Monthly breach report · July 2026

2026 Data Breaches: Cybersecurity Incidents Explained

Most of July's largest data breaches did not begin with a broken perimeter. In four of the five incidents below, attackers used access that already worked.

Bob Cristello
Bob Cristello August 4, 2026  ·  Updated monthly
Five incidents · July 2026 How they got in
4 of 5
used access that already worked
3 of 5
exposed identifiers that cannot be reissued
6,998,886 individuals — the largest known exposure of U.S. driver's license numbers in 2026
$4.99M
Record global average cost of a breach — IBM, July 29
$11.5M
U.S. average in the same report
4th year
Phishing led all initial attack vectors, consecutively
11 days
From notification to proposed class action, in two of five incidents

July 2026: Key Takeaways

Most of July's largest data breaches did not begin with a broken perimeter. In four of the five incidents below, attackers used access that already worked: a phished employee, a vishing call, a vendor's ticketing platform, and an unnamed vendor with network access. The second pattern is location. Support tickets, systems inherited in an acquisition, and environments accessible through a vendor are not places anyone designs to store Social Security numbers. In July, they all did.

IBM's 2026 Cost of a Data Breach Report, released July 29, put the global average at a record $4.99 million and the U.S. average at $11.5 million. Phishing led all initial attack vectors for the fourth consecutive year. Two of July's five incidents drew proposed class actions within 11 days of notification, and three exposed identifiers that cannot be reissued, creating liability with no expiration date.

What happened in July:

  • 01 AssuranceAmerica, an auto insurance managing general agency, confirmed the largest known exposure of U.S. driver's license numbers this year, affecting nearly 7 million people, after malicious activity targeting one employee.
  • 02 Ernst & Young disclosed that an unauthorized party spent two weeks inside a third-party IT service management platform, downloading tax documents belonging to customers of financial institutions that use the firm.
  • 03 Craneware, whose software supports more than 2,000 U.S. hospitals and health systems and nearly 10,000 clinics and retail pharmacies, told the London Stock Exchange that attackers exfiltrated file names, a percentage of employee data, and a subset of customer and partner records.
  • 04 Abbott confirmed unauthorized access to legacy Exact Sciences systems in its Cancer Diagnostics business. The compromise came roughly twelve weeks after the company closed the acquisition that brought those systems inside.
  • 05 NYC Health + Hospitals returned to the news when an extortion group claimed an 11-terabyte archive, months after the system confirmed a breach that exposed fingerprints and palm prints.

What security teams should take from this month:

Valid credentials do not trigger alarms. A phished login, a vishing call that yields an SSO session, or a compromised vendor account looks like normal work to every control built to detect intrusion. When the front door opens legitimately, the only remaining variable is what state the data was in when the attacker reached it.

Sensitive data does not stay where you filed it. July's exposures sat in support tickets, acquired legacy environments, and vendor-reachable systems, none of them designed to hold regulated data. Automated discovery finds it wherever it drifted. Field-level encryption and tokenization decide whether reaching it means reading it.

One vendor's incident becomes many disclosures. Craneware, the platform behind EY's support tickets, and the unnamed vendor at NYC Health + Hospitals each held or reached regulated data belonging to other organizations. Contractual assurance does not reduce that exposure. What you send, and in what form, does.

2026 editions January February March April May June July 2026

Data Breaches from July 2026

July's breaches share an uncomfortable trait: the victims' defenses mostly worked as designed. AssuranceAmerica detected its intrusion in a day. Craneware contained its incident, and external specialists confirmed no residual indicators of compromise. Abbott reported no operational impact and noted that the compromised legacy systems sat apart from their own. Yet none of it changed the outcome. In each case, the attacker had already authenticated, and the data was already readable. Two entry points recurred all month: a person and a vendor. Knowing where regulated data lives, retaining less of it, and protecting it at the data layer remain the controls that change what a breach is worth.

Initial access

How they got in

Four of the five July incidents started with credentials or connections that already had permission. Only one entry path remains undisclosed.

Phished employee
AssuranceAmerica

Malicious activity targeting a single employee, which yielded credentials used to access and copy files.

Vishing to SSO
Abbott · unconfirmed

A vishing campaign against several employees, compromising a corporate Microsoft Entra single sign-on account.

Vendor ticketing platform
Ernst & Young

Unauthorized access to a third-party IT service management platform used for internal support workflows.

Vendor network access
NYC Health + Hospitals

The actor may have gained access to its systems due to a security breach at a third-party vendor.

Not disclosed
Craneware

Craneware has not disclosed the vector, the threat actor, or the duration of access.

Sequence

Intrusion, detection, disclosure

Every July headline traces back to access gained weeks or months earlier. The gap between the two is where the data sat readable.

Nov 2025 – Feb 2026 NYC Health + Hospitals — an unauthorized actor accesses the network following a compromise at a third-party vendor.
Feb 2, 2026 NYC Health + Hospitals detects the activity.
Mar 16–17, 2026 AssuranceAmerica — malicious activity targets one employee; suspicious activity detected the next day.
Mar 23, 2026 Abbott completes its $21 billion acquisition of Exact Sciences.
Mar 28 – Apr 12 Ernst & Young — an unauthorized third party accesses the IT service management platform and downloads client documents.
Apr 23, 2026 Ernst & Young detects unusual activity on the platform.
Mid-June 2026 Abbott — attackers are inside the legacy Exact Sciences environment, roughly twelve weeks after close.
Jun 15, 2026 AssuranceAmerica concludes its file review; notifications roll out through June and July.
Jul 4, 2026 Abbott — ShadowByt3$ claims access to the LabCentral customer portal using compromised customer credentials.
Jul 13, 2026 Ernst & Young sends notification letters.
Jul 16, 2026 Abbott confirms unauthorized access in its Cancer Diagnostics business.
Jul 20, 2026 Craneware discloses the incident to the London Stock Exchange. A proposed class action is filed against Ernst & Young.
Jul 24, 2026 A proposed federal class action follows against Abbott.
Jul 27, 2026 ShinyHunters claims responsibility for the Ernst & Young incident. LeakNet publishes a preview of a claimed 11-terabyte NYC Health + Hospitals archive.
Jul 29, 2026 IBM releases its 2026 Cost of a Data Breach Report: $4.99M global average, $11.5M in the U.S.

What was exposed

Reissuable, or permanent

A payment card can be replaced. A palm print cannot. Three of July's five incidents exposed identifiers with no expiration date.

Identifier Recoverable? Assurance­America Ernst &
Young
Craneware Abbott NYC Health
+ Hospitals
Social Security number Never
Driver's license number Never
Tax ID / taxpayer identification Never
Biometrics — fingerprints, palm prints Never
Date of birth Never
Medical records, diagnoses, test results Never
Health insurance and payor IDs Rarely
Name, address, contact information Rarely
Insurance policy, claims, vehicle data Rarely
Financial account and payment card Reissuable
Online account credentials Reissuable
Employee, customer and partner records Varies
Confirmed by the organization Claimed by a threat actor, unverified Not reported

AssuranceAmerica

Insurance

AssuranceAmerica, an Atlanta-based managing general agency, detected suspicious activity on March 17, 2026, and traced it to malicious activity the previous day targeting one of its employees. An unauthorized third party then reached portions of the IT environment and copied data files. The file review concluded on June 15, and notifications rolled out through June and July. The company is also offering 12 months of credit monitoring and identity protection through IDX. The result is the largest known exposure of American driver's license numbers in 2026, and it turned on one compromised person rather than any flaw in the network.

