Sign in

Mathew J Schwartz

@mathewjschwartz.bsky.social
210 followers 101 following 1.2K posts

Cybersecurity reporter

PostsRepliesMedia
Mathew J Schwartz @mathewjschwartz.bsky.social · 1h
Weekly Cryptohack Roundup: —Cybersecurity consultant convicted in a $54 million exploit case —$30 million penalty in Fundsz fraud case —ZackXBT probe into North Korean laundering operation —Crypto wallets linked to ransomware gang www.databreachtoday.com/cryptohack-r...
databreachtoday.com
Cryptohack Roundup: Conviction in Uranium Finance Hack
This week, a conviction in a $54 million exploit, a $30 million Fundsz fraud penalty, Near Intents post-hack, Abstract Blockchain will shutdown, Velocity’s victim
000
Mathew J Schwartz @mathewjschwartz.bsky.social · 4h
A concerted Chinese attempt to take over neighboring Taiwan is more likely to involve "cyber-enabled economic warfare" rather than outright invasion, a Washington, D.C., national security think tank warns. www.databreachtoday.com/china-could-...
databreachtoday.com
China Could Coerce Taiwan by Hacking Comms, Think Tank Warns
A concerted Chinese attempt to take over neighboring Taiwan is more likely to involve "cyber-enabled economic warfare" rather than outright invasion,
010
Mathew J Schwartz @mathewjschwartz.bsky.social · 7h
Anthropic expands its "Cyber Verification Program" to accept usage applications for three tiers of access, including one designed for cyber defenders www.databreachtoday.com/anthropic-ex...
databreachtoday.com
Anthropic Expands Access to Frontier Cyber AI Models
Anthropic opened its advanced cyber AI program to applications from any organization, offering tiered access for defense, red teaming and critical infrastructure
000
Mathew J Schwartz @mathewjschwartz.bsky.social · 22h
Sign of the times: South Korea suspects a relatively new, free AI penetration testing tool helped an attacker steal data on 66,000 customers from seven of the country's banks. www.bankinfosecurity.com/south-korea-...
bankinfosecurity.com
South Korea Suspects AI Tool Helped Steal Bank Customer Data
Police in South Korea probing data breaches at multiple banks have found signs on attack servers that the threat actor used a free, open-source and semi-automated
101
Mathew J Schwartz @mathewjschwartz.bsky.social · 23h
The number of patients affected by a 2025 hacking incident involving health data contained on legacy servers managed by Oracle-owned electronic health record vendor Cerner has soared to about 20 million. www.databreachtoday.com/oracle-healt...
databreachtoday.com
Oracle Health's Cerner EHR Breach Figure Soars to 20 Million
The number of patients affected in a 2025 hacking incident involving health data managed by electronic health record vendor Cerner has soared to about 20 million.
010
Mathew J Schwartz @mathewjschwartz.bsky.social · 08/10/2026
Two August cyberattacks against U.S.-bound supertankers — which led to them being boarded by Coast Guard and FBI cyber specialists — exploited known but unpatched vulnerabilities in the ships' on-board systems, a federal official said this week. www.databreachtoday.com/coast-guard-...
databreachtoday.com
Coast Guard Boardings of Hacked Vessels: New Details
Two cyberattacks on U.S.-bound supertankers in August, which led to them being boarded by Coast Guard and FBI cyber specialists, exploited known, unpatched
000
Mathew J Schwartz @mathewjschwartz.bsky.social · 08/10/2026
Medical devices and other healthcare tech are lagging traditional IT systems in their ability to support post-quantum cryptography, raising concerns for healthcare delivery organizations about protecting sensitive patient data from future quantum attacks. www.databreachtoday.com/medical-devi...
databreachtoday.com
Medical Devices Face a Post-Quantum Security Gap
Medical devices and other healthcare technology are lagging traditional IT systems in their ability to support post-quantum cryptography, raising concerns for
000
Mathew J Schwartz @mathewjschwartz.bsky.social · 08/10/2026
EU drops sponsorship of disinformation conference at Trump officials’ request www.theguardian.com/us-news/2026...
