Major Cyber Attacks, Data Breaches, Ransomware Attacks in April 2026


Date

Victim

Summary

Threat Actor

Business Impact

Source Link

April 1, 2026

Mercor

Mercor says it was hit by cyber attack tied to compromise of open-source LiteLLM project

TeamPCP (supply chain compromise) and Lapsus$ (claimed data theft)

The supply chain attack compromised Mercor through the LiteLLM library, potentially exposing sensitive company data, including source code, databases, and credentials while impacting thousands of organisations relying on the same software.

Mercor Cyber Attack

April 1, 2026

CareCloud, Inc. and its patients/users

On March 24, 2026, CareCloud filed a report with the SEC regarding a network outage in its Health division that affected one of six EHR systems for approximately eight hours around March 16.

Unknown

The incident caused a network disruption in CareCloud’s health systems and potentially exposed sensitive patient data, putting affected individuals at risk of identity theft and fraud while investigations into data access continued.

CareCloud Data Breach

April 1, 2026

Cisco Systems

Cisco source code stolen in Trivy-linked dev environment breach

TeamPCP

The attackers breached Cisco’s internal development environment using stolen credentials, leading to the theft of source code, exposure of AWS keys, and unauthorised access to internal systems and customer-related repositories, raising risks of further compromise.

Source: Bleeping Computer

April 3, 2026

European Commission and multiple EU entities

CERT-EU: European Commission hack exposes data of 30 EU entities

TeamPCP

The cloud-based breach exposed sensitive data from at least 30 EU entities, including emails, usernames, and internal information, after attackers infiltrated the European Commission’s hosting environment and exfiltrated data without disrupting services.

Source: Bleeping Computer

April 7, 2026

Jones Day

Jones Day confirms data breach after hackers leak client files online

Silent ransom group

The phishing-based breach allowed hackers to access and leak sensitive client files linked to at least 10 clients, exposing confidential legal data and raising risks of reputational damage and potential misuse of sensitive information.

Jones Day Data Breach

April 7, 2026

Snowflake customers

Snowflake customers hit in data theft attacks after SaaS integrator breach

ShinyHunters

The breach of a SaaS integration provider allowed attackers to steal authentication tokens and use them to access and exfiltrate sensitive data from multiple Snowflake customer environments, leading to widespread data theft and potential extortion risks.

Source: Bleeping Computer

April 8, 2026

Eurail B.V.

Passport numbers for more than 300,000 leaked during December Eurail data breach

Unknown

The breach exposed personal data,including names and passport numbers, of over 300,000 travelers after hackers accessed Eurail’s systems, with the stolen information later being offered for sale on the dark web, increasing risks of identity theft and fraud.

Source: The Record

April 8, 2026

Los Angeles City Attorney’s Office (affecting Los Angeles Police Department data)

Breach exposes LAPD files stored in city attorney system

World Leaks

The breach exposed around 7.7TB of sensitive LAPD data, including personnel records, witness details, and medical information after hackers accessed a city attorney system, raising serious privacy and safety concerns for officers and individuals involved in cases.

Source: The Record

April 08, 2026

China’s supercomputers

A hacker has allegedly breached one of China’s supercomputers and is attempting to sell a trove of stolen data

FlamingChina

The cyber attack allegedly led to the theft of more than 10 petabytes of sensitive data including defence research and classified scientific information creating major national security concerns and exposing weaknesses in critical infrastructure protection

Source: CNN.com

April 13, 2026

Basic-Fit

Hack at Dutch gym chain Basic-Fit exposes customer data in several EU countries

Unknown

The breach attack exposed personal and financial data of around 1 million gym members across multiple European countries after hackers breached internal systems and downloaded sensitive information, increasing risks of fraud and phishing.

Source: The Record

April 13, 2026

Booking.com

Booking.com confirms hackers accessed customers data

Unknown

The breach allowed unauthorised access to customer booking data including names contact details and reservation information which was later used in phishing attacks to target users and potentially compromise their accounts and personal information.

Source: Tech Crunch

April 13, 2026

Rockstar Games

Stolen Rockstar Games analytics data leaked by extortion gang

ShinyHunters

The breach led to the theft and public leak of internal analytics data including game metrics and user behavior insights, exposing business sensitive information and creating extortion pressure on the company despite no impact on players or operations.