Scale of breach
6,998,886

individuals, per the company's filings with the Maine and Indiana attorneys general.

Data exposed

Each affected file contained a name plus one or more of the following:

  • Contact information
  • Automobile insurance policy or insurance account information
  • Driver or vehicle information
  • Claims-related information
  • Driver's license number
  • Tax ID information
  • Social Security number
Breach cause

Malicious activity targeting a single employee, which yielded credentials used to access and copy files. No threat group has claimed the incident, and no public source reports a ransom demand.

Source: AssuranceAmerica notice of data breach filed with the California Attorney General, oag.ca.gov. The affected count comes from the company's filings with the attorneys general of Maine and Indiana, first reported by TechCrunch.

Key Lessons

Neither a driver's license number nor a Tax ID can be reset. That is what separates this breach from a payment card exposure, where reissuing the card ends the problem. Insurers collect government identity documents because underwriting requires them, so minimization is the first question: how long does a closed claims file need a license number in readable form? Everything retained past that point should be tokenized. One employee will eventually click, and tokenization decides what that click costs.

Ernst & Young

Professional services

Ernst & Young uses a third-party IT service management platform so its technology staff can support teams performing tax work for clients. Those support tickets carry attachments, and those attachments contain tax filings. EY detected unusual activity on the platform on April 23, 2026, and determined that an unauthorized third party had accessed it between March 28 and April 12 and downloaded client documents. Notification letters went out on July 13, and a proposed class action followed on July 20. Most affected individuals are customers of financial institutions that retain EY for investment-related tax work, so they never had a direct relationship with the firm.

Scale of breach
Not disclosed

EY has not disclosed a total. State filings list 873 Texas residents, 480 Massachusetts residents, and 13 Vermont residents. The firm is offering 24 months of credit monitoring, identity monitoring, and identity restoration.

Data exposed

Documents attached to support tickets, containing personal and financial information included in or used to prepare tax filings:

  • Names and addresses
  • Dates of birth
  • Social Security numbers
  • Financial account and payment card information
Breach cause

Unauthorized access to a third-party IT service management platform used for internal support workflows. EY has not named the vendor or the initial access method. ShinyHunters claimed responsibility on July 27 and set a July 31 deadline for EY to make contact, telling reporters that credentials obtained in a supply-chain compromise also gave it access to EY's Jira, GitHub, and Azure environments. EY has not confirmed the group's involvement or the broader access claim. The deadline passed without publication, and as of August 4, the group has stated that further releases are being prepared.

Source: Ernst & Young LLP breach report filed with the California Attorney General, oag.ca.gov/ecrime/databreach/reports/sb24-626542

Key Lessons

A help desk platform is a data store that nobody inventories as one. Its purpose is workflow, so it gets classified as an operational tool while quietly accumulating whatever employees attach to tickets. An inventory that says tax filings live in the tax systems is not wrong, only incomplete, and that gap is where this data sat. The exposure compounds through the supply chain: financial institutions gave the data to EY, EY moved it into a vendor platform, and the people whose Social Security numbers were taken had no relationship with either. Discovery must scan where data drifted, not where policy says it lives.

Craneware

Healthcare software

Craneware, an Edinburgh-based healthcare financial software firm, disclosed a cybersecurity incident to the London Stock Exchange on July 20, 2026, reporting unauthorized access to a subset of its data environment. The company contained the incident, appointed external forensic specialists, and notified the UK Information Commissioner's Office and the FBI. Customer services and operations continued without disruption. What makes the incident significant is not its severity at Craneware but its reach. The Trisus platform handles revenue integrity, charge capture, claims analytics, and pharmacy program management for a large share of the American hospital sector.

Scale of breach
Not disclosed

The company reports partnering with more than 2,000 hospitals and health systems and supporting nearly 10,000 clinics and retail pharmacies.

Data exposed

The company reports that investigations established the following:

  • A significant volume of file names viewed and exfiltrated
  • A percentage of Craneware employee data
  • A subset of customer and partner records
  • A large element assessed as non-sensitive or already-public regulatory data
Breach cause

Unauthorized access to a subset of the company's data environment. Craneware has not disclosed the vector, the threat actor, or the duration of access, and external specialists confirmed no residual indicators of compromise.

Source: The Craneware Group plc, Notice of Cyber Security Incident, London Stock Exchange Regulatory News Service, July 20, 2026, investegate.co.uk

Key Lessons

This entry belongs in the report for the same reason the NAIC breach did last month: concentration, not severity. A hospital can harden its own endpoints, train its own staff, and patch its own systems. But none of that addresses the risk with the vendor that processes its billing. Where healthcare organizations retain control is in what they hand over and in what form. Sending tokenized identifiers to a revenue analytics platform preserves the analytics while removing identity data from the vendor's blast radius.

Abbott

Medical devices & diagnostics

Abbott completed its $21 billion acquisition of Exact Sciences on March 23, 2026. By mid-June, attackers were inside the legacy Exact Sciences environment. Abbott confirmed the incident on July 16, describing unauthorized access to a limited number of internal systems in its Cancer Diagnostics business only, and stated that the legacy Exact Sciences systems are separate from Abbott's own. Roughly twelve weeks separated the closing of the deal from the compromise of the systems it brought in. That is not enough time to inventory, segment, and secure an acquired data estate of that size. A proposed federal class action followed on July 24. An extortion group called ShinyHunters has claimed responsibility for the Cancer Diagnostics intrusion, and its claims about the volume and content of the data taken remain unverified.

A second and unrelated claim landed in the same window. A threat actor calling itself ShadowByt3$ says it reached Abbott's Core Laboratory business through the LabCentral customer portal on July 4 using compromised customer credentials, taking product and regulatory documentation rather than customer data. Abbott says LabCentral is externally hosted and that there has been no known exposure of sensitive customer or business information.

Scale of breach
Not disclosed

Abbott has confirmed unauthorized access to a limited number of Cancer Diagnostics systems but has not disclosed the number. ShinyHunters claims 30 million customer records, including approximately 1 million Social Security numbers, more than 22 million doctor and patient notes, and more than 20 million medical orders. Nothing has been published, and no independent party has verified any part of the claim.

Data exposed

Abbott has not specified categories and continues to investigate what information the attackers accessed. The claimed data, unverified, includes:

  • Names and contact information
  • Dates of birth
  • Social Security numbers
Breach cause

ShinyHunters says it gained access through a vishing campaign against several employees in mid-June, compromising a corporate Microsoft Entra single sign-on account and taking data from connected applications. Abbott has not confirmed the vector or named the group. The group's original publication deadline of July 18 was extended to July 21 after contact was made, and as of August 4 no data has been published.

