July 2026: Key Takeaways
Most of July's largest data breaches did not begin with a broken perimeter. In four of the five incidents below, attackers used access that already worked: a phished employee, a vishing call, a vendor's ticketing platform, and an unnamed vendor with network access. The second pattern is location. Support tickets, systems inherited in an acquisition, and environments accessible through a vendor are not places anyone designs to store Social Security numbers. In July, they all did.
IBM's 2026 Cost of a Data Breach Report, released July 29, put the global average at a record $4.99 million and the U.S. average at $11.5 million. Phishing led all initial attack vectors for the fourth consecutive year. Two of July's five incidents drew proposed class actions within 11 days of notification, and three exposed identifiers that cannot be reissued, creating liability with no expiration date.
What happened in July:
- 01 AssuranceAmerica, an auto insurance managing general agency, confirmed the largest known exposure of U.S. driver's license numbers this year, affecting nearly 7 million people, after malicious activity targeting one employee.
- 02 Ernst & Young disclosed that an unauthorized party spent two weeks inside a third-party IT service management platform, downloading tax documents belonging to customers of financial institutions that use the firm.
- 03 Craneware, whose software supports more than 2,000 U.S. hospitals and health systems and nearly 10,000 clinics and retail pharmacies, told the London Stock Exchange that attackers exfiltrated file names, a percentage of employee data, and a subset of customer and partner records.
- 04 Abbott confirmed unauthorized access to legacy Exact Sciences systems in its Cancer Diagnostics business. The compromise came roughly twelve weeks after the company closed the acquisition that brought those systems inside.
- 05 NYC Health + Hospitals returned to the news when an extortion group claimed an 11-terabyte archive, months after the system confirmed a breach that exposed fingerprints and palm prints.
What security teams should take from this month:
Valid credentials do not trigger alarms. A phished login, a vishing call that yields an SSO session, or a compromised vendor account looks like normal work to every control built to detect intrusion. When the front door opens legitimately, the only remaining variable is what state the data was in when the attacker reached it.
Sensitive data does not stay where you filed it. July's exposures sat in support tickets, acquired legacy environments, and vendor-reachable systems, none of them designed to hold regulated data. Automated discovery finds it wherever it drifted. Field-level encryption and tokenization decide whether reaching it means reading it.
One vendor's incident becomes many disclosures. Craneware, the platform behind EY's support tickets, and the unnamed vendor at NYC Health + Hospitals each held or reached regulated data belonging to other organizations. Contractual assurance does not reduce that exposure. What you send, and in what form, does.
Data Breaches from July 2026
July's breaches share an uncomfortable trait: the victims' defenses mostly worked as designed. AssuranceAmerica detected its intrusion in a day. Craneware contained its incident, and external specialists confirmed no residual indicators of compromise. Abbott reported no operational impact and noted that the compromised legacy systems sat apart from their own. Yet none of it changed the outcome. In each case, the attacker had already authenticated, and the data was already readable. Two entry points recurred all month: a person and a vendor. Knowing where regulated data lives, retaining less of it, and protecting it at the data layer remain the controls that change what a breach is worth.
Initial access
How they got in
Four of the five July incidents started with credentials or connections that already had permission. Only one entry path remains undisclosed.
Malicious activity targeting a single employee, which yielded credentials used to access and copy files.
A vishing campaign against several employees, compromising a corporate Microsoft Entra single sign-on account.
Unauthorized access to a third-party IT service management platform used for internal support workflows.
The actor may have gained access to its systems due to a security breach at a third-party vendor.
Craneware has not disclosed the vector, the threat actor, or the duration of access.
Sequence
Intrusion, detection, disclosure
Every July headline traces back to access gained weeks or months earlier. The gap between the two is where the data sat readable.
What was exposed
Reissuable, or permanent
A payment card can be replaced. A palm print cannot. Three of July's five incidents exposed identifiers with no expiration date.
| Identifier | Recoverable? | AssuranceAmerica | Ernst & Young |
Craneware | Abbott | NYC Health + Hospitals |
|---|---|---|---|---|---|---|
| Social Security number | Never | |||||
| Driver's license number | Never | |||||
| Tax ID / taxpayer identification | Never | |||||
| Biometrics — fingerprints, palm prints | Never | |||||
| Date of birth | Never | |||||
| Medical records, diagnoses, test results | Never | |||||
| Health insurance and payor IDs | Rarely | |||||
| Name, address, contact information | Rarely | |||||
| Insurance policy, claims, vehicle data | Rarely | |||||
| Financial account and payment card | Reissuable | |||||
| Online account credentials | Reissuable | |||||
| Employee, customer and partner records | Varies |
AssuranceAmerica
InsuranceAssuranceAmerica, an Atlanta-based managing general agency, detected suspicious activity on March 17, 2026, and traced it to malicious activity the previous day targeting one of its employees. An unauthorized third party then reached portions of the IT environment and copied data files. The file review concluded on June 15, and notifications rolled out through June and July. The company is also offering 12 months of credit monitoring and identity protection through IDX. The result is the largest known exposure of American driver's license numbers in 2026, and it turned on one compromised person rather than any flaw in the network.
individuals, per the company's filings with the Maine and Indiana attorneys general.