Source: Bleeping Computer

April 14, 2026

McGraw-Hill

McGraw-Hill confirms data breach following extortion threat

ShinyHunters

The breach allowed attackers to access a limited set of internal data through a Salesforce misconfiguration and use it for extortion threats, creating risks of data exposure and reputational damage despite no access to sensitive customer or student information.

Source: Bleeping Computer

April 20, 2026

Ameriprise Financial Services

Ameriprise Data Breach Impacts More Than 47,000 People

Unknown

The data breach exposed sensitive personal information of 47,876 customers after an unauthorised actor accessed internal data, increasing risks of identity theft and financial fraud for affected individuals.

Ameriprise Data Breach

April 20, 2026

Bol.com

Dutch ecommerce site Bol.com investigates claims of a data breach

Unknown

The incident raised concerns after a dataset allegedly containing around 400,000 customer records was put up for sale online, potentially exposing personal and account details and increasing risks of phishing and fraud, although the company said there was no confirmed breach or system compromise.

Source: techzine.eu

April 21, 2026

Vercel (via breach at Context AI)

App host Vercel confirms security incident; says customer data was stolen via breach at Context AI

Unknown

The breach allowed hackers to access internal systems and steal customer data, including API keys, source code, and database information after compromising a third-party AI tool, raising concerns about wider downstream risks across multiple organisations.

Source: Tech Crunch

April 21, 2026

Canada Life

Hackers accessed personal information of 70,000 people in Canada Life data breach

ShinyHunters

The breach exposed personal information including names, dates of birth, addresses, gender, and income details of up to 70,000 individuals after attackers accessed systems through a compromised employee account, increasing risks of identity theft and targeted fraud.

Canada Life Data Breach

April 21, 2026

Gonets satellite communication system (Russia)

Ukrainian hackers breach internal data of Russia’s Starlink-like Gonets system

Ukrainian hackers (pro-Ukraine cyber units)

The cyber attack exposed sensitive internal communications and operational data from Russia’s Gonets satellite system after Ukrainian hackers gained access to internal accounts, potentially revealing infrastructure details and intelligence linked to military and state users.

Russia’s Gonets satellite communication system breached

April 22, 2026

France Titres (Agence Nationale des Titres Sécurisés – ANTS)

France Titres data breach: 19 million records allegedly stolen

breach3d

The breach potentially exposed sensitive personal data such as names, birth details, contact information, and account identifiers of millions of individuals, significantly increasing risks of phishing, identity theft, and large-scale social engineering attacks.

France’s Titres Data Breach

April 23, 2026

Vercel

Vercel says some of its customers’ data was stolen prior to its recent hack

Unknown

The breach revealed that hackers had already accessed and stolen some customer data before the incident was detected, indicating a broader compromise that exposed sensitive information and increased risks for affected users.

Source: Tech Crunch

April 23, 2026

Rituals Cosmetics

Luxury cosmetics giant Rituals discloses data breach

Unknown

The breach exposed customer membership data including names, contact details, and demographic information after attackers accessed and downloaded records from Rituals’ loyalty database, increasing risks of phishing and targeted scams despite no financial data being compromised.

Luxury Cosmetics Giant Rituals Breached

April 24, 2026

Udemy

ShinyHunters claim Udemy data theft

ShinyHunters

Udemy faced a large-scale data breach claim in which ShinyHunters said they stole 1.4 million user and instructor records, exposing email addresses, names, phone numbers, physical addresses, employer details, and instructor payout information, creating significant phishing, fraud, and identity theft risks for affected users.

Source: cybernews.com

April 24, 2026

UK Biobank

UK Biobank data breach raises concerns over healthcare data security

Unknown

The breach led to sensitive health and genetic data of around 500,000 individuals being exposed and even listed for sale online, raising serious privacy concerns and prompting authorities to suspend access and investigate the incident.

Source: Cyber Express

April 24, 2026

Coupang

South Korea says Coupang data breach probe affects US security talks

Unknown

The massive data breach involving tens of millions of users escalated beyond a corporate incident, straining U.S.–South Korea relations and delaying key security and defence discussions due to legal and political tensions surrounding the investigation.

Source: Investing.com

April 24, 2026

ADT Inc.