Source: Abbott statement on cyber incident in Cancer Diagnostics business, abbott.com

Key Lessons

Due diligence prices an acquisition's revenue with far more rigor than it maps the acquisition's data. A company closing a deal inherits every archive, every legacy database, and every retention practice the target ever had. It inherits them on day one, while integration runs for quarters. The separate legacy environment Abbott describes is the environment an attacker reached. Automated discovery across an acquired estate belongs in the first 30 days after close, not in the integration backlog, because regulated data is a liability from the moment the papers are signed.

NYC Health + Hospitals

Public health system

NYC Health + Hospitals, the largest public health system in the United States, confirmed in March that an unauthorized actor had accessed its network from late November 2025 through February 2026 following a compromise at a third-party vendor. It reported at least 1.8 million affected individuals to the Department of Health and Human Services, and it is offering 24 months of credit monitoring through Kroll to anyone who has been a patient or workforce member since 2020. The incident returned to the news on July 27, when an extortion operation calling itself LeakNet published a preview of what it claims is an 11-terabyte archive linked to more than 12 million people. No independent review has confirmed that figure, and the confirmed count remains 1.8 million.

Scale of breach
1,800,000+

At least 1.8 million individuals, according to the system's report to HHS. LeakNet's claim of more than 12 million remains unverified.

Data exposed

Categories vary by individual and include:

  • Medical information, including record numbers, diagnoses, medications, test results, images, and treatment plans
  • Health insurance information, including Medicaid, Medicare, and government payor ID numbers
  • Billing, claims, and payment information
  • Biometric information, specifically fingerprints and palm prints
  • Social Security numbers, driver's license numbers, and taxpayer identification numbers
  • Precise geolocation data
  • Credit and debit card numbers, financial account information, and online account credentials
Breach cause

The health system says the actor may have gained access to its systems due to a security breach at a third-party vendor. It detected the activity on February 2, 2026.

Source: NYC Health + Hospitals, Notice of Data Breach, nychealthandhospitals.org. The affected count comes from the system's report to the HHS Office for Civil Rights.

Key Lessons

Every downstream control arrives too late for a fingerprint. Cards get reissued, and passwords rotated, but a palm print is permanent, and the people in this breach carry that exposure for life. So, the question is not how to protect it. It is why a hospital system held it in a form that could be copied, which makes this minimization before encryption. Biometric identifiers belong in storage as irreversible templates, retained only as long as the access-control purpose lasts. A breach you have closed is not finished while the stolen data remains readable.

A breach you have closed is not finished while the stolen data remains readable.

Learn how PK Protect finds and protects regulated data.

Explore PK Protect

Data Breaches from June 2026

June was dominated by data-theft extortion rather than ransomware. Researchers now describe ShinyHunters, the month’s principal actor, as a durable cybercrime brand rather than a single crew; it ran a pay-or-leak campaign across healthcare, insurance regulation, and entertainment using an Oracle PeopleSoft zero-day and social engineering, while a parallel pharmaceutical breach turned on a single developer credential. In nearly every case, the perimeter did not fail: attackers logged in with valid or inherited access, then took data usable the moment it left the perimeter. Knowing where sensitive data resides, minimizing what is retained, and protecting it at the data layer remain the best assurance against breaches.

One Medical (Amazon)

Healthcare

Amazon-owned primary care provider One Medical confirmed a breach of a third-party file storage system holding archived records for its senior care division. It discovered the access on June 13, 2026, and determined that an unauthorized party reached the platform between June 8 and 11. One Medical said the incident was limited to legacy data for One Medical Seniors patients, formerly Iora Health, acquired in 2021, and did not touch its other systems or main electronic medical record. Days later, ShinyHunters claimed 8.8 terabytes and set a June 22 deadline before publishing.

Scale of breach
8.8 TB

ShinyHunters claimed 8.8 terabytes; One Medical described the affected group as a subset of legacy One Medical Seniors patients within a network serving more than 830,000 patients overall.

Data exposed

Demographic information and clinical records of legacy Iora Health and One Medical Seniors patients. No other One Medical or Amazon systems were involved.

Breach cause

Unauthorized access to a third-party archival file storage platform; ShinyHunters claimed responsibility, though One Medical has not named the group.

Source: HIPAA Journal reporting on the One Medical breach notice, hipaajournal.com

Key Lessons

Legacy systems are healthcare security’s most common blind spot, and this is a clean example. The exposed data belonged to a practice acquired five years ago, parked in an archive that likely received less protection than the live record, yet it still contained clinical records on elderly patients, data with permanent identifiers, and a real risk of Medicare fraud. The fix is twofold: automated discovery that surfaces forgotten and migrated data, and persistent encryption so an archive breach yields unreadable files. Data you have stopped using is still your responsibility.

National Association of Insurance Commissioners (NAIC)

Insurance regulation

The NAIC, which coordinates insurance regulation across all fifty U.S. states, disclosed that an unknown third party had gained unauthorized access to its systems. It identified the access on or about June 11, 2026, traced it to its PeopleSoft environment, and posted notices on June 17 and 18. ShinyHunters claimed responsibility on June 18, listed the NAIC with a June 22 deadline, and published its claimed haul online around June 25. NAIC’s position is that the exposure reaches into the sector’s financial plumbing but is far narrower than the attacker first alleged, and that much of what was taken was already public.

Scale of breach
3.1 TB

ShinyHunters claimed 3.1 terabytes across more than 105,000 files, affecting the NAIC, all fifty state insurance departments, and thousands of licensed insurers.

Data exposed

The attacker’s initial claim, roughly 2.1 million insurer regulatory filing PDFs across systems including INSData, SERFF, and OPTINS, was later walked back by ShinyHunters itself, which revised the count to about 260,000 filing documents and removed the system references, saying its first statement was based on an AI-generated misinterpretation of its own data. NAIC’s outside experts concluded that SERFF, OPTINS, and the other named systems were not actually accessed, and that what was taken was largely already-public statutory financial reports and credit rating agency data, along with outdated logs and configuration files. NAIC states that no personally identifiable information or payment data was involved.

Breach cause

Unauthorized access to the NAIC’s PeopleSoft system; ShinyHunters claimed responsibility. The intrusion fits the group’s broader 2026 Oracle PeopleSoft zero-day campaign.

Source: The Insurer, Threat actor group ShinyHunters claims to have obtained NAIC data, theinsurer.com

Key Lessons

This is a systemic-risk breach, not a consumer-records one: a single aggregator consolidated filings and identifiers from across the entire U.S. insurance industry, so a single intrusion exposed thousands of insurers at once. It is the sector’s version of the vendor problem: sensitive data funneled into shared platforms whose security becomes everyone’s. The lesson holds even after NAIC’s clarification that most of the data was already public, because the risk was never the sensitivity of any one filing; it was the concentration. Encryption and tokenization at rest, plus strict access governance, would have meant that reaching the system did not equal reading its contents.

Madison Square Garden Entertainment

Entertainment

ShinyHunters published roughly 45 gigabytes stolen from Madison Square Garden Entertainment after it missed a June 15 ransom deadline; the group says it broke in on June 5, listed the company on June 12, and released the data on June 16. The striking element is its nature: MSG has used facial recognition across its venues for years, including to bar attorneys from firms litigating against it, and that surveillance apparatus is in the leak. Class action lawsuits followed within a day. It is MSG’s second major breach in under a year.

