CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back 🛡 Active Threats

Data Breaches That Have Happened This Year (2026 Update) - tech.co

tech.co Archived Mar 17, 2026 ✓ Full text saved

Data Breaches That Have Happened This Year (2026 Update) tech.co

Full text archived locally
✦ AI Summary · Claude Sonnet


    Data breaches have become an all-too-common reality for businesses in 2026. From small startups to huge corporations, these breaches are impacting everyone and understanding the full scope of the problem is the first step to preventing your business from falling victim. Additionally, the consequences of these breaches are nothing if not substantial. Ransomware attacks, phishing schemes, and even weak passwords are wreaking havoc on businesses, forcing some to shutter their doors when these attacks become too much to bare. That’s why we want to spread the word and keep businesses in the know about what kind of companies are being hit with data breaches, so you can understand exactly how big the problem is and how you can keep your business safe in 2026. Find Out if Your Personal Data Is Being Leaked Online in Real-Time Surfshark One includes a data breach and credit card info alert system, along with a VPN and antivirus protection for just $3.19/month. Get Surfshark One 🛡️ 30 Day Risk-Free Money Back Guarantee 💰 Key Takeaways Types: Data breaches are the result of a number of types of cyber attacks, including phishing schemes, ransomware attacks, malware, and social engineering. Cost: Statistics vary, but most studies put the cost of a data breach between one and ten million dollars. Business size: No matter the size of your business, data breaches are possible, with big names like McDonald’s and Adidas falling victim. Prevention: Businesses can prevent data breaches by training staff and shoring up cybersecurity measures like two-factor authentication. Data Breaches in 2026 January 2026 January 18 Brightspeed: The fiber broadband provider opens investigation into claims that personal information belonging to more than 1 million customers was stolen by the Crimson Collective hacker group. January 16 Canadian Investment Regulatory Organization (CIRO): CIRO discloses that personal information belonging to 750,000 people was compromised during a wide-ranging cyberattack in August 2025. Reportedly, the breach was the result of a “sophisticated phishing attack.” January 7 Ledger: The crypto hardware wallet provider revealed that its third-party payment processor, Global-e, had been the victim of a security incident exposing customer names and contact information. The breach has affected an undisclosed number of users who have made purchases on Ledger.com. January 4 Sedgwick: The ransomware gang TridentLocker has claimed responsibility for stealing 3.4GB of data from the claims administration company’s government-focused subsidiary. Samples of the information have supposedly been posted on TridentLocker’s dark web leak site. January 2 Illinois Department of Human Services: The agency recently disclosed that due to human error, the private health-related information of about hundreds of thousands of Illinoisans was uplaoded to a publicly accessible website. The information was left there for more than three years before the mistake was discovered. Data Breaches in 2025 December 2025 December 15 700Credit: The largest provider of credit checks and identity verification services for automotive businesses in North America confirms that it suffered a massive data breach between July and October 2025. Reportedly, more than 5.8 million individuals were affected, with hackers gaining access to customer information via a compromised third-party API. December 10 Pierce County Library: Data was accessed belonging to patrons of the Pierce County Library between April 15 and April 21 this year, as disclosed on the organization’s website. Compromised data included names and dates of birth of patrons, as well as current and former employees social security numbers, financial account information, driver’s license numbers, credit card information, passport numbers, health insurance information, medical information and dates of birth. TriZetto Provider Solutions: The company has started notifying clients of a cybersecurity issue stemming from a a web portal used by customers to access its systems.  The date of this access was pinpointed to October 2nd, and TriZetto claims no further unauthorized access has occurred since this date. Compromised information includes addresses, dates of birth, social security numbers, and health insurance numbers. December 9 VITAS Hospice Services: The largest for-profit hospice company in the US, VITAS, reported that a vendor account had given cybercriminals access to over 300,00 patient accounts, and included data such as medical information, social security numbers and next-of-kin contacts. December 5 Inotiv: Pharmaceutical firm Inotiv notifies people that it has been the victim of a ransomware attack, and personal information has been stolen. The breach, which took place in August, affected 9,542 individuals. Although not yet verified, the group Qilin has taken responsibility for the breach and states it took over 162,000 files. December 3 Freedom Mobile: Canadian company Freedom Mobile informed customers that in October it had detected unauthorized activity on its customer account management platform. A third party had gained access to the system and customer data was compromised, including first and last name, home address, date of birth, phone number and Freedom Mobile account number. Asus: Tech firm Asus announces on its website that one of its suppliers was hacked by a third party, affecting its camera source code. The firm assures customers that products, privacy and company systems are not impacted. December 1 Coupang: It is revealed that South Korea’s largest online retailer has been the victim of a data breach, potentially affecting almost 34 million customers. The breach is believed to stem from a a server overseas being compromised earlier in the year. No credit card data is believed to have been accessed, but compromised data includes names, email addresses, phone numbers and postal addressed. The CEO later resigns from