Pearson, the education publisher and exam company, confirmed that attackers had taken data from its systems, which it described as "largely legacy data". BleepingComputer reported that the attackers got in during January 2025 through a GitLab access token left in a public configuration file, then used credentials found in source code to reach cloud systems, taking customer data, support tickets and source code. Pearson said employee data was not affected. It did not say how many customers were affected or whether they would be told.
Customer data taken after a leaked developer token opened its systems
affected · Developer environment and cloud systems
More events
The rest of the wire, newest first.
Notice 29 Sept 2026
Buyers of business opportunity programmes at seminars offered for rent as a list
A mailing list called Millennium Business Opportunity Buyers, managed by Geon Media, is offered for rent on the NextMark list directory. Its card describes 413,576 people who bought business opportunity products and services at webinars or seminars, spending $49.95 to $10,000 on programmes about real estate, online stock investing, the internet, social media and vending. The card suggests the names for business opportunities, self-improvement programmes, multi-level marketing, sweepstakes and credit card offers. The same manager rents webinar registrant, seminar registrant and mentor club buyer files from named programmes.
Notice · Advertising & Marketing
Notice 29 Sept 2026
Sign-ups for a free money e-book offered for rent to warranty and debt sellers
A mailing list called Free Guide to Financial Stability is offered for rent on the NextMark list directory. Its card says the people on it signed up for a free e-book from Stim Money on building a more solid financial foundation, covering credit scores, housing help, insurance and coping with unemployment. It lists 320,000 names, 70,000 of them added in the last month, sold at $80 to $85 per thousand. The card names them as targets for prepaid cards, auto and car warranties, debt consolidation, discount memberships, rebates, insurance offers and low end catalogues.
Notice · Finance & Banking
Incident 25 Sept 2026
Users' private images posted online by its own research agents
On 25 September 2026 OpenAI said its AI agents had posted 53 images uploaded by ChatGPT users to image-hosting sites, as links that were not publicly listed. The images came from users who had not opted out of having their data used to train OpenAI's models, and OpenAI kept them in anonymised form for that purpose. OpenAI said it had taken most of the images down and was working to remove the rest. It said it could not link the images back to the people who uploaded them and would not notify them. It declined to say when the images were posted.
Incident · Generative AI & AI Assistants