theguardian.com
EU drops sponsorship of disinformation conference at Trump officials’ request
Lithuania and Canada were also pressured to withdraw, and days before #Disinfo2026, logos were wiped off website
130
Mathew J Schwartz @mathewjschwartz.bsky.social · 08/10/2026
All hail "Le Chonk": The Mistral model may finally allow European companies to deploy highly capable and privately run AI that is neither American nor Chinese. www.databreachtoday.com/mistral-tout...
databreachtoday.com
Mistral Touts 'Le Chonk' as Capable European Sovereign Model
Mistral, the French company widely seen as Europe's only potential artificial intelligence champion, unveiled a new model that boasts strong cybersecurity
000
Mathew J Schwartz @mathewjschwartz.bsky.social · 08/10/2026
Dutch startup Hadrian closed a $40 million Series B funding round to expand its offensive security platform into internal attack-path testing, agentic AI risk detection and autonomous remediation that can proactively implement controls to stop attacks. www.databreachtoday.com/hadrian-expa...
databreachtoday.com
Hadrian Expands Offensive Security Platform With $40M Raise
Dutch startup Hadrian closed a $40 million Series B funding round to expand its offensive security platform into internal attack-path testing, agentic AI risk
000
Mathew J Schwartz @mathewjschwartz.bsky.social · 07/10/2026
Denmark braces for wave of phishing attacks after attackers steal data for nearly 9 million Danes from the Central Register of Persons www.databreachtoday.com/denmark-brac...
databreachtoday.com
Denmark Braces for Wave of Phishing Attacks
Denmark's residents have been hit by a data breach affecting the country's Central Register of Persons, exposing names, addresses, CPR numbers and other details of
042
Mathew J Schwartz @mathewjschwartz.bsky.social · 07/10/2026
Google pauses open-source software bug bounty program amid AI slop, citing 'significant rise in automated submissions' lacking validity www.databreachtoday.com/google-pause...
databreachtoday.com
Google Pauses Open-Source Bug Bounty Program Amid AI Slop
Google has indefinitely paused a bug bounty program designed to reward researchers who find flaws in the open-source software it maintains, citing "a
010
Mathew J Schwartz @mathewjschwartz.bsky.social · 07/10/2026
Citrix patched yet another under-fire zero-day in NetScaler (no, not the two that were being exploited starting in August and patched on Sept. 27) www.databreachtoday.com/citrix-patch...
databreachtoday.com
Citrix Patches Yet Another Under-Fire Zero-Day in NetScaler
Just one week after patching two zero-day vulnerabilities being actively exploited in its NetScaler appliances, Citrix has issued another emergency patch for a
010
Mathew J Schwartz @mathewjschwartz.bsky.social · 05/10/2026
US Senate unanimously passes health cybersecurity bill designed to bolster health sector cybersecurity and resiliency. Among other provisions, the bill calls for regulators to raise the bar on minimum cyber best practices for healthcare sector organizations. www.databreachtoday.com/us-senate-un...
databreachtoday.com
US Senate Unanimously Passes Health Cyber Bill
The U.S. Senate on Thursday unanimously passed a bipartisan bill that proposes to bolster health sector cybersecurity and resiliency. Among other provisions, the
020
Mathew J Schwartz @mathewjschwartz.bsky.social · 05/10/2026
A suspected member of the "financially motivated data theft and extortion brand" ShinyHunters, who's 16 years old, has reportedly been detained in Jordan and is assisting the FBI. www.databreachtoday.com/key-shinyhun...
databreachtoday.com
Key ShinyHunters Suspect Reportedly Detained in Jordan
Sixteen-year-old Saif al-Din Khader, a suspected member of the ShinyHunters digital extortion group, has reportedly been detained in Jordan and is assisting the
020
Mathew J Schwartz @mathewjschwartz.bsky.social · 05/10/2026
For sale: a phishing toolkit that taps social media posts and advertisements to deliver adversary-in-the-middle attacks. The Chinese-language kit, 'Milk Dragon,' is sold on a subscription basis. www.databreachtoday.com/phishing-too... #AiTM
databreachtoday.com
Phishing Toolkit Taps Social Media Posts and Advertisements
Want to amass more phishing scam victims? Offering targets soon-to-expire discounts on well-known consumer brand items is one of the strategies being practiced by
010
Mathew J Schwartz @mathewjschwartz.bsky.social · 24/09/2026
Texan member of Scattered Spider #cybercrime group receives 45-month prison sentence, must forfeit $18 million in ill-gotten #cryptocurrency gains, plus vehicles, jewelry, 150 pairs of shoes and "one painting of Muhammad Ali." www.databreachtoday.com/texan-scatte...
databreachtoday.com
Texan Scattered Spider Member Receives 45-Month Sentence
A Texas man who admitted to being a member of the notorious cybercrime group Scattered Spider has been sentenced to serve nearly three years in U.S. federal prison.