the company as a result of the breach. November 2025 November 27 Mixpanel/OpenAI/Pornhub: Third party analytics platform Mixpanel disclosed a data breach that occurred on November 9. Data taken includes analytics data sets that could be used to identify individuals. One of Mixpanel’s clients, OpenAI, has since terminated its collaboration with Mixpanel. In December, hacking group ShinyHunters claimed responsibility for the hack and claimed to hold information on Pornhub Premium members, and is attempting to extort these customers. November 26 Marquis: In notifications filed in Maine, Texas and Iowa, fintech firm Marquis revealed that it had experienced a data breach in August, with the data of almost 800,000 individuals being compromised, with personal and financial information being accessed. November 22 SitusAMC: Real estate company SitusAMC announced that it had experienced a security incident which led to its systems being compromised. It stated that data affected included accounting records and legal agreements, and data related to client customers may have also been involved. November 11 Fieldtex Products Inc: The company announced that on August 19th it had identified unauthorized activity within its computer systems. It stated that a “limited amount of protected health information may have been impacted.” November 10 Nikkei Data Breach: The Japanese publishing giant confirmed it suffered a data breach that put the personal information of over 17,000 employees and business partners at risk, after unauthorized actors gained access to the company’s Slack platform. The attackers were able to gain access by stealing the login credentials from an employee’s compromised personal computer. November 7 The Washington Post Hacking: The media giant revealed that it had fallen victim to a hacking as part of a wider attack on some Oracle business software. The attackers were supposedly mailing executives at various organizations in early October, demanding a ransom payment for files they had stolen. October 2025 October 30 Hyundai Data Breach: The automotive manufacturer has suffered a data breach that compromised the personal data of up to 2.7 million owners. The stolen data includes Social Security numbers and driver’s licenses. October 23 Conduent Business Services Data Breach: Nearly 4.3 million individuals were impacted by a breach of Conduent Business Services, a New Jersey-based business services provider. The breach was reported to the California Attorney General in October, but took place in late 2024 and early 2025. Many other companies customers were affected — About 462,000 current and former customers of Blue Cross Blue Shield of Montana saw their details exposed, for just one example. October 14 Vietnam Airlines Data Breach: Vietnam airlines contacted customers on October 14th by email to inform them that hacked had uploaded 23 million records, including those belonging to airline customers, to a forum on October 10th. The data is believed to span from November 2020 to June 2025. The airline stated that the source of the breach was a third party platform. October 11 Qantas Data Breach: Data stolen from the Australian airline has been leaked online, with Qantas stating that customer names, email address and frequent flyer numbers of over five million customers are included. The data was leaked on the dark web by hacking group Scattered Lapsus$ Hunters after the deadline for ransom payment passed. October 6 Huawei Data Breach: A threat actor claims credit for a breach at the China-based Huawei Technologies, saying they gained sensitive intellectual property from the incident. According to the claim, the stolen data includes internal assets: source code, development tools, build files, scripts, and technical manuals. The threat actors is reportedly attempting to sell some of this data. October 3 Discord Data Breach: Popular messaging and VoIP social platform Discord has revealed a breach to one of its third-party customer service providers. Stolen data may include names, email addresses, billing information including payment type and the last four digits of credit cards, and even images of government IDs. Discord hasn’t disclosed the exact amount, calling it “limited” – however, the platform has 200 million monthly active users, so even a small fraction could impact millions. October 1 Kido Schools Data Breach: Hackers attempted to extort Kido Schools, a nursery chain, with threats to leak stolen children’s images and data on the internet. At first, the group posted several batch of profiles of their young victims on their website. However, once the news gained traction with a disgusted public, the hackers had a change of heart, first blurring the images before ultimately deleting all the data entirely. Kido has not paid the ransom, thought to be around £600,000 (that’s a little over $700,00 USD). September 2025 September 27 Harrods Data Breach: Luxury UK department store Harrods has had 430,000 customer records stolen in a data breach, taken by an unauthorized third party. The company have said the stolen data includes basic personal information, such as names and contact details. It has also said it is not going to engage with the “threat actor.” September 21 Stellantis Data Breach: The car-making company Stellantis, responsible for Chrysler, Fiat, Jeep, and Dodge brands, has confirmed a data breach that involved personal customer information. In a statement, the company said it had experienced the breach of a third-party platform that supports its North American customer service operations. A spokesperson of the company declined to answer what customer data types were stolen. September 15 Kering Data Breach: Kering, the owner of luxury brands including Gucci, Balenciaga and Alexander McQueen, has revealed it suffered a data breach after hackers stole sensitive customer data. Among the stolen data were names, email addresses, phone numbers, home addresses, and the total amount of money they spent in stores. Kering has assured customers that the stolen data doesn’t include credit card numbers. It has contacted those affected by the breach, and has not disclosed how many have been affected. September 8 Tenable Data Breach: Tenable, an exposure management