Scale of breach
26M+

ShinyHunters claimed more than 26 million customer and corporate records in a roughly 45-gigabyte dump.

Data exposed

Customer account and ticketing details, support emails, and internal corporate documents tied to the Knicks and Rangers, alongside facial recognition surveillance records, threat-assessment ratings, and detailed guest profiles with fields such as “claim to fame” and “cost of talent.” Payment card numbers and Social Security numbers were not confirmed in this dump.

Breach cause

Data-theft extortion by ShinyHunters; the company declined to pay, and the data was published. MSG has not detailed the initial intrusion vector.

Source: The Next Web, ShinyHunters published 45GB of Madison Square Garden data, including facial recognition surveillance records, thenextweb.com

Key Lessons

The biometric angle echoes last month’s NYC Health and Hospitals breach for the same reason: a face, like a fingerprint, cannot be reissued. Data collected to control building access is now in criminal hands, and the people in it cannot reset their exposure. Before encryption even applies, there is a data-minimization lesson: biometric and behavioral profiles should not be retained by default, and where kept must be encrypted and access-governed at rest.

DentaQuest

Dental benefits

DentaQuest, one of the largest U.S. dental and vision benefits administrators and a Sun Life Financial subsidiary, was hit by a ShinyHunters pay-or-leak campaign. After no agreement was reached, ShinyHunters published hundreds of gigabytes, which Have I Been Pwned analyzed in early June. DentaQuest acknowledged the incident in a June 1 notice describing unauthorized access to a limited portion of its network. As the largest U.S. Medicaid and CHIP dental benefits administrator, it has exposure to many low-income families and children.

Scale of breach
2.6M

2.6 million unique individuals, per Have I Been Pwned’s analysis of the leaked dataset; the company manages benefits for roughly 32 million Americans.

Data exposed

Names, mailing addresses, gender, dates of birth, phone numbers, email addresses, and health insurance information, much of it in healthcare enrollment files, with some records containing Medicaid IDs.

Breach cause

ShinyHunters data theft and extortion; the company did not reach an agreement, and the data was published.

Source: Security Affairs, DentaQuest Breach: ShinyHunters Publish Data Impacting 2.6 Million People, securityaffairs.com

Key Lessons

Medicaid IDs and enrollment records are exactly the regulated, durable data that should never sit in a form an attacker can read after exfiltration. Structured enrollment files point to large volumes of standardized, highly sensitive records, the precise case where field-level encryption and tokenization pay off. A benefits administrator is also a concentration point, holding data for states, insurers, and millions of members, so its posture becomes theirs. Encrypting the fields that carry Medicaid IDs would have changed what the leak was worth.

Novo Nordisk

Pharmaceutical

The Danish maker of Ozempic and Wegovy disclosed on June 11, 2026, that attackers had reached a limited number of internal IT systems and copied non-public data, including personal data. Two things stand out. First, the entry point: FulcrumSec, the group claiming responsibility, said it gained access months earlier through an exposed high-privilege developer credential, then moved laterally on credentials left in code repositories. They did not break the perimeter; they authenticated. Second, the outcome split by how data was protected: the clinical trial patient data was pseudonymized and could not identify participants without separately protected information, while healthcare professional records were directly identifying.

Scale of breach
1.3 TB

Novo Nordisk did not disclose a total; the claimant group referenced roughly 700,000 files and about 1.3 terabytes, including data on about 11,500 pseudonymized clinical trial participants. A second group separately claimed an intrusion targeting the company’s AI assets.

Data exposed

For trial patients, pseudonymized data: a random patient ID, trial details, sex, year of birth, biomarkers, and health and lifestyle factors. For healthcare professionals, directly identifying data: names, registration numbers, emails, phone and WhatsApp details, and office locations. The attacker also claimed source code, drug research, manufacturing records, and internal AI models.

Breach cause

Unauthorized access via an exposed high-privilege developer credential (a GitHub personal access token), followed by lateral movement using credentials found in repositories. Attributed to the claimant group FulcrumSec; no ransomware was involved.

Source: Dark Reading, Novo Nordisk Breach Exposes Software Development Pipeline Risk, darkreading.com

Key Lessons

This is the month’s most instructive breach because it shows data-centric protection working and failing in the same incident. Because the trial data was pseudonymized, Novo Nordisk could credibly tell patients the records could not be tied back to them, de-identification doing exactly what it is designed to do. Everything not protected that way, the healthcare professional contact details, the source code, the AI models, left fully usable. The entry point cuts the other way: one developer token and credentials left in repositories were enough, which is why secrets management and non-human-identity inventory now matter. Protect and minimize the data, and a breach becomes a disclosure you can manage rather than one that defines you.

A breach you have closed is not finished while the stolen data remains readable.

Learn how PK Protect finds and protects regulated data.

Explore PK Protect

Data Breaches from May 2026

May 2026 made one thing clear: attackers did not break in; they logged in. Almost every major incident this month began with a person rather than a flaw, whether it was a help desk agent who talked out of a credential, an employee who phished into surrendering a single sign-on token, or a vendor whose access was simply inherited. Two patterns defined the month. The first was a sustained ShinyHunters extortion campaign targeting SaaS and CRM platforms, exfiltrating data at scale from Salesforce, Microsoft 365, and similar systems. The second was a wave of third-party vendor compromises in healthcare, in which the entry point lay entirely outside the breached organization. In both cases, the perimeter held, and the data still walked out the door because it was readable the moment an attacker reached it.

NYC Health + Hospitals

Healthcare

The largest public health system in the United States confirmed a months-long intrusion that originated at an unnamed third-party vendor. NYC Health + Hospitals detected suspicious activity on February 2, 2026, and later determined that an unauthorized actor had access to parts of its network from roughly November 25, 2025 through February 11, 2026, copying files during that window. The system serves a safety-net population that is largely on Medicaid, and it offered affected individuals 24 months of credit monitoring retroactive to any interaction since 2020. What sets this breach apart from a typical healthcare incident is the data type: alongside medical and financial records, attackers took biometric fingerprints and palm prints.

Scale of breach
1.8M+

At least 1.8 million people confirmed; reported to the U.S. Department of Health and Human Services as one of the largest healthcare breaches of 2026.

Data exposed

Medical records (diagnoses, medications, test results), health insurance information, Social Security numbers, government-issued identification including driver’s licenses and passports, financial account details, online account credentials, precise geolocation data, and biometric fingerprints and palm prints.

Breach cause

Compromised unnamed third-party vendor; specific access vector not disclosed.

Source: TechCrunch reporting on the NYC Health + Hospitals breach notice, techcrunch.com

Key Lessons

A stolen password can be changed, a Social Security number can be flagged, a credit card can be reissued. A stolen fingerprint cannot. Biometric exposure is permanent, which makes it the clearest possible case for protecting the data at rest rather than relying on the network around it. The breach also illustrates the vendor problem in its starkest form: the organization that hardened its own systems was compromised through one it did not run. Automated data discovery that flags where biometric and regulated data lives, combined with persistent encryption on that data, would have meant the exfiltrated files were unreadable to the attacker regardless of which vendor opened the door.