010
Mathew J Schwartz @mathewjschwartz.bsky.social · 23/09/2026
Cyber extortion group claims: 'We have compromised the FBI.' Experts see the threat to leak stolen FBI employee data as being primarily a brand-building exercise designed to pressure future victims. www.databreachtoday.com/cyber-extort...
databreachtoday.com
Cyber Extortion Group Claims: 'We Have Compromised the FBI'
Cyber extortion group ShinyHunters claims to have breached FBI systems and stolen employees' personal data, threatening its release unless. DataBreachToday
000
Mathew J Schwartz @mathewjschwartz.bsky.social · 22/09/2026
Migrating to post-quantum cryptography might sound fine in theory, but can organizations procure the new hardware they need, and from a trusted supplier? In a video interview, Moona Ederveen-Schneider details evolving #PQC and geopolitical challenges. www.databreachtoday.com/post-quantum...
databreachtoday.com
Post-Quantum Cryptography Migration Faces a Hardware Problem
Migrating to post-quantum cryptography might sound fine in theory, but can organizations procure the new hardware they need, and from a trusted supplier? Answering
000
Mathew J Schwartz @mathewjschwartz.bsky.social · 22/09/2026
No one has any idea what Trump's 'AI Force' would do www.databreachtoday.com/no-one-has-a...
databreachtoday.com
No One Has Any Idea What Trump's 'AI Force' Would Do
President Donald Trump says he is forming an "AI Force" modeled on Space Force and will soon name an AI czar. The announcement came with no mission,
000
Mathew J Schwartz @mathewjschwartz.bsky.social · 22/09/2026
Not so harmonious: EU states hoard cyber incident data, as auditors find cross-border cooperation has only gone so far. www.databreachtoday.com/so-harmoniou...
databreachtoday.com
Not So Harmonious: EU States Hoard Cyber Incident Data
When hackers triggered cascading disruptions to European air travel in fall 2025, none of the affected countries - including Germany, Belgium and Ireland -
000
Mathew J Schwartz @mathewjschwartz.bsky.social · 22/09/2026
Cyber extortion war: ShinyHunters holds rival Cl0p to ransom www.databreachtoday.com/blogs/cyber-...
databreachtoday.com
Cyber Extortion War: ShinyHunters Holds Rival Clop to Ransom
Russian cyber extortion group Cl0p appears to be under fire from Western rival ShinyHunters, which defaced Cl0p's data-leak site, dropped names of the group's alleged members, and demanded a large ran...
000
Mathew J Schwartz @mathewjschwartz.bsky.social · 17/09/2026
US boarded 2 commercial oil tankers to investigate cyberattacks potentially perpetrated by Iran or by another threat actor trying to exploit the ongoing Iran-U.S. war. www.databreachtoday.com/us-boarded-2...
databreachtoday.com
US Boarded 2 Oil Tankers to Investigate Cyberattacks
The Coast Guard and FBI boarded two foreign oil tankers bound toward Texas after signs their networks were compromised, inspecting IT and operational systems as
010
Mathew J Schwartz @mathewjschwartz.bsky.social · 17/09/2026
Scoop: Texan member of the notorious Scattered Spider cybercrime collective pleads guilty to hack attacks. Ahmed Elbadawy tied to dozens of social engineering hits, SIM swapping, exfiltrating sensitive databases and stealing millions in cryptocurrency. www.databreachtoday.com/texan-scatte...
databreachtoday.com
031
Mathew J Schwartz @mathewjschwartz.bsky.social · 16/09/2026
Zero-days found in popular TP-Link "smart" security camera www.databreachtoday.com/zero-days-fo... #IoT
databreachtoday.com
Zero-Days Found in TP-Link Smart Security Camera
Two previously unknown vulnerabilities in TP-Link's best-selling home security camera could open the door to attacker exploitation and compromise other network
010
Mathew J Schwartz @mathewjschwartz.bsky.social · 16/09/2026
Iranian state hackers are targeting dissidents, activists and journalists over messaging apps and pushing them to open malicious files on their personal devices to avoid corporate security controls, warn cybersecurity agencies in a joint alert. www.databreachtoday.com/iranian-hack...