company, has disclosed it suffered a data breach as part of a wider attack on Salesforce and the Salesloft Drift marketing application that has impacted numerous organizations. This has come after an unauthorized user gained access to a segment of customer information stored within its Salesforce instance. It has advised its customers to remain vigilant. September 2 Jaguar Land Rover Cyberattack: The British carmaker has shut down its car production after dealing with a cyberattack. The company have said the attack has affected “some data,” although it could not provide details of what data was affected, including whether customers’ or suppliers’ information was stolen. August 2025 August 15 Workday Data Breach: The HR giant reported a data breach where hackers stole an unspecified amount of personal information from one of its third-party customer relationship databases. Stolen information included names, email addresses, and phone numbers. According to Workday, no customer tenants were impacted. August 6 Google Salesforce CRM Breach: Dozens of companies have been breached through the Salesforce CRM, with hackers using social engineering techniques to call employees posing as IT, getting them to install a fake app on their device to access data. August 5 Cisco Vishing Attack: Networking giant Cisco announced that an employee fell victim to a voice phishing attack — or vishing attack — that allowed the hackers to access sensitive user including email addresses and phone numbers. July 2025 July 28 TransUnion Data Breach: The consumer credit reporting company has warned customers that a data breach has exposed the personal information of over 4.4 million people in the US. The information was stolen from the company’s Salesforce account. While TransUnion have said the data exposed is “limited,” it has not been confirmed what this entails exactly. July 26 Tea Dating Advice Hack: US-based women-only app in the US revealed there had been “unauthorized access” to 72,000 images submitted by women. The company has said the breach affected users who signed up before February 2024, and that it had “acted fast” and “was working with some of the most trusted cyber security experts.” July 16 Allianz Life Cyberattack: Over a million people at risk after the insurance giant confirmed a cyberattack that saw it lose sensitive data on the “majority” of customers. The attack occured when an unauthorized actor accessed a third-party CRM the company uses. July 14 McDonald’s Cybersecurity Error: More than 64 million McDonald’s job applicants have their personal information exposed thanks to a huge security oversight in an AI chatbot. The issue was highlighted by two security researchers, who managed to crack the chatbot with the password “123456.” July 11 Anne Arundel Dermatology Cybersecurity Incident: Personal information belonging to no fewer than 1.9 million individuals is compromised during a massive data breach at Anne Arundel Dermatology. This follows a similar breach that took place on May 13, 2024. June 2025 June 27 Compumedics USA, Inc. Data Seizure: A ransomware attack affecting more than 318,000 people is revealed. According to the company, an unauthorized party gained access to its network between February 15, 2025 and March 23, 2025. June 24 McLaren Health Care Data Breach: Over 743,000 individuals are notified that their personal information has been seized in a massive cyberattack. Reportedly, the attack occurred between July 17, 2024 and August 3, 2024. June 12 Central Kentucky Radiology Cyberattack: The medical facility begins notifying its customers that it has recently become aware of a data breach which took place on October 18, 2024. It is thought that compromised information includes credit or debit card numbers and other confidential information. June 9 United Natural Foods Cyberattack: The primary food distributor for supermarket giant Whole Foods said on Monday it had become aware of “unauthorized activity” on some of its IT systems. This has caused the supplier to take some services offline, leaving some grocery store shelves empty. May 2025 May 29 Farmers Insurance Data Breach: The insurance company has revealed a data breach impacting 1.1 million customers, as a result of the widespread Salesforce attacks. The company announced that an unauthorized actor accessed its database at a third-party vendor containing customer information. May 29 Victoria’s Secret Incident: The fashion giant has taken down its website and some in-store services, in response to a security incident. Customers are still being served in Victoria’s Secret and PINK stores, however CEO Hillary Super has told employees that, “Recovery is going to take a while.” May 24 LexisNexis Risk Solutions Data Breach: The Georgia-based data analytics company has revealed that a data breach in December 2024 caused the personal information of over 364,000 individuals to be stolen. May 23 Adidas Data Breach: According to the sneaker and sportswear giant, hackers were able to obtain customer contact information through a “third-party customer service provider.” The company has assured that the affected data doesn’t include passwords, credit card or any other payment-related information. May 22 Coca-Cola Data Leak: Ransomware gang Everest claimed they’d swiped personal data from 959 employees. The gang threatened to release the data unless Coca-Cola contacted them for a deal, and when it didn’t, they released 1,104 files, including passport scans and visa copies. April 2025 April 28 Ascension Health Cyberattack: Ascension Health reveals that a cyberattack it suffered in December led to the seizure of information belonging to 437,000 patients. April 21 Union Health System, Inc Data Breach: The Indiana-based healthcare company, which comprises two hospitals and a medical group, discloses that it has suffered a data breach. As many as 262,831 individuals are thought to have been affected. Onsite Mammography Cyberattack: Healthcare company reveals that the breach that it suffered last year led to more than 350,000 individuals being compromised. April 14 Bell Ambulance, Inc. Data Seizure: Company confirms that it was subject to a data breach in February 2025. 