They Did Not Steal Passwords. They Stole the Map of Who to Attack Next.

Alleged Entra directory theft exposed organisational maps rather than passwords. Treat bulk directory reads as a high-impact identity event.

Alleged Entra directory theft exposed organisational maps rather than passwords. Treat bulk directory reads as a high-impact identity event.

SafePal says private keys and funds were not exposed, but order records linked wallet ownership to names, contact details and home addresses.

France’s Education Ministry is testing whether a breach first described as staff-only reached student records across a fragmented national data estate.

ExfilSquad’s leaked data points to exposed Dataverse records, not a confirmed Dynamics exploit. Anonymous low-code permissions can be the entire breach path.

MyDr cannot yet confirm the breach scope, while officials cite nearly 19 million people. The platform concentration risk is already clear.

RingCentral’s core platform was not breached, yet 1.6 million people were exposed. The incident shows why organisational security extends beyond production infrastructure.

Business intelligence platforms are rarely treated like privileged infrastructure. They sit behind dashboards, charts and reports. They are used by analysts, managers and finance teams. They do not look like identity systems, hypervisors or database servers, so they are often…