databreachtoday.com
Iranian Hackers Dodging Corporate Defenses to Reach Critics
Iranian state hackers are steering dissidents, activists and journalists away from corporate devices and onto personal computers to plant spyware that can capture
000
Mathew J Schwartz @mathewjschwartz.bsky.social · 16/09/2026
Discourse about the potential of unchecked AI systems and frontier labs' ability to control rogue AI agents culminated in several AI executives calling for slower AI development, a move that saw AI-related stocks fall and drew rebuke from the U.S. president. www.databreachtoday.com/ai-ceos-call...
databreachtoday.com
AI CEOs Call for Slower Frontier Development as Stocks Fall
Discourse about the potential of unchecked AI systems and frontier labs' ability to control rogue AI agents culminated in several AI executives calling for slower
000
Mathew J Schwartz @mathewjschwartz.bsky.social · 16/09/2026
Revolut's hacker began blackmailing crypto industry figures at least two months ago, after stealing their data by wielding a hacked government agency email account to socially engineer the payments platform into sharing it. www.databreachtoday.com/crypto-indus...
databreachtoday.com
Crypto Industry Figures Blackmailed by Revolut's Hacker
Personally identifiable information for multiple cryptocurrency industry figures was targeted and stolen by the threat actor who hacked payments platform Revolut,
000
Mathew J Schwartz @mathewjschwartz.bsky.social · 16/09/2026
UK lawmakers call for new legislation to address the threat AI may pose to human rights, including demands that the riskiest systems clear regulatory hurdles before deployment - and warning that no U.K. regulator can currently stop a model from shipping. www.databreachtoday.com/no-uk-regula...
databreachtoday.com
No UK Regulators Can Stop Risky AI Models, Panel Warns
British lawmakers are calling for new legislation to address the threat AI may pose to human rights, including demands that the riskiest systems clear regulatory
000
Mathew J Schwartz @mathewjschwartz.bsky.social · 15/09/2026
Popular DevSecOps platform GitLab is being actively targeted by hackers attempting to exploit a recently patched, critical path traversal vulnerability that allows them to steal data stored on a GitLab server, including sensitive data and credentials. www.databreachtoday.com/in-the-wild-...
databreachtoday.com
In-the-Wild Attacks Hit Popular DevSecOps Platform GitLab
Attackers are actively targeting a recently patched vulnerability in the popular DevSecOps platform GitLab that they can exploit to steal data and credentials from
010
Mathew J Schwartz @mathewjschwartz.bsky.social · 15/09/2026
Financial platform Revolut reports data breach after falling for social engineering attack that looked like official government request for sensitive customer data. www.databreachtoday.com/revolut-reve...
bankinfosecurity.com
Revolut Reveals Data Breach Tied to Faked Official Request
Digital financial platform Revolut is notifying customers that it suffered a data breach exposing their personal details after it fell for an official-looking
000
Mathew J Schwartz @mathewjschwartz.bsky.social · 15/09/2026
Finnish authorities issued a European Arrest Warrant for convicted Vastaamo hacker Aleksanteri Kivimäki after he failed to return to prison, widening the search for the man who stole 33,000 psychotherapy records and extorted patients. www.databreachtoday.com/finnish-poli...
databreachtoday.com
Finnish Police Alert Europe Over Fugitive Vastaamo Hacker
Finnish authorities issued a European Arrest Warrant for convicted Vastaamo hacker Aleksanteri Kivimäki after he failed to return to prison, widening the search
010
Mathew J Schwartz @mathewjschwartz.bsky.social · 14/09/2026
Ukrainian who helped develop Conti ransomware gets 4 years in US prison after being arrested/extradited from Cork, Ireland. www.databreachtoday.com/ukrainian-co...