114,000 individuals are estimated to have been affected. April 13 OnTrac Hacker Attack: The last-mile delivery company suffered an attack where the attackers obtained personal details including IDs and health information. Dates of birth, Social Security numbers, and driver’s licenses could have also been accessed. The attack affected over 40,000 individuals. April 11 Yale New Haven Health System Data Breach: Healthcare center discloses that it has experienced a “data security incident.” Roughly 5.6 million patients may have been affected, according to estimates from the Department of Health and Human Services. Endue Software Cyberattack: Software provider reveals that it was recently affected by a cyberattack in which customer data was illicitly accessed. The company thinks that 118,028 customers may have been affected. April 9 Blue Shield of California Data Theft: The health insurance giant suffers a massive data breach. Over a three-year window, it’s suspected that as many as 4.7 million patients could be impacted. April 4 Alabama Ophthalmology Associates Cyberattack: Healthcare practice announces that, in January 2025, it became aware of suspicious activity within its network environment. This led to the seizure of information belonging to 131,576 patients. Central Texas Pediatric Orthopedics Data Seizure: Pediatric healthcare provider notifies patients about a data breach that it suffered in January 2025. It’s thought that 140,000 patients may have been affected. April 2 Dameron Hospital Cyberattack: California-based hospital is forced to pay out $650,000 to settle litigation related to a massive cyberattack it experienced back in December 2023, during which information belonging to 210,706 individuals was illegally accessed. April Google Data Leak: The massive data leak has made 183 million Gmail credentials vulnerable, including emails and passwords. March 2025 March 28 Community Dental Care, Inc. Cyberattack: The Minnesota-based dental care facility discloses that sensitive personal information belonging to 134,903 patients was accessed during a cybersecurity breach that occurred in December 2024. Frederick Health Cybersecurity Incident: Frederick Health Medical Group is subject to a massive cybersecurity breach in which 934,326 patients are affected. Reportedly, stolen information includes patient names, addresses, dates of birth, social security numbers, drivers’ license numbers, medical record numbers, health insurance information, and clinical information related to some patients’ care. March 26 Cooper Health System Data Seizure: The three-hospital Southern New Jersey health system revealed that certain personal and protected health information was stolen by an unknown actor on May 14, 2024. Potentially affected data included names, dates of birth, Social Security numbers, and health insurance information. March 24 DaVita Ransomeware Attack: The healthcare company has reported an attack on its internal operations, which has primarily affected its laboratories. DaVita is offering breach victims free identity restoration services. March 14 Chord Data Leak: Dental practice reveals that a third party gained access to several employee email accounts between August and September 2024. Confidential information belonging to 173,430 patients is thought to have been accessed. March 7 Sunflower Medical Group, P.A. Cyberattack: Medical company reveals that information belonging to 220,968 individuals was illicitly accessed in December 2024. The company claims there is no evidence to suggest that personal information has been “misused.” Numotion Data Breach: Wheelchair and mobility equipment provider confirms that it suffered a data breach resulting in the exposure of 494,326 individuals’ personal information. The breach occurred between September and November 2024, with an unauthorized third party gaining access to employee emails through a phishing scam. March 4 Hillcrest Convalescent Center, Inc. Cyberattack: Hillcrest announces that it has suffered a data breach, with information belonging to 106,194 individuals thought to have been illicitly accessed. This potentially includes names, dates of birth, social security numbers, patient data, medical information, treatment information, health insurance information, and healthcare provider information. February 2025 February 28 Legacy Professionals LLP Data Leak: Accounting firm notifies Attorney General of Maine that “sensitive identifiable information” under its stewardship has been accessed, following suspicious activity related to data stored on its computer network. More than 215,000 people are thought to have been affected. February 11 New Era Life Insurance Companies Cyberattack: Insurance company notifies customers that as many as 335,506 individuals may have been compromised in a massive cyberattack. Exposed information is thought to include names, birth dates, insurance ID numbers, claim information, and social security numbers. February 8 Authority of the City of Bainbridge and Decatur County Data Hack: Over 120,000 individuals thought to be affected by significant data breach. The breach resulted from unauthorized access to a number of different locations, including desktop computers, laptops, and network servers. February 6 VectraRx Mail Pharmacy Services, LLC Data Breach: Arizona-based delivery service notifies customers that it was subject to a data breach in December 2024, with over 100,000 customers thought to be affected. Stolen information potentially includes names, social security numbers, and dates of birth. January 2025 January 30 Community Health Center, Inc Cyberattack: More than 1 million patients are compromised in massive cyberattack in the largest healthcare data breach of the year up until this point. Some of the affected patients in question are deceased, so their next of kin have been notified. January 21 University Diagnostic Medical Imaging, PC Data Breach: Radiology facility announces that it recently suffered a cyberattack. Personal information belonging to 138,080 people is believed to have been compromised. January 17 Allegheny Health Network Data Loss: Allegheny Health Network’s home medical equipment and home infusion therapy services are compromised in a massive data breach. It’s estimated that information belonging