Today, I loaded the 1,000th data breach into Have I Been Pwned. Reflecting on that milestone number, I pondered how to mark the occasion in writing, and what immediately came to mind was a very simple question: why is it still needed? Espec

The 1,000th data breach has been added to the Have I Been Pwned (HIBP) service, a milestone that prompts reflection on the persistent need for such tools. The ongoing accumulation of data breaches suggests that the time lag between a breach occurring and its public disclosure may be worsening.
HIBP, a website that allows individuals to check if their personal information has been compromised in known data breaches, now contains records from 1,000 distinct security incidents. The sheer volume of breaches cataloged highlights a significant and ongoing problem in the digital landscape.
The accumulation of such a large number of breaches raises questions about the effectiveness of current data protection measures and the transparency surrounding security incidents. The fact that HIBP continues to grow, reaching this significant number, indicates that organizations are still experiencing frequent and substantial data compromises.
While the exact reasons for the potential increase in disclosure lag are not detailed, the milestone suggests a systemic issue. This could involve challenges in breach detection, internal investigation processes, or a reluctance to disclose incidents promptly.
The implications of delayed breach disclosure are significant for individuals. Without timely notification, affected parties are left vulnerable to identity theft, financial fraud, and other malicious activities for longer periods. This extended exposure increases the potential harm caused by a breach.
For organizations, a delayed disclosure can exacerbate the damage to their reputation and lead to greater regulatory scrutiny and potential fines. Prompt and transparent communication is generally considered best practice in managing the aftermath of a security incident.
The continued need for services like HIBP underscores the reality that data breaches are a persistent threat. The service provides a valuable resource for individuals to proactively check their exposure and take steps to mitigate potential risks.
General security best practices for individuals include using strong, unique passwords for different accounts, enabling multi-factor authentication wherever possible, and being vigilant about phishing attempts and suspicious communications. Regularly reviewing financial accounts for unauthorized activity is also recommended.

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.