databreachtoday.com
Ukrainian Conti Ransomware Developer Gets 4 Years in US Prison
A U.S. court sentenced Ukrainian national Oleksii Lytvynenko to four years in prison after he admitted developing malware and stealing data for Conti, the
000
Mathew J Schwartz @mathewjschwartz.bsky.social · 14/09/2026
Hardcoded credentials recovered from corporate cloud environments are giving cyber-extortion groups such as FulcrumSec ongoing, easy access to experimental drug data, customer records and more. www.databreachtoday.com/novo-nordisk... #cybersecurity
databreachtoday.com
Novo Nordisk Data Breach Tied to Stolen GitHub Access Tokens
Cyber extortion group FulcrumSec continues to find hardcoded credentials in public-facing IT infrastructure and exploit them as part of what it's dubbed a
010
Mathew J Schwartz @mathewjschwartz.bsky.social · 07/09/2026
Patch now: Latvian manufacturer MikroTik issues update to fix multiple vulnerabilities in its routers, including two being chained together, which Poland's computer emergency response team discovered being used for in-the-wild attacks "in recent days." routers-amid-zero-day-attacks-a-32762
databreachtoday.com
MikroTik Issues Patches for Routers Amid Zero-Day Attacks
Latvian router-maker MikroTik has issued emergency patches in the face of in-the-wild "MikroTrick" attacks that chain together exploits for two zero-day
000
Reposted by Mathew J Schwartz
Brian Honan @brianhonan.bsky.social · 03/09/2026
Many thanks to @mathewjschwartz.bsky.social for including my comments on this issue and how organisations need to include non-digital data, such as paper based data, in their data protection program. Its an issue I see a lot where paper records are not protected as well as they should be #GDPR
063
Mathew J Schwartz @mathewjschwartz.bsky.social · 04/09/2026
This week's data breach roundup includes: —FBI probes a massive breach of U.S. driver's licenses —Dropbox accounts breached —Border Gateway Protocol hijack compromises Virtualizor servers —U.S. Coast Guard opens a cybersecurity policy office www.databreachtoday.com/breach-round...
databreachtoday.com
Breach Roundup: FBI Probes Sale of 153 Million Driver's Licenses
This week: a massive breach of U.S. driver's licenses, Dropbox accounts breached, a BGP hijack, Artifactory flaw, Russian national indicted, Aesto health breach, a
000
Mathew J Schwartz @mathewjschwartz.bsky.social · 03/09/2026
Ireland's data protection watchdog details psychiatric data breaches after medical records 'contaminated by animal droppings' recovered from disused hospitals filled with asbestos and mold. Cue #GDPR fines/requirements for the country's national health service www.databreachtoday.com/irish-privac...
databreachtoday.com
Irish Privacy Watchdog Details Psychiatric Data Breaches
Rotting "old mental health" records stored on paper "contaminated by animal droppings" and left in abandoned psychiatric hospitals in Ireland
030
Mathew J Schwartz @mathewjschwartz.bsky.social · 02/09/2026
Attackers have begun attempting to target a critical vulnerability in open-source framework Langflow, used to build artificial intelligence agents and workflows. The flaw enables remote-code authentication without an attacker having to first authenticate. www.databreachtoday.com/attacks-targ...
databreachtoday.com
Attacks Targeting Langflow AI Agent-Building Tool Surge
Open-source framework Langflow, designed to build artificial intelligence agents and workflows, is under fire again, with attackers now wielding exploit code for a
030
Mathew J Schwartz @mathewjschwartz.bsky.social · 02/09/2026
Attackers are actively exploiting flaws in PaperCut NG/MF printer management software. PaperCut issued a second set of emergency patches; rresearchers found weaknesses in first effort, and said anyone still running unpatched version should assume compromise. www.databreachtoday.com/attackers-ac...
databreachtoday.com
Attackers Actively Exploit Flaws in PaperCut NG/MF
Print management software vendor PaperCut published two emergency patches as it battles attackers actively exploiting zero-day vulnerabilities in widely used
000
Mathew J Schwartz @mathewjschwartz.bsky.social · 01/09/2026
Insight Partners spent $200 million on an IP intelligence vendor led by the former CEO of BeyondTrust to increase the size of its research organization. www.databreachtoday.com/spur-expands...