to as many as 292,773 individuals could’ve been exposed. Asheville Eye Associates, PLLC Hacking Incident: Data belonging to more than 200,000 individuals is seized in a massive cyberattack. Exposed information included names, addresses, health insurance information, and medical treatment information. January 14 Bankers Cooperative Group, Inc Cyberattack: New Jersey-based insurance broker shares details of a cyberattack that took place in August 2024, in which sensitive customer information was accessed via one employee email account. January 9 Heritage Health Care Data Theft: Healthcare provider discloses that data belonging to over 12,000 people was compromised in a cyberattack in October 2024. The data in question could include names, dates of birth, social security numbers, and health insurance information. January 7 Medusind Inc. Data Breach: Medical billing company is subject to a cyberattack, exposing the data of 360,000 individuals. Among the compromised data, the hackers have stolen personal information, health information, health insurance and billing information, payment information, and government identification. January 4 Buffalo Surgery Center Data Seizure: Medical clinic notifies patients that a massive data security incident has affected Excelsior Orthopaedics, LLP, one of its affiliates. The hack is thought to have affected as many as 64,000 patients. Data Breaches in 2024 December 2024 December 30 Tycon Medical Systems, Inc. Data Seizure: Information potentially belonging to 112,847 patients is stolen during a massive data breach. Compromised information is not currently known, but it could include names, Social Security numbers, and medical records. December 24 Lexington Diagnostic Center Data Breach: The Kentucky radiology center confirms that data belonging to 29,819 patients was compromised in a March 2024 cyberattack. Reportedly, stolen data varied from patient to patient, and there is not yet any evidence that it has been misused. December 23 Dignity Health Lassen Medical Clinic Hack: California-based medical clinic notifies 65,482 of its patients that their data may have been compromised in a September 2024 cyberattack. Stolen files include patient information, such as names, addresses, dates of birth, driver’s license numbers, financial account numbers, medical information, and health insurance information. December 20 In-Home Attendant Services Ltd. Data Theft: Company files notice that confidential information under its control was accessed by an unauthorized party. Information including names, Social Security numbers, driver’s license numbers, financial account information, medical information, health insurance information, and dates of birth was compromised. December 19 Richmond University Medical Center Data Breach: Richmond University Medical Center reports a data breach after discovering that bad actors gained access to files on its computer network. It is thought that 674,033 individuals were impacted. December 18 Ott Cone & Redpath, PA Data Theft: The company, which provides legal services to several healthcare entities, discloses that it was subject to a cyberattack that could affect as many individuals as 22,171. December 17 PracticeSuite, Inc. Data Breach: PracticeSuite, Inc. notifies customers that a server it uses for storage was illegally accessed on October 18. The leak potentially affects around 13,000 people. December 16 Rhode Island Cyberattack: A major cyberattack exposes the personal and bank information of hundreds of thousands of Rhode Island residents, with an international cybercriminal group thought to be responsible. December 11 Senior Dating Data Breach: Dating platform Senior Data is subject to a massive data breach, exposing the personal information of 765,517 users. Ladies.com, which is owned by the same entity, is also impacted. December 6 Michigan Township Civic Center Hack: A planned $45 million civic center project is suspended after the township’s finances are illegally accessed in a “sophisticated cybersecurity attack.” December 5 PIH Health Hospitals Data Breach: PIH Health Hospitals is targeted in a ransomware attack, leaving its more than 3 million California patients unable to access health care until their systems come back online. December 3 Bologna FC Ransomware Attack: Italian soccer club Bologna FC is hit by a massive cyberattack, in which passport scans, contracts, and personal data for the club’s players since 2017 is accessed, alongside information about the club. November 2024 November 21 Finastra Cyberattack: One of the largest fintech companies in the world, UK-based Finastra is illegally accessed, with hackers obtaining over 400GB of data, including sensitive client information. November 19 Library of Congress Data Breach: Library of Congress’s communication systems are illegally accessed, with the cybercriminals able to read private emails between employees and congressional offices. November 11 China-backed Hackers Breach US Telecom Providers: Multiple telecommunications providers are hit by China-backed hackers as part of a massive campaign to obtain the wiretap systems that are used by law enforcement. November 7 Los Angeles Housing Authority Hack: The Housing Authority of the City of Los Angeles (HACLA) confirms that it has suffered its second breach in two years. Reportedly, the hackers claimed 891GB of data. November 6 Retina Group of Florida Data Breach: The eye care provider has reported it suffered a breach, with the data almost 153,000 patients potentially compromised. This is after suspicious activity indicative of an intrusion was detected on its computer network. November 5 Planned Parenthood of Montana Cyberattack: The Montana chapter of Planned Parenthood suffers a cyberbreach in which 93 gigabytes of data is exposed. Over 18,000 individuals could be affected. November 4 Thompson Coburn Hack: Law firm Thompson Coburn, and its client Presbyterian Healthcare Services, reports data breach that could impact over 300,000 people. The company is quickly faced with a lawsuit. November 1 Kaiser Permanente Email Data Breach: Healthcare provider Kaiser Permanente informs its members that its email servers were illegally accessed in September 2024. It is thought that over 40,000 