tesla CEO Elon Musk listens with black eyes as U.S. President Donald Trump speaks to reporters in the Oval Office of the White House on May 30, 2025.WASHINGTON DC – MAY 30: A dark-eyed Tesla CEO Elon Musk listens as US President Donald Trump speaks to reporters in the Oval Office of the White House on May 30, 2025 in Washington, DC. Image credit: Kevin Dietsch / Getty Images

The Trump administration's Department of Government Efficiency (DOGE, as it was widely known), led by Elon Musk and his band of private-sector minions, violated federal protocol and defied common security practices. Despite warnings about national security risks and conflicts of interest surrounding Mr. Musk's overseas dealings, they looted federal databases of national data. Legal experts say DOGE employees are “personally liable” under U.S. hacking laws, but would also need court consent.

Musk's public falling out with President Trump later led to the billionaire leaving DOGE, and staffers feared they could face federal charges without Musk's protection.

In late September, senior executives at large American companies began receiving threatening emails from a prolific ransomware and extortion group called Clop. Attached to the email were copies of personal information and a multi-million dollar ransom demand not to be released.

Several months ago, the Clop gang secretly exploited a never-before-seen vulnerability in Oracle's E-Business software, a suite of applications used to host companies' core business information, including financial and human resources records, supply chain data, and customer databases. This vulnerability allowed Clop to steal large amounts of sensitive employee data, including data belonging to executives, from dozens of organizations that relied on Oracle's software.

Oracle was busy fixing the vulnerability and didn't know about it until it was discovered in October. But it was already too late. Hackers had already stolen large amounts of data from universities, hospitals, health systems, news organizations, and more.

This was Klopp's latest major hacking operation. The group previously exploited flaws in enterprise file transfer services such as GoAnywhere, MOVEit, and Cleo Software, which are used by tech giants to share large amounts of information over the Internet.

Salesforce customers have had a tough year due to two data breaches that allowed hackers at the downstream technology company to steal 1 billion customer data stored in Salesforce's cloud.

Hackers targeted at least two companies: Salesloft and Gainsight. Both companies enable customers to process and analyze data stored in Salesforce.

By penetrating these companies directly, hackers were able to access all data through customer connections to Salesforce. Some of the largest technology companies had their data stolen in this breach, including Bugcrowd, Cloudflare, Google, Proofpoint, Docusign, GitLab, Linkedin, SonicWall, and Verizon.

A hacking collective known as Scattered Lapsus$ Hunters, made up of members from various hacking groups including ShinyHunters, published a data breach site advertising stolen records in exchange for a ransom paid by victims. The number of new victims continues to increase.

Hackers breached the UK retail industry earlier this year, stealing data from Marks & Spencer and stealing at least 6.5 million customer records from Co-ops. The back-to-back hacks caused outages and disruptions across the retailer's network, destroying systems used to support retailers and leaving some grocery store shelves empty. Later, luxury store Harrods was also hacked.

BIRMINGHAM, UK - SEPTEMBER 30: Aerial view of the JLR sign at the Jaguar Land Rover Vehicle Manufacturing Plant in Castle Bromwich, Birmingham, UK on September 30, 2025.Aerial view of the JLR sign after the hack and data breach at the Jaguar Land Rover vehicle manufacturing plant in Castle Bromwich, Birmingham, UK, September 30, 2025. Image credit: Christopher Furlong / Getty Images

But a major cyberattack targeting Jaguar Land Rover, one of the country's biggest employers, has hit the UK economy hard. A hack and data breach in September halted production at JLR's car factories for several months as the company worked to get its systems back up and running.

The impact has affected JLR's suppliers across the UK, with some going out of business altogether. The UK government has finally secured a £1.5bn bailout for Jaguar Land Rover's employees and suppliers to ensure they receive a paycheck during the closure.

British security experts said the breach was the most economically damaging cyber attack ever to hit the UK and showed that disruption could be more valuable to financially motivated hackers than stolen data.

South Korea has experienced major data breaches every month this year, putting the personal data of millions of citizens at risk thanks to security flaws and sloppy data practices at the country's largest technology and phone providers.

SK Telecom, the country's largest telephone company, was hacked and 23 million customer records were exposed. Some cyberattacks are believed to have been carried out by hostile neighboring North Korea. A large-scale data center fire destroyed many years of South Korean government data that had not been backed up.

But the centerpiece of the data breach was the theft over several months of the personal information of about 33 million customers from the country's retail giant Coupang, also known as the Amazon of Asia. The data theft began in June but was not discovered until November and ultimately led to the resignation of the company's chief executive.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

UK NHS technology provider confirms data breach

December 18, 2025

Cisco announces Chinese hackers are exploiting customers with new zero-day attack

December 17, 2025

Hacking group says it's blackmailing Pornhub after stealing users' viewing data

December 16, 2025

Google and Apple release emergency security updates after zero-day attack

December 12, 2025

Credit reporting giant 700Credit's data breach affects at least 5.6 million people

December 12, 2025

Researchers say Home Depot had access to its internal systems exposed for a year

December 12, 2025

Leave A Reply Cancel Reply

Top Reviews
Editors Picks

7 days left: Founders and VCs save over $300 on all stage passes

March 24, 2025

AI chip startup Furiosaai reportedly rejecting $800 million acquisition offer from Meta

March 24, 2025

20 Hottest Open Source Startups of 2024

March 22, 2025

Andrill may build a weapons factory in the UK

March 21, 2025
About Us
About Us

Welcome to Tech Brunch, your go-to destination for cutting-edge insights, news, and analysis in the fields of Artificial Intelligence (AI), Cryptocurrency, Technology, and Startups. At Tech Brunch, we are passionate about exploring the latest trends, innovations, and developments shaping the future of these dynamic industries.

Our Picks

Crafton raises stakes in India with new $670 million funding

December 19, 2025

Hacking, theft and destruction: 2025's worst data breaches

December 19, 2025

UK NHS technology provider confirms data breach

December 18, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

© 2025 TechBrunch. Designed by TechBrunch.
  • Home
  • About Tech Brunch
  • Advertise with Tech Brunch
  • Contact us
  • DMCA Notice
  • Privacy Policy
  • Terms of Use

Type above and press Enter to search. Press Esc to cancel.