Instructure (Canvas)

Education tech

Education technology company Instructure was breached twice within roughly two weeks by the extortion group ShinyHunters, in what is now considered the largest education-sector breach on record. The group gained initial access in late April 2026 by exploiting the Free-For-Teacher program, a feature that let educators create Canvas accounts without institutional verification. Instructure disclosed an incident on May 1 and said it had contained the issue by May 6. On May 7, ShinyHunters defaced Canvas login portals at roughly 330 institutions, including Harvard, Princeton, and the University of Pennsylvania, knocking the platform offline during final exam periods. On May 11, one day before the group’s deadline, Instructure paid a ransom and said it received “shred logs” confirming data destruction. Canvas is used by 41 percent of higher education institutions in North America.

Scale of breach
275M

ShinyHunters claimed to have exfiltrated 3.65 terabytes of data and roughly 275 million records across nearly 9,000 institutions; analysis identified approximately 231 million unique email addresses.

Data exposed

Names, email addresses, student ID numbers, and internal private messages. Instructure stated it found no evidence that passwords, dates of birth, government identifiers, or financial information were involved.

Breach cause

ShinyHunters’ extortion attack via a vulnerability in the Free-For-Teacher account program.

Source: Inside Higher Ed, Instructure Pays Ransom to Canvas Hackers, insidehighered.com

Key Lessons

This is the breach that proves paying the ransom is not the same as protecting the data. Instructure paid and received a promise, but 275 million students and staff still had their information copied by a criminal group, and the inclusion of private messages makes this far more dangerous than a name-and-email leak. The “contained by May 6, defaced on May 7” sequence is a reminder that an organization’s belief that an incident is over is not evidence that it is. The durable defense is not negotiation after the fact, it is rendering exfiltrated data useless before it leaves: persistent encryption on student records and message stores, scoped access, and discovery that surfaces unverified account programs before an attacker finds them first.

Charter Communications (Spectrum)

Telecom

One of the largest broadband providers in the United States was compromised on April 1, 2026, when ShinyHunters used a voice phishing call to persuade an employee to share credentials for a Microsoft Entra account. The group used that access to reach Charter’s Salesforce environment and exfiltrate customer data, then listed the company on its leak site with a May 27 deadline. Charter did not pay, and the data was published. The company maintained that only sales tools were affected and that no sensitive personal information or customer proprietary network information was exfiltrated, while independent analysis told a more populated story. This incident is one node in a broader ShinyHunters Salesforce campaign that also touched Carnival, Canvas, CarGurus, Panera Bread, and 7-Eleven.

Scale of breach
4.9M

ShinyHunters claimed more than 42 million records; HaveIBeenPwned confirmed approximately 4.9 million unique email addresses, plus roughly 85,000 records from an internal employee directory.

Data exposed

Names, email addresses, home and company addresses, phone numbers, plan information, and support ticket details; the employee subset included job titles. Charter stated no passwords or payment information were in the dataset.

Breach cause

Voice phishing (vishing) compromise of an employee’s Microsoft Entra account, used to access the Salesforce CRM instance.

Source: SecurityWeek, Charter Communications Data Breach Could Impact Nearly 5 Million, securityweek.com

Key Lessons

A single phone call gave an attacker a path into a CRM holding millions of customer records, which is the entire ShinyHunters playbook in one sentence. The gap between Charter’s “only sales tools” framing and the 4.9 million records confirmed in the wild is instructive: from a customer’s standpoint, the question is not how limited the breach felt internally, but whether the exposed data fuels phishing and fraud, and here it does. CRM platforms concentrate exactly the kind of personal data that should never sit in plaintext. Encrypting and tokenizing sensitive fields inside the CRM, paired with monitoring for anomalous bulk export volumes, would have blunted both the theft and its aftermath.

Carnival Corporation

Travel

The world’s largest cruise operator disclosed that a social engineering attack against a single employee account opened a path into its IT systems. Carnival identified the unauthorized activity on April 14, 2026, blocked it, and determined on April 22 that an attacker had copied personal information. The data the company itself confirmed is a near-complete identity toolkit, and an independent analysis of the leaked dataset identified millions of loyalty program accounts tied to Carnival’s Holland America brand. The company is offering affected individuals 24 months of TransUnion credit monitoring. For a company with a long and documented history of breaches, this incident adds another entry to an already lengthy record.

Scale of breach
6M

Approximately 6 million individuals notified by Carnival; ShinyHunters claimed 8.7 million records, and HaveIBeenPwned analysis indicated roughly 7.5 million Mariner Society loyalty accounts were affected.

Data exposed

Names, addresses, dates of birth, email addresses, phone numbers, and government-issued identification numbers, including driver’s license and passport numbers. The leaked loyalty dataset also included gender, geographic location, and loyalty program details.

Breach cause

Social engineering of a single employee account, used to access and exfiltrate files from company systems.

Source: SecurityWeek, Carnival Data Breach Exposed 6 Million People, securityweek.com

Key Lessons

One deceived employee should not be able to expose 6 million people’s passport and driver’s license numbers, and the fact that it can is an architecture problem, not just a training problem. Passport and license numbers are exactly the kind of durable identifiers that enable identity theft for years, and unlike a password, they are not something a customer can rotate. Carnival’s repeated appearances in breach databases suggest the underlying issue is structural rather than a one-time failure. Persistent encryption of customer identity data, least-privilege access that limits what any single account can access, and bulk-export controls would have turned a single phished login into a contained incident instead of a 6-million-person disclosure.

The Oncology Institute

Healthcare

A publicly traded cancer care provider operating more than 100 clinics across five states confirmed that patient data was compromised through a third-party software vendor. The disclosure was a follow-up to a voluntary filing the company made in November 2025, when the vendor’s investigation was still ongoing, and patient impact was unconfirmed. On May 20, 2026, Kroll, acting as the third-party administrator for the vendor, notified The Oncology Institute that an unauthorized actor had accessed systems containing patient data. The company said the incident appears to have affected multiple other healthcare providers as well, and that its continuity plan allowed care and operations to continue. The vendor has not been named publicly, though reporting has pointed to billing-software providers in the healthcare supply chain that suffered breaches affecting millions.

Scale of breach
Not disclosed

Number of affected patients not yet disclosed; the company stated that the incident affected other healthcare service providers and that it is reserving rights against third parties.

Data exposed

Patient data confirmed affected; specific data types not yet disclosed. The company is offering credit monitoring and identity protection to impacted patients.

Breach cause

Unauthorized third-party access to a software service vendor’s systems; no threat actor has claimed responsibility.

Source: SecurityWeek reporting on the company’s SEC Form 8-K filing, securityweek.com

Key Lessons

This breach is the quiet version of the month’s loudest theme: the breached organization did nothing visibly wrong, and its patients were still exposed because the failure occurred within a vendor’s systems. Healthcare runs on an interconnected web of billing, eligibility, and software providers, each of which becomes part of the provider’s actual attack surface the moment it is granted access to patient data. Medical records carry permanent identifiers that cannot be reissued, and a provider cannot encrypt data it has handed to a vendor in plaintext. The lesson is to push protection upstream: require that sensitive data shared with vendors is encrypted and policy-governed before it leaves your environment, and maintain a current map, through automated discovery, of which third parties hold which regulated data.