people could be affected. October 2024 October 28 Mystic Valley Elder Services Data Breach: Non-profit care provider announces that the data breach it suffered earlier in the year has resulted in information belonging to nearly 90,000 individuals being compromised. October 18 RRCA Accounts Management, Inc. Cyberattack: In June this year, cybercriminals gained illegal access to the full-service collection agency’s customer data. The attack was quickly shut down, but not before personal information belonging to 115,837 people was accessed. October 18 Summit Pathology and Summit Pathology Laboratories, Inc Leak: Summit notifies patients that a malicious actor has obtained personal and health information belonging to 1,813,538 patients. As of November 12, the case is being investigated. October 14 OnePoint Patient Care Data Breach: The Arizona-based hospice pharmacy discloses a data breach that affects as many as 800,000 individuals. The Inc Ramson ransomware group claims responsibility in mid-September, before a Department of Health and Human Services investigation is launched. October 10 Game Freak Employee Data Leak: The firm behind the Pokemon franchise confirms that illicit actors gained access to data belonging to 2,606 employees and partners. Among the stolen material were alleged codenames for the Nintendo Switch 2, source code for existing games, and more. October 6 Cisco Data Breach: Reports emerge that a hacker known as “IntelBroker” and two others breached Cisco’s IT network, giving them access to a large amount of Cisco data. According to the perpetrators, stolen data includes “Github projects, Gitlab Projects, SonarQube projects, Source code” and much more. September 2024 September 12 Fortinent Customer Data Breach: Security vendor Fortinet confirmed last week that data belonging to a “small number” of its more than 775,000 customers had been compromised. Having obtained information from an Azure SharePoint site, the hacker allegedly leaked it after Fortinet refused to entertain ransom demands. September 11 Access Sports Medicine & Orthopaedics Data Breach: Healthcare services provider Access Sports reveals that confidential information belonging to 88,000 patients has been stolen, including names, Social Security numbers, dates of birth, and financial, medical, and health insurance information. Suspicious activity was detected on May 10, but not before the information in question was compromised. September 6 Slim CD Credit Card Information Leak: Credit card information belonging to 1.7 million people is reported stolen by payment services provider Slim CD. Allegedly, an “unauthorized actor” seized the customer information in June of this year, which potentially includes names, addresses, credit card numbers, and card expiration dates. August 2024 August 24 Port of Seattle Ransomware Attack: The Port of Seattle is subject to a ransomware attack perpetrated by a criminal organization known as Rhysida. The Port is refusing to bow to the demands, so stolen data is expected to be shared on the dark web. August 16 National Public Data Breach: As reported elsewhere by Tech.co, personal information belonging to 2.9 billion individuals has been leaked on the dark web in a catastrophic data breach. A new court filing alleges that four months ago, background check company National Public Data (NPD) was breached by hacking group USDoD. Full names, addresses, dates of birth, phone numbers, and Security Social numbers were compromised in the breach, which is likely to have affected most – if not all – US citizens. August 12 Jerico Pictures/National Public Data Alleged Data Breach: A class action lawsuit filed at the beginning of August has alleged that background check company Jerico Pictures (currently operating as National Public Data) suffered a data breach impacting almost 3 billion people. Data exposed includes names, social security numbers, physical addresses, and in some cases, aliases associated with certain individuals. July 2024 July 26 FBCS Data Breach Update: Debt collection firm Financial Business and Consumer Solutions (FBCS) – which first reported in April that more than 1.9 million people in the US had been impacted by a February breach of their systems – has said that the number is actually much higher, and is actually closer to 4.2 million. This is the second time the company have revised the figure, which stood at 3.2 million in May 2024. The data exposed differs from person to person, but it’s thought that full names, Social Security numbers, dates of birth and driver’s license numbers have all been lifted from the organization’s systems. July 15 Disney Data Breach: A hacking group going by the name “NullBulge” has managed to get its hands on reams of internal company Slack messages sent by employees of Disney. The messages – which were lifted from more than 10,000 channels and amount to around 1.2 TB of data – were allegedly obtained through a form of cookie hacking. July 14 AT&T Data Breach Update: It has been revealed that telecommunications behemoth AT&T – which suffered a severe data breach this year impacting nearly all of its customers – paid $370,000 to a hacker to ensure that they deleted the customer information they’d extracted from the company’s system. The hackers were paid in Bitcoin back in May, Wired reports. June 2024 June 24 Excelsior Orthopaedics Data Breach: The Illinois-based orthopaedic care provider exposed a data breach it had experienced, compromising the personal information of nearly 400,000 individuals. An unauthorized third party had accessed their systems, and viewed or copied the data of current and former patients, and employees. June 13 Truist Bank Data Breach: One of the largest banks in America – Truist Bank – reveals that it suffered a data breach back in October 2023 after employee information appeared for sale online. A hacking group known as Sp1d3r has claimed responsibility and is reportedly selling the dataset for around $1 million. Truist – which looks after more than $500 billion in assets and has 65,000 staff members on its payroll –  said they notified “a small number of clients” at the time of the breach. June 11 Tile Data Breach: Life360, the company behind the Tile tracker device, reveals