databreachtoday.com
Treasury Launches Quantum Task Force for Financial Sector
The U.S. Department of the Treasury launched a public-private Quantum-Readiness Task Force to move banks, market infrastructures and their vendors toward
000
Mathew J Schwartz @mathewjschwartz.bsky.social · 01/09/2026
Quantum leap: The U.S. Department of the Treasury is building a public-private task force as part of an effort to push banks, market infrastructure operators and their technology vendors onto quantum-safe encryption. www.databreachtoday.com/treasury-lau... #cryptography
databreachtoday.com
Treasury Launches Quantum Task Force for Financial Sector
The U.S. Department of the Treasury launched a public-private Quantum-Readiness Task Force to move banks, market infrastructures and their vendors toward
020
Mathew J Schwartz @mathewjschwartz.bsky.social · 01/09/2026
A cyberattack last week disrupted medical technology maker Boston Scientific's global operations, affecting remote monitoring capabilities of some of its new cardiac devices. www.databreachtoday.com/hack-hinderi...
databreachtoday.com
Hack Hindering Boston Scientific Cardiac Device Monitoring
A cyberattack this week that disrupted medical technology maker Boston Scientific's global operations is disrupting remote monitoring capabilities of some of its
000
Mathew J Schwartz @mathewjschwartz.bsky.social · 01/09/2026
Even comes with a refueling crew 🤣
010
Mathew J Schwartz @mathewjschwartz.bsky.social · 01/09/2026
Dialysis chain to pay $15 million to settle class action lawsuit resulting from 2025 ransomware and data theft attack that affected over 2.5 million people. www.databreachtoday.com/dialysis-cha...
databreachtoday.com
Dialysis Chain to Pay $15M Settlement in Interlock Attack
DaVita, which operates more than 3,000 kidney dialysis centers in the United States and 14 other countries, has agreed to pay $15 million to settle proposed class
000
Mathew J Schwartz @mathewjschwartz.bsky.social · 31/08/2026
Judge orders Pentagon to reverse Anthropic blacklisting, saying it "constituted unlawful retaliation in violation of the First Amendment." www.databreachtoday.com/judge-orders...
databreachtoday.com
Judge Orders Pentagon to Reverse Anthropic Blacklisting
The U.S. federal judge told the Department of Defense to cancel the supply chain designation it levied against Anthropic in a decision giving the artificial
000
Mathew J Schwartz @mathewjschwartz.bsky.social · 22/08/2026
A rising number of cyberattacks have AI-assisted fingerprints, with Claude Code especially tied to semi-automated intrusions, data theft and ransomware attacks. How do researchers know this? Attackers' OPSEC, or lack thereof. www.databreachtoday.com/rising-numbe...
databreachtoday.com
Rising Number of Cyberattacks Have AI-Assisted Fingerprints
Attackers' operational security fails reveal they're increasingly wielding artificial intelligence tools in semi-autonomous ways to help them conduct reconnaissance
000
Mathew J Schwartz @mathewjschwartz.bsky.social · 21/08/2026
Democratic U.S. senators are demanding answers from the State Department about why the U.S. is requiring that government officials have direct access to the health data systems of dozens of foreign nations as a condition for U.S. global health funding. www.databreachtoday.com/senators-pro...
databreachtoday.com
Senators Probe US Access to Foreign Health Data Systems
Eight U.S. senators are demanding answers from the U.S. State Department about why the government is requiring that American officials have direct access to the
000
Mathew J Schwartz @mathewjschwartz.bsky.social · 21/08/2026
U.S. federal prosecutors charged 17 Iranian nationals with a decade-long hacking campaign that stole more than 31 terabytes of research and intellectual property from hundreds of universities, companies and government agencies around the world. www.databreachtoday.com/us-doj-charg...
databreachtoday.com
US DOJ Charges 17 Iranians in Decade-Long Hacking Campaign
A 14-count superseding indictment unsealed Tuesday charges 17 members of the Mabna Institute with stealing more than 31 terabytes of research and intellectual
000
Mathew J Schwartz @mathewjschwartz.bsky.social · 21/08/2026
More than three weeks after a wave of cyberattacks struck dozens of rural and small town water and wastewater utilities in at least 12 states, experts are still trying to figure out what exactly the attackers thought they were doing. www.databreachtoday.com/baffling-cas...
databreachtoday.com
A Baffling Case of Inept Iranian Strikes on Water Utilities
More than three weeks after a wave of likely Iranian cyberattacks struck dozens of rural and small town water and wastewater utilities in at least 12 states,
031