A breach you have closed is not finished while the stolen data remains readable.

Learn how PK Protect finds and protects regulated data.

Explore PK Protect

Data Breaches from April 2026

April 2026 was dominated by supply-chain compromises and OAuth abuse. Two major U.S. banks were hit through a shared third-party vendor, a French government identity agency had records on millions of citizens offered for sale, a medical device giant faced a ShinyHunters extortion claim, Adobe was reportedly breached through an Indian BPO contractor, and an AI productivity tool became the entry point into a major cloud platform. Attackers are no longer breaking down the front door; they are walking in through trusted third parties. Knowing where sensitive data resides and protecting it accordingly remains the best assurance for breach resiliency.

Citizens Financial Group & Frost Bank

Banking

The Everest ransomware group posted both U.S. banks on its dark web leak site on April 20. The same-day leak involving shared document-production data points to a single-vendor compromise. Both banks confirmed the breach originated at an unnamed third-party vendor, not their own networks. Class action lawsuits were filed within days.

Scale of breach
3.4M

3.4 million records claimed from Citizens; over 250,000 SSNs and TINs from Frost.

Data exposed

Citizens — names, addresses, account numbers. Frost — names, addresses, Social Security numbers, taxpayer identification numbers, mortgage interest records, W-2s, 1099s, and HSA contributions.

Breach cause

Everest ransomware via a shared third-party vendor.

Source: Massachusetts Attorney General Data Breach Notification, mass.gov

Key Lessons

Two well-resourced banks blaming the same unnamed vendor on the same day means the vendor’s security posture became their security posture. The contrast between the datasets is instructive; Citizens’ exposure is largely to scams and profiling, while Frost’s is a near-complete identity-theft toolkit. Persistent encryption that travels with the data would have neutralized Frost’s exposure entirely; the hackers may have taken the files, but encrypted SSNs and tax records are useless without keys.

France Titres / ANTS (French Government)

Government

France’s official issuer of national ID cards, passports, and driver’s licenses detected a breach on April 15. The next day, a threat actor known as “breach3d” listed the data for sale on a hacker forum. ANTS confirmed 11.7 million accounts were impacted and took the portal offline on April 24.

Scale of breach
11.7M

11.7 million accounts confirmed; threat actor claims up to 19 million records.

Data exposed

Login IDs, full names, email addresses, dates of birth, account identifiers, and, in some cases, postal addresses, place of birth, and phone numbers.

Breach cause

Undisclosed; investigation ongoing under CNIL, Paris Prosecutor, and ANSSI.

Source: ANTS Official Security Notice (ants.gouv.fr), ants.gouv.fr

Key Lessons

Government identity database breaches are categorically more dangerous than commercial breaches because the data carries implicit authority. A scammer who knows a victim’s name, birthdate, and address sourced from the agency that issued their passport can run impersonations that random scraped data cannot match. Critical identity systems require data minimization, encryption that stays with the data, and continuous monitoring for anomalies in bulk exports.

Medtronic

Medical devices

Medical technology giant Medtronic confirmed on April 24, alongside an SEC Form 8-K filing, that an unauthorized party had accessed corporate IT systems. ShinyHunters claimed up to nine million records. Medtronic emphasized that hospital networks running their devices were not exposed.

Scale of breach
9M

Up to 9 million records claimed by ShinyHunters; investigation ongoing.

Data exposed

Personal information and internal corporate data; specific types still being assessed.

Breach cause

ShinyHunters extortion attack; initial access vector not disclosed.

Source: SEC EDGAR — Medtronic Form 8-K Filing, sec.gov

Key Lessons

Medical device manufacturers carry both corporate and clinical risk surfaces, and the corporate-only framing only holds if segmentation is real. Medical records contain permanent identifiers; unlike credit cards, you cannot cancel your medical history. Persistent encryption on corporate-held customer and partner data limits what attackers can monetize, and automated discovery ensures regulated data does not drift into unprotected systems.

Adobe

Software

A threat actor known as “Mr. Raccoon” allegedly breached Adobe through an Indian Business Process Outsourcing (BPO) firm contracted for support operations. The attacker delivered a Remote Access Tool via phishing, pivoted to a manager’s account, and reached the helpdesk environment, where a single agent could export all tickets in one request. Adobe has not publicly confirmed or denied the breach.

Scale of breach
13M

13 million customer support tickets, 15,000 employee records, and all HackerOne bug bounty submissions claimed.

Data exposed

Customer names, email addresses, account IDs, internal technical notes, and unpublished vulnerability reports.

Breach cause

Supply-chain compromise via third-party BPO; phishing followed by privilege escalation.

Source: International Cyber Security News, cybersecuritynews.com

Key Lessons

A single support agent being able to extract 13 million records in one query is an architectural gap, not a policy gap. The HackerOne submissions are the most damaging part; unpublished vulnerabilities could be weaponized before patches ship. Bulk export controls and DLP triggers on anomalous query volumes would have caught this. Persistent encryption on customer support data would have rendered the stolen tickets unusable after exfiltration.

Vercel (via Context.ai)

Cloud platform

Vercel disclosed on April 19 that a Vercel employee’s Google Workspace account was compromised via Context.ai, a third-party AI tool granted broad OAuth permissions. The Context.ai compromise traced back to a Lumma Stealer infection in February, a two-month dwell time. The breach was discovered when the attacker listed the stolen data for $2 million on BreachForums.

Scale of breach
Limited

Limited customer subset; threat actor claims 580 employee records plus access keys, source code, and tokens.

Data exposed

Employee records, access keys, API keys, GitHub and NPM tokens, and non-sensitive environment variables.

Breach cause

OAuth supply-chain compromise via Lumma Stealer infection at Context.ai.

Source: Vercel Official Security Bulletin, vercel.com

Key Lessons

One employee granting broad Workspace permissions to a third-party AI tool gave attackers an inherited trust path into Vercel. The breach was not discovered by Vercel’s security team; it was discovered when the attacker chose to monetize publicly. The OAuth graph is now the new perimeter, and most companies have no inventory of which third-party apps their employees have authorized. Tightening OAuth scope reviews and inventorying authorized third-party apps would have closed the lateral path before it was used.

A breach you have closed is not finished while the stolen data remains readable.

Learn how PK Protect finds and protects regulated data.

Explore PK Protect

Data Breaches from March 2026

March was a volatile month for data breaches and ransomware. The most prominent was the attack on Stryker. While that incident didn’t expose data, it still had a significant effect on the company. As always, knowing where sensitive data is and remediating it accordingly provides you with the best assurance for breach resiliency.

Stryker

Medical devices

Stryker, a medical device company, was recently the target of a hack deployed by an Iran-linked group, Handala. It caused system outages throughout the organization. It was not a ransomware attack. Rather, this was a data theft and wipe strike. Windows-based devices, including laptops and mobile devices, were wiped. As of March 30, the company had restored most manufacturing sites.