that its databases have been breached, and that the company is being targeted for extortion. In a statement, the company shared that the affected data includes names, addresses, email addresses, phone numbers and Tile device identification numbers. June 1 Ticketmaster Data Breach: Ticketmaster confirms a rumored data breach from earlier in the year that saw records for its customers, including name, address, phone number, email address, order history and partial payment information, being offered for sale by hackers. Over 560 million customers are expected to be impacted. May 2024 May 31 FinWise Bank Data Breach: FinWise Bank has warned customers that it suffered a data breach, as a result of a former employee accessing sensitive files after the end of their employment. The breach impacted the data of 689,000 customers, and the stolen dataset included full names and other personal data elements. It was not revealed how a previous employee was able to access the data. May 13 Helsinki City Council Data Breach: Local government systems in the Finnish capital Helsinki have suffered a data breach after a hack targeted at their education systems. Students and guardians may have had their personal information stolen from the system by a threat actor who managed to find a way in via a remote access server. The hack is known to have occurred at the beginning of the month, but that information was only made public by city officials this week. May 10 JPMorgan Chase Data Breach: The Maine District Attorney’s Office has been notified that almost half a million people banking with JPMorgan Chase could have had their personal information extracted from the company’s systems thanks to a software flaw dating back to 2021. Luckily, at present, there seems to be no evidence of foul play or the data being misused in any manner. It could, however, have been accessed by authorized parties associated or working with the bank at the time. May 9 Dell Data Breach: Dell emails customers to inform that that their data may have been compromised after an attack on its customer portal. According to Dell, while no financial information was accessed, customers home addresses and order information may have been compromised. Data purportedly from the breach is being offered for sale on hacker forums, suggesting details of 49 million customers have been obtained. May 1 Dropbox Data Breach: Dropbox tells users that its Dropbox Sign service has been accessed by a threat actor, who was able to see data including email addresses, phone numbers, hashed passwords and multi factor authenticator details. Dropbox cloud customers are unaffected. April 2024 April 17 US Government Data Breach: A threat actor known to be part of a Serbian hacking group claims to have breached Space-eyes, CSO Online reports. an intelligence corporation that works with the United States Department of Justice, the Department of Homeland Security, and a range of agencies and teams within the Armed Forces. The hacker claims they’ve stolen “highly confidential” documents relating to the services the company has provided to the government. April 14 Giant Tiger Data Breach: A hacker claims to have stolen records of almost three million Giant Tiger customers. Although the attack happened back in March, the Canadian retailer only disclosed the incident this week. According to the hacker claiming to have extracted the data, the files contain email addresses, names, physical addresses and phone numbers. April 12 Roku Data Breach: Streaming provider Roku has revealed that it suffered a data breach back in March. Over half a million (576,000) customers had their data compromised in the attack. “After concluding our investigation of this first incident” Roku explained in a blog post, referencing a previous data breach the company suffered this year. “We notified affected customers in early March and continued to monitor account activity closely to protect our customers and their personal information. Through this monitoring we identified a second incident, which impacted approximately 576,000 additional accounts.” March 2024 March 20 Vans Data Breach: Vans customers have been told they might be at risk of fraud and identity theft following a breach of the company’s systems. “On December 13, we detected unauthorized activities on a part of our IT systems, apparently carried out by external threat actors,” the company said in a breach notification letter sent out to account holders. It claims that no “detailed financial information” or passwords were exposed during the incident. March 18 Fujistu Data Breach: Multinational technology company Fujitsu has confirmed that it fell victim to a cyberattack recently after malware was found on a collection of the company’s work computers. The company – which employs almost 125,000 people globally – did not reveal what kind of information had been exposed by the attack. February 2024 February 13 Bank of America Data Breach: Tens of thousands of Bank of America customers have had their data exposed in a breach relating to a ransomware attack targeted at Infosys Mccamish Systems, one of the bank’s service providers. The attack occurred at the beginning of November 2023. However, the news only hit the headlines after notifications began to be sent around to customers at the start of February. This may have violated state laws determining how long companies have to notify impacted customers, some reports have pointed out. More than 57,000 customers are thought to have been impacted by the breach. Types of information exposed include addresses, names, social security numbers, DOBs, as well as some banking information (account numbers, credit card info). January 2024 January 27 Anthropic Data Leak: Artificial intelligence startup Anthropic – the company behind the ChatGPT rival Claude – has suffered a small data leak. A contractor working with the company sent an email containing “non-sensitive customer information” to a third party who should not have had access to it. Customer names and some information about their current Anthropic balances were the only types of information leaked in the incident, and customers impacted by the mistake have been notified. January 23 Trello Data Breach: 15 million users of