communitychoicecu.comCommunity Choice Credit Union domain; breach victim organization
ThreatNoir Weekend Brief — May 9
Morning Review in IT Security — May 9, 2026
The threat landscape continues to intensify as multiple high-profile organizations face data exposure incidents spanning financial services, hospitality, technology, and retail sectors. Today's review covers six significant breaches affecting millions of users across North America, Europe, and South America, underscoring the persistent vulnerability of critical infrastructure and customer databases to sophisticated threat actors.
Community Choice Credit Union Allegedly Breached Exposing 1M+ Premium Credit Client Records
A threat actor is actively advertising a dataset attributed to Community Choice Credit Union that contains over one million records from premium credit clients. The perpetrator has released a sample demonstrating access to sensitive financial information including full card numbers, cardholder names, issuing banks, and residential addresses. The domain communitychoicecu.com has been identified as the targeted organization. Source: Community Choice Credit Union Allegedly Breached Exposing 1M+ Premium Credit Client Records
ShinyHunters Claims Second Attack Against Instructure
The threat actor group ShinyHunters has claimed responsibility for a second attack against Instructure, the major educational technology company serving institutions worldwide. The breach poses significant risk to hundreds of millions of individuals whose personally identifiable information is potentially compromised. Instructure continues efforts to regain control of its systems and mitigate the exposure of user data across its platform. Source: ShinyHunters Claims Second Attack Against Instructure
Preferred Hotels & Resorts Allegedly Breached Exposing 450,000 High-Net-Worth Reservations
A threat actor claims to have exploited a vulnerability in the Preferred Hotels & Resorts Central Reservation System during 2025, resulting in the extraction of approximately 450,000 reservation records across 620 hotels in the network. The breach specifically targeted high-net-worth individuals, exposing sensitive travel and personal information associated with luxury hospitality bookings. Source: Preferred Hotels & Resorts allegedly breached exposing 450,000 high-net-worth reservations
Meetic Allegedly Leaked Exposing 7 Million User Records From the French Online Dating Platform
A significant data exposure has affected Meetic, one of France's leading online dating platforms, with a threat actor claiming to have leaked 7,169,561 user records. The perpetrator released the entire database publicly under the hashtag #freebreach3d, making the personal information of millions of European users freely available on the dark web. Source: Meetic Allegedly Leaked Exposing 7 Million User Records From the French Online Dating Platform
Credilink Allegedly Breached Exposing 243 Million Records From the Brazilian Credit Data Provider
A threat actor is actively selling a dataset containing 243 million records attributed to Credilink, a Brazilian credit information and risk analysis provider serving financial institutions and retailers throughout the region. The breach of this critical financial infrastructure provider exposes sensitive credit data that could facilitate identity theft and fraud across Brazil's financial sector. Source: Credilink Allegedly Breached Exposing 243 Million Records From the Brazilian Credit Data Provider
LDLC Allegedly Leaked Exposing 1.5 Million Customer Records From the French Tech Retailer
LDLC, a prominent French technology retailer, has suffered a data leak exposing 1.5 million customer records. The breach compromises personal and transactional information from the company's customer base, raising concerns regarding compliance with European data protection regulations. Source: LDLC Allegedly Leaked Exposing 1.5 Million Customer Records From the French Tech Retailer
The convergence of these incidents demonstrates the escalating sophistication and scale of threat actor operations targeting organizations across multiple continents and sectors. Organizations must prioritize immediate incident response protocols, customer notification procedures, and comprehensive security assessments to address vulnerabilities in critical systems and infrastructure.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- #freebreach3dCampaign hashtag used by threat actor to announce and distribute the leaked Meetic database
credilink.com.brBreached Brazilian credit data provider