Scale of breach

Company applications and internal systems

Breach cause

Handala gained access to the company’s Active Directory Services, using the Microsoft endpoint management tool, Microsoft Intune.

Key Lessons

This is a unique incident. Hackers didn’t steal data; they wiped in from internal systems, which triggered operational fallout. The attack on endpoint systems wasn’t to exfiltrate or hold for ransom; it was about disruption.

When there’s a compromise to endpoints, cyber criminals can deploy software to wipe, encrypt, or exfiltrate data as well as disable security mechanisms.

While you cannot eliminate this risk, you can do these things:

  • Ensure automated sensitive data discovery, so you always know where data is.
  • Use policy-based protection to determine what to do with the discovered data consistently (e.g., encrypt, mask, redact, etc.).
  • Enable persistent encryption that stays with data regardless of where it goes.

Aura

Digital security

Aura announced a data breach via a targeted phishing attack that led to the exposure of marketing data lists. The company identified the breach within an hour and activated its incident response plan. Aura announced that the hack did not expose any sensitive data.

Scale of breach
900,000

records

Data exposed

Names and email addresses

Breach cause

ShinyHunters claimed responsibility via a phishing attack.

Source: Aura’s statement, aura.com

Key Lessons

Aura did an excellent job of responding quickly. Often, it takes weeks or even months to detect unauthorized access. Even though data stolen wasn’t sensitive, it’s still a reminder that organizations should deploy data-centric encryption, which is “sticky.” It stays with the data no matter where it goes.

Data breach resiliency strategies can reduce the effects of ransomware. Such programs involve enterprise-wide visibility of sensitive data and preemptive protections, such as encryption, masking, and redaction.

Navia

Benefits admin

An exposed API was a weak link for an attacker to gain unauthorized access. The hackers stole personal and health-related data. Their investigation revealed that the threat actor acquired information from December 22, 2025, to January 15, 2026.

Scale of breach
2.7M

people

Data exposed

Social Security numbers, account data, names, dates of birth, phone numbers, email addresses, and health plan information

Breach cause

Exposed API

Source: Navia’s notice, naviabenefits.com

Key Lessons

Perimeter defenses were insufficient to thwart unauthorized actors. They stole PII and PHI; data that should be encrypted at rest and in transit. Persistent encryption driven by enterprise-wide policies could have made a difference. The hackers may have taken the data, but with encryption, it would have been unusable.

Pathstone Family Office

Wealth management

Pathstone Family Office, a wealth management firm, was the victim of a data breach perpetrated by ShinyHunters. The theft included 641,000 records of sensitive and proprietary information. The group attempted to extort Pathstone Family Office, threatening to release data.

Scale of breach
641,000

records

Data exposed

Social Security numbers, dates of birth, addresses, and potentially detailed financial profiles of clients

Breach cause

ShinyHunters ransomware

Key Lessons

Attorneys filed a class action against Pathstone, alleging inadequate cybersecurity practices and noncompliance. Those claims will have to play out in court. Pathstone has yet to issue breach notifications or public responses. Any breach indicates a gap in perimeter security; access controls likely failed. Modern encryption that stays with data could have rendered it useless to the cyber criminals.

University of Hawaiʻi

Education

The University of Hawaiʻi was the victim of a ransomware attack. It impacted research systems, exposing personal information.

Scale of breach
1.2M

individuals

Data exposed

Social Security numbers, driver’s license details, and health-related research information

Breach cause

Ransomware

Source: University of Hawaiʻi statement, hawaii.edu

Key Lessons

An unauthorized user was able to encrypt and exfiltrate data during the attack. UH said that they have no reports of hackers publishing any stolen data. They continue to investigate the root cause. This incident brings to the forefront the discussion on knowing where all sensitive data resides.

The breached files were part of a subset and were collected between 1993 and 2007. This was likely old data that UH may no longer have needed to keep. It could have been “forgotten data,” which carries risk. Having policies in place to delete or remove old data would have potentially prevented this.

A breach you have closed is not finished while the stolen data remains readable.

Learn how PK Protect finds and protects regulated data.

Explore PK Protect

Data Breaches from February 2026

Even though February is a short month, there were numerous 2026 data breaches. Healthcare, fintech, marketplaces, and publishing platforms all experienced incidents. Many involve lawsuits from customers.

BridgePay

Payments

BridgePay, a payments platform, confirmed a ransomware attack that led to a system disruption. City governments are a large part of the company’s customer base, and many reported outages. As of February 28, BridgePay had restored all its infrastructure.

Scale of breach

The company stated there was no exposure of credit card numbers.

Data exposed

Unknown

Breach cause

Ransomware

Source: BridgePay’s statement

Key Lessons

Ransomware continues to be a risk for any organization. Proactively securing data against it is your best approach. Key components of a proactive data security program include automated data discovery and protection. Discovery is a critical first step since you must know where all sensitive information is to protect it.

Using policy-driven protection controls enables you to define them centrally and apply them consistently across your enterprise. You can also ensure secure data exchange with certificate-free, modern encryption.

University of Mississippi Medical Center

Healthcare

The University of Mississippi Medical Center closed clinics after a ransomware attack in February. The impact included IT systems and EHRs, requiring manual processes for patient care. They were able to reopen clinics on March 2.

Scale of breach

Impacted data included phone and email access. It also forced clinicians to move to downtime procedures.

Data exposed

The organization has not disclosed whether there was any breach of PII or PHI.

Breach cause

Ransomware

Source: The organization has yet to send any data breach notifications. They announced the issue on their social media profiles and published a statement on March 2 about reopening clinics.

Key Lessons

Healthcare remains an attractive target for ransomware. Few are ready, as almost 40% of organizations facing an incident took a month or more to recover.

Data breach resiliency strategies can reduce the effects of ransomware. Such programs involve enterprise-wide visibility of sensitive data and preemptive protections, such as encryption, masking, and redaction.

Marquis Health

Healthcare

Over 780,000 people had their information stolen in this healthcare data breach. The company detected the breach in 2025. It only recently came to light when the organized issued breach notifications in multiple states. Marquis stated that the SonicWall hack was to blame and has since filed suit against them.

Scale of breach
780,000

individuals

Data exposed

Names, addresses, Social Security numbers, dates of birth, account numbers, credit/debit card numbers, and taxpayer identification numbers

Breach cause

Ransomware breach on SonicWall cloud backup hack

Source: New Hampshire, Maine, Massachusetts

Key Lessons

The source of the breach was Marquis’s cybersecurity partner, SonicWall, as alleged in their lawsuit. Marquis’s investigation found that the attacker leveraged configuration data extracted from SonicWall’s cloud backup infrastructure tied to an API code change.

Marquis also stated its firewall was up to date and had other security controls in place, including MFA.

This incident underscores the importance of auditing partners that support technology, networks, or other infrastructure. Additionally, companies must take steps to ensure exfiltrated data isn’t usable by encrypting, masking, or redacting it properly and consistently.

Substack

Publishing

Substack, a subscription-based publishing platform, suffered a data breach that exposed subscriber information. The company confirmed that no passwords, payment card data, or financial records were part of the incident.