project management software platform Trello have their data leaked on the dark web, multiple sources report. “In January 2024, data was scraped from Trello and posted for sale on a popular hacking forum,” a cautionary email from Have I Been Pwned warning users about the breach states. “Containing over 15 million email addresses, names, and usernames, the data was obtained by enumerating a publicly accessible resource using email addresses from previous breach corpuses” the email continues. “Trello advised that no unauthorized access had occurred.” January 2 Victoria Court System Data Breach: The Guardian reports that the court system in Victoria, Australia has been hacked – and the unauthorized parties gained access the recordings of various court hearings. However, “no other court systems or records, including employee or financial data, were accessed,” chief executive Louise Anderson said in a statement. December 2023 December 11 Norton Healthcare Data Breach: Norton Healthcare has suffered a data breach impacting an estimated 2.5 million people. The firm, based in Kentucky, says that threat actors gained unauthorized access to personal information about millions of patients, as well as a considerable number of employees. The Healthcare provider is one of the biggest in the state, with more than 40 clinics dotted in and around Kentucky’s state capital, Louiseville, TechCrunch reports. Although the data breach happened between May 7 and May 9, it only came to light this month when it was filed with Maine’s attorney general. An internal investigation by Norton suggests the threat actors had access to a broad selection of sensitive information. November 2023 November 24 Vanderbilt University Medical Center Data Breach: A Tennessee-based medical institution has confirmed it fell victim to a ransomware attack orchestrated by the Meow ransomware gang. The Medical Center – which has over 40,000 employees – was one of several organizations added to the group leak database in November 2023. “Vanderbilt University Medical Center (VUMC) identified and contained a cybersecurity incident in which a database was compromised and has launched an investigation into the incident,” the center revealed in a statement published by The Record. “Preliminary results from the investigation indicate that the compromised database did not contain personal or protected information about patients or employees.” November 15 Toronto Public Library Data Breach: The Toronto Public Library has said that sensitive, personal information relating to their employees, as well as library customers and volunteers, was stolen from their systems during a highly sophisticated ransomware attack. Some of the information had been stored in the system since 1998. According to Bleeping Computer, the Black Basta ransomware gang are behind the attack, a group who’s activity were first observed in 2022. November 5 Infosys Data Breach: Indian IT services company Infosys says they’ve been struck with a “security event” which made several of the firm’s applications unavailable in its US unit, called Infosys McCamish Systems. The company is still investigating the impact the attack has had on its systems. November 2 Boeing Data Breach: Aircraft manufacturer Boeing says that a “cyber incident” impacted several different elements of its business, with Reuters reporting that the company is already working with law enforcement to investigate the attack. The company has confirmed that the incident has no bearing on flight safety. The LockBit ransomware gang initially claimed responsibility for the attack and posted a threat directed at Boeing on their website – which has since been taken down. There is no clear evidence available at this point that suggests Boeing has paid the organization a ransom. October 2023 October 30 Indian Council of Medical Research Data Breach: Around 815 million Indian citizens may have had their Covid test and other health data exposed to a huge data breach. A US security firm first alerted the Indian authorities in mid-October after a threat actor going by the name of “pwn0001” claimed to have the names, addresses, and phone numbers of hundreds of millions of Indians for sale. India’s opposition parties are asking the government to urgently launch a probe into the breach and create a working data security plan for government agencies and departments. October 19 Okta Data Breach: Identity services and authentication management provider Okta has revealed that its support case management system was accessed by a threat actor using stolen credentials. “The unauthorized access to Okta’s customer support system leveraged a service account stored in the system itself. This service account was granted permissions to view and update customer support cases” Okta’s chief security office said in a recent statement. “During our investigation into suspicious use of this account, Okta Security identified that an employee had signed in to their personal Google profile on the Chrome browser of their Okta-managed laptop.” October 11 Air Europa Data Breach: Spanish airline carrier Air Europa has told their customers to cancel all of their credit cards after hackers managed to access their financial information during a breach. Card numbers, expiration dates, and 3-digit CVV numbers found on the back of credit and debit cards were all extracted from the company’s systems. Air Europa says the relevant authorities, (including banks) have been notified and their systems are fully operational once more. October 6 23andMe Data Breach: Biotech company 23andMe has suffered a data breach – customer accounts were broken into with a credential-stuffing attack. Genetic data belonging to people who have used the service has been stolen, which may include first names and last names, email addresses, birth dates, and information 23andMe stores relating to users’ genetic ancestry and history. Reports suggest that the hackers were targeting/looking for data pertaining to individuals of Ashkenazi Jewish and Chinese descent. September 2023 Septem
    💬 Team Notes
    Article Info
    Source
    tech.co
    Category
    🛡 Active Threats
    Published
    Archived
    Mar 17, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