ADT confirms data breach after ShinyHunters leak threat

ShinyHunters

ADT confirmed that attackers accessed and stole customer and prospective customer data, exposing personal information such as names, phone numbers, and addresses, while triggering an internal investigation and containment efforts after the intrusion was discovered.

Source: Bleeping Computer

April 27, 2026

Medtronic

Medtronic confirms breach after hackers claim 9 million records theft

ShinyHunters

Medtronic confirmed that attackers breached parts of its corporate IT environment and accessed internal data, with hackers claiming to have stolen around 9 million records, forcing the company to launch containment and forensic investigations, although patient care, products, and operations remained unaffected.

Source: Bleeping Computer

April 28, 2026

Vimeo

Vimeo confirms user and customer data breach

ShinyHunters

Vimeo confirmed that attackers accessed customer email addresses, technical data, and video metadata through a compromised third-party vendor, exposing user information but without disrupting platform operations or affecting login credentials and payment data.

Source: Security Week

April 28, 2026

Pitney Bowes

Pitney Bowes becomes the latest victim of ShinyHunters breach spree

ShinyHunters

Pitney Bowes confirmed that attackers accessed business customer records in its Salesforce CRM environment after a phishing-led account compromise, exposing millions of contact records and creating risks of phishing, fraud, and customer data misuse, though its core systems remained unaffected.

Source: The Register

April 29, 2026

Amtrak

Amtrak data breach exposes millions of customer records

ShinyHunters

Amtrak suffered a large-scale data breach in which attackers apparently gained access to millions of customer records, exposing names, email addresses, physical addresses, and support ticket histories, increasing the risk of highly targeted phishing and identity-based fraud against travelers.

Amtrak Data Breach

April 30, 2026

Movistar Perú

Movistar Peru data breach impacts 4 million users

Dedale

Movistar Perú suffered a large-scale data exposure affecting nearly 4 million users, with leaked names, phone numbers, national IDs, birth dates, and telecom plan details, increasing the risk of phishing, identity theft, and SIM-swapping fraud against customers.

Source: escudodigital.com

April 30, 2026

National Health Insurance Company of Moldova (CNAM)

Moldova’s health insurance agency reports possible data leak after cyber attack

Unknown

Moldova’s health insurance agency reported that a cyber attack may have exposed sensitive patient and payment records affecting roughly one-third of its healthcare database, raising serious privacy risks for insured citizens even though medical services continued without disruption. 

Source: The Record Media





Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


The Samsung Keyboard supports glide typing, voice dictation, multiple languages, and deep customization through Good Lock. On paper, it’s a very capable and perfectly functional keyboard. However, it’s only when I started using it that I realized great features don’t necessarily translate to a great user experience. Here’s every problem I faced with the Samsung Keyboard, and why I’m permanently sticking with Gboard as my main Android keyboard.

I have been using Gboard and the Samsung Keyboard on a recently bought Galaxy S24, which I got at a massive discount.

Google’s voice typing doesn’t cut me off mid-sentence

Fewer corrections, fewer cutoffs, faster dictation

I might be a professional writer, but I hate typing—whether it’s on a physical keyboard or a virtual one. I type slower than I think, which I suspect is true for most people. That becomes a problem when I have multiple ideas in my head and need to get them down fast. It’s happened far too often: I start typing one idea and forget the other. Since jacking my brain into a computer isn’t an option (yet), I’ve been leaning more and more on voice typing as the fastest way to capture my thoughts.

Now, both Samsung Keyboard and Gboard support voice typing, but I’ve noticed that Gboard with Google’s voice engine is just better at transcription accuracy. It picks up on accents flawlessly and manages to output the right words. In my experience, it also seems to have a more up-to-date dictionary. When I mention a proper noun—something recently trending like a video game or a movie name—Samsung’s voice typing fails to catch it, but Google nails it.

That said, you can choose Google as your preferred voice typing engine inside Samsung Keyboard, but it’s a buggy experience. I’ve noticed that the transcription gets cut off while I’m in the middle of talking—even when I haven’t taken a long pause. This can be a real problem when I’m transcribing hands-free.

Gboard offers a more accurate glide typing experience

Google accurately maps my swipe gestures to the right words

Voice typing isn’t always possible, especially when you’re in a crowded place and want to be respectful (or secretive). At times like these, I settle for glide (or swipe) typing. It’s generally much faster than tapping on the keyboard—provided the prediction engine maps your gestures to the right word. If it doesn’t, you have to delete that word, draw that gesture again, or worse—type it out manually.