Scale of breach

Unknown

Data exposed

Email addresses and phone numbers

Breach cause

Unauthorized third-party access

Source: The company sent this email to users.

Key Lessons

Since the hacker had limited account access, there was no PII or PHI breached. However, this incident serves as a warning against depending too much on perimeter controls as the last line of defense. Unfortunately, weaknesses are common here. The best way to bolster defenses is with data-centric protections that are always present. When data has persistent protection, if stolen, data is typically unusable.

CarGurus

Marketplace

CarGurus, an online automotive marketplace, revealed a data breach affecting over 12 million users. An Australian cybersecurity consultant, Troy Hunt, was the first to report this after finding published PII data.

The company reported a system compromise involving stored customer account information. They investigated, secured the impacted platforms, and implemented more safeguards in response. Victims have filed class action lawsuits.

Scale of breach
12M+

users

Data exposed

Names, email addresses, physical addresses, IP addresses, and phone numbers

Breach cause

ShinyHunters claimed responsibility via social engineering.

Source: One lawsuit alleges that CarGurus did not provide a data breach notice. There are no formal notices, but the company did acknowledge it, stating it was “limited in scope.”

Key Lessons

Employees can be a weak link in cybersecurity. While training helps, hackers have become very sophisticated in their social engineering attacks. As such, you can’t always count on employees to recognize and report phishing.

To further safeguard data against such a breach, persistent, modern encryption should be part of a data protection program. When it is, it never leaves the data, so anything hackers steal won’t be of value if they can’t decrypt it.

A breach you have closed is not finished while the stolen data remains readable.

Learn how PK Protect finds and protects regulated data.

Explore PK Protect

Data Breaches from January 2026

We’re kicking off 2026 data breaches with a review of January. The incidents in January cover multiple industries. What’s unique about this batch is that there was exposure of both consumer and corporate data. Explore the cases in January and the key insights into preventing these in your organization.

Illinois and Minnesota Department of Human Services

Government

Both Illinois and Minnesota experienced a system failure that exposed the personal data of nearly one million people. In the Illinois incident, sensitive information was on display publicly and was visible for four years.

The Minnesota breach was the result of excessive internal access, leading to improper disclosure.

Scale of breach
~1M

individuals

Data exposed

Names, addresses, case numbers, case status, and referral information (Illinois); names, addresses, email addresses, dates of birth, phone numbers, Medicaid ID, the first four digits of Social Security numbers, and other protected information (Minnesota).

Breach cause

In Illinois, an error caused patient data to be publicly viewable. In Minnesota, the culprit was unauthorized access to data that was outside the scope of employee work assignments.

Source: Report from HIPAA Journal (Illinois)

Key Lessons

It's imperative for every organization to have complete visibility of where sensitive data resides. Automated discovery provides this visibility enterprise-wide and centralized, policy-based protection ensures consistent security of data. For four years, the data of Illinois residents was available online. Having an always-up-to-date inventory with data-centric protection can prevent such exposure.

Identity access control (IAC) plays a key role in thwarting unauthorized access, but relying on it as the last line of defense has shortcomings. IAC doesn't truly protect your critical data and sensitive data can be exposed if data moves or credentials are compromised. Protecting data through encryption, masking, or redaction secures data at rest and in motion and ensures that exfiltrated data is useless to bad actors.

Ledger and Global-e

Crypto

Ledger, a crypto wallet platform, confirmed a customer data breach related to its e-commerce payment partner, Global-e. While there were no crypto assets stolen, hackers later used this information in phishing campaigns.

Scale of breach

Unknown

Data exposed

Name, addresses, email addresses, phone numbers, and order details.

Breach cause

The company identified unusual activity in its cloud systems and moved to secure it. They did not disclose the root cause.

Source: Global-e Statement

Key Lessons

Companies should adopt persistent encryption and protection across all environments. With such a proactive strategy in place, organizations can protect across the enterprise. When security is data-centric, it reduces the effect of breaches.

Cloud-Sharing Sites

Cloud storage

The threat actor Zestix has been selling corporate data stolen from multiple companies. They are acting as an initial access broker (IAB) on the dark web. The hack occurred due to stolen credentials. ShareFile, Nextcloud, and OwnCloud were all victims of the attack. There were impacted organizations across many sectors, including aviation, defense, healthcare, utilities, mass transit, telecom, legal, real estate, and government.

Scale of breach

Unknown

Data exposed

Highly sensitive corporate data, including health records and government contracts.

Breach cause

Stolen credentials and lack of multi-factor authentication

Source: Infostealers published a detailed analysis of the hacks.

Key Lessons

Cloud exposure has been a risk component for many years. MFA has become mandatory in many regulations. Will this alone be enough to reduce unauthorized access? No, but enterprise-wide data encryption, redaction, and masking limit the fallout of such an attack.

Nike

Apparel

On January 24, Nike launched an investigation into a possible cyber attack. This action came after WorldLeaks claimed it had stolen and posted 1.4 terabytes of internal company data.

Scale of breach
1.4 TB

of company data

Data exposed

Product development intellectual property and supply chain logistics

Breach cause

Not defined, but threat intelligence firms have suggested a connection to supply chain infrastructure.

Source: The National CIO Review provided an extensive review of the attack and leak.

Key Lessons

This data breach involves corporate data versus customer data. Investigators did not find personal identifiers. However, the leak of IP and other trade secrets could have been of value to competitors.

Organizations should enforce security controls and cybersecurity best practices with supply chain vendors. Additionally, security embedded into data follows it wherever it goes.

Crunchbase

Business data

Crunchbase confirmed a data breach in January after a hack. ShinyHunters, a cybercrime group, claimed responsibility. The company revealed there was file exfiltration but said there were no operational disruptions. The incident is still under investigation, and they have yet to send any notifications to customers.

Scale of breach
2M

records

Data exposed

PII and corporate data (e.g., contracts and internal documents)

Breach cause

Social engineering campaign using voice phishing techniques

Source: SecurityWeek was the first to report the story and received confirmation from Crunchbase.

Key Lessons

Social engineering, especially deepfakes, is much more sophisticated than ever before. They are emerging as a key way for hackers to compromise credentials. While you can't eliminate all breach risk, you can take proactive steps to minimize the impact. Examples include:

  • Identifying older files and enforcing data retention policies
  • Using encryption mechanisms that stay with data
  • Applying data discovery and classification solutions to build an inventory of sensitive information

Match Group

Dating apps

The family of Match dating apps finishes out the list of the major 2026 data breaches in January. ShinyHunters was also the cyber criminal in this case. The group claimed they have millions of documents, while Match called it a “security incident” that is still under investigation.

Scale of breach
10M

records

Data exposed

User and corporate data

Breach cause

According to ShinyHunters dark web leak site, it cited AppsFlyer as the entry point. AppsFlyer is a marketing analytics company for apps.

Source: The Register published a review of the breach and exposures.

Key Lessons

It appears this is another third-party system failure. Data sharing for analytics is essential to any business but carries risk. Secure data exchange, internally or externally, with modern encryption allows for access while safeguarding data.