Now, both Samsung Keyboard and Gboard support glide typing, but I’ve noticed Gboard is far more accurate. That said, when I researched this online, I found a 50-50 divide—some people say Gboard is more accurate, others say Samsung is. I do have a theory on why this happens.

Before my Galaxy S24, I used a Pixel 6a, before that a Xiaomi, and before that a Nokia 6.1 Plus. All of my past smartphones came with Gboard by default. I believe Gboard learned my typing patterns over time—what word correlates to what gesture, which corrections I accept, and which ones I reject. After a decade of building up that prediction model, Gboard knows what I mean when my thumb traces a particular shape. Samsung Keyboard, on the other hand, is starting from zero on this Galaxy S24—leading to all the prediction errors. At least that’s my working theory.

There’s also the argument for muscle memory. While glide typing, you need to hit all the correct keycaps for the prediction engine to work. If you’re even off by a slight amount, the prediction model might think you meant to hit “S” instead of “W.” Now, because of my years of typing on Gboard, it’s likely that my muscle memory is optimized for its specific layout and has trouble adapting to Samsung’s.

Swiping vs typing.


Is Swiping Really Faster Than Typing on a Phone Keyboard?

Which typing method reigns supreme?

I mix three languages in one message, and Gboard just gets it

Predictive multilingual typing doesn’t get any better than this

I’m trilingual—I speak English, Hindi, and Bengali. When I’m messaging my friends and family, we’re basically code-mixing—jumping between languages in the same sentence using the Latin alphabet. Now, my friends and I have noticed that Gboard handles code-mixing much more seamlessly than Samsung Keyboard.

If you just have the English dictionary enabled, neither keyboard can guess that you’re trying to transliterate a different language into English. It’ll always try to autocorrect everything, which breaks the flow. The only way to fix this is by downloading a transliteration dictionary like Hinglish (Hindi + English) or Bangla (Latin). Both Samsung Keyboard and Gboard support these dictionaries, but the problem with Samsung Keyboard is that it can only use one dictionary at a time.

Let’s say I’m writing something in Latinized Bangla and suddenly drop a Hindi phrase. Samsung Keyboard will attempt to autocorrect those Hindi words. Gboard is more context-aware. Since my Hinglish keyboard is already installed, I don’t have to manually switch to it. Gboard can detect that I’m using a Hindi word even with the English or Bangla keyboard enabled, and it won’t try to autocorrect what I’m writing. This also works flawlessly with glide typing, which is a huge quality-of-life improvement over Samsung Keyboard.

This isn’t just an India-specific thing either. Code-mixing is how billions of people type every day—Spanglish in the US, Taglish in the Philippines, Franglais across parts of Europe and Africa.

Gboard looks good without me spending an hour on it

I don’t have time for manual customization

Samsung Keyboard is hands down the more customizable option, especially if you combine it with the Keys Cafe module inside Good Lock. You get granular control over almost every aspect of the keyboard—key colors, keycaps, gesture animations, and a whole lot more. While for some users, this is heaven, I just find it too overcomplicated and a massive time sink.

I don’t have the patience to sit and adjust every visual detail of my keyboard. Sure, it gets stale after a while, and you’d want to freshen it up, but I don’t want to spend the better part of an hour tweaking a virtual keyboard. This is where Gboard wins (at least for me) by doing less.

Android 16 brings Material 3 Expressive, which automatically themes your system apps using your wallpaper’s color scheme. With Gboard, all you have to do is change the wallpaper, and the keyboard updates to match—no Good Lock, no manual color picking. It’s a cleaner, more seamless way to keep your phone looking good without putting in the extra legwork.


The keyboard you don’t think about is the one that’s working

I didn’t switch to Gboard because Samsung Keyboard was broken. I switched because Gboard made typing feel effortless. If you’re a Samsung user who’s never tried it, it’s a free download and a five-second switch. You might not go back either.

Pixel 7 with the 8vim keyboard.


I Tried the Weirdest Android Keyboards So You Don’t Have To

Can strange layouts and gestures beat the good old-fashioned QWERTY?



Source link