Each affected file contained a name plus one or more of the following:
- Contact information
- Automobile insurance policy or insurance account information
- Driver or vehicle information
- Claims-related information
- Driver's license number
- Tax ID information
- Social Security number
Malicious activity targeting a single employee, which yielded credentials used to access and copy files. No threat group has claimed the incident, and no public source reports a ransom demand.
Source: AssuranceAmerica notice of data breach filed with the California Attorney General, oag.ca.gov. The affected count comes from the company's filings with the attorneys general of Maine and Indiana, first reported by TechCrunch.
Neither a driver's license number nor a Tax ID can be reset. That is what separates this breach from a payment card exposure, where reissuing the card ends the problem. Insurers collect government identity documents because underwriting requires them, so minimization is the first question: how long does a closed claims file need a license number in readable form? Everything retained past that point should be tokenized. One employee will eventually click, and tokenization decides what that click costs.
Ernst & Young
Professional servicesErnst & Young uses a third-party IT service management platform so its technology staff can support teams performing tax work for clients. Those support tickets carry attachments, and those attachments contain tax filings. EY detected unusual activity on the platform on April 23, 2026, and determined that an unauthorized third party had accessed it between March 28 and April 12 and downloaded client documents. Notification letters went out on July 13, and a proposed class action followed on July 20. Most affected individuals are customers of financial institutions that retain EY for investment-related tax work, so they never had a direct relationship with the firm.
EY has not disclosed a total. State filings list 873 Texas residents, 480 Massachusetts residents, and 13 Vermont residents. The firm is offering 24 months of credit monitoring, identity monitoring, and identity restoration.
Documents attached to support tickets, containing personal and financial information included in or used to prepare tax filings:
- Names and addresses
- Dates of birth
- Social Security numbers
- Financial account and payment card information
Unauthorized access to a third-party IT service management platform used for internal support workflows. EY has not named the vendor or the initial access method. ShinyHunters claimed responsibility on July 27 and set a July 31 deadline for EY to make contact, telling reporters that credentials obtained in a supply-chain compromise also gave it access to EY's Jira, GitHub, and Azure environments. EY has not confirmed the group's involvement or the broader access claim. The deadline passed without publication, and as of August 4, the group has stated that further releases are being prepared.
Source: Ernst & Young LLP breach report filed with the California Attorney General, oag.ca.gov/ecrime/databreach/reports/sb24-626542
A help desk platform is a data store that nobody inventories as one. Its purpose is workflow, so it gets classified as an operational tool while quietly accumulating whatever employees attach to tickets. An inventory that says tax filings live in the tax systems is not wrong, only incomplete, and that gap is where this data sat. The exposure compounds through the supply chain: financial institutions gave the data to EY, EY moved it into a vendor platform, and the people whose Social Security numbers were taken had no relationship with either. Discovery must scan where data drifted, not where policy says it lives.
Craneware
Healthcare softwareCraneware, an Edinburgh-based healthcare financial software firm, disclosed a cybersecurity incident to the London Stock Exchange on July 20, 2026, reporting unauthorized access to a subset of its data environment. The company contained the incident, appointed external forensic specialists, and notified the UK Information Commissioner's Office and the FBI. Customer services and operations continued without disruption. What makes the incident significant is not its severity at Craneware but its reach. The Trisus platform handles revenue integrity, charge capture, claims analytics, and pharmacy program management for a large share of the American hospital sector.
The company reports partnering with more than 2,000 hospitals and health systems and supporting nearly 10,000 clinics and retail pharmacies.
The company reports that investigations established the following:
- A significant volume of file names viewed and exfiltrated
- A percentage of Craneware employee data
- A subset of customer and partner records
- A large element assessed as non-sensitive or already-public regulatory data
Unauthorized access to a subset of the company's data environment. Craneware has not disclosed the vector, the threat actor, or the duration of access, and external specialists confirmed no residual indicators of compromise.
Source: The Craneware Group plc, Notice of Cyber Security Incident, London Stock Exchange Regulatory News Service, July 20, 2026, investegate.co.uk
This entry belongs in the report for the same reason the NAIC breach did last month: concentration, not severity. A hospital can harden its own endpoints, train its own staff, and patch its own systems. But none of that addresses the risk with the vendor that processes its billing. Where healthcare organizations retain control is in what they hand over and in what form. Sending tokenized identifiers to a revenue analytics platform preserves the analytics while removing identity data from the vendor's blast radius.
Abbott
Medical devices & diagnosticsAbbott completed its $21 billion acquisition of Exact Sciences on March 23, 2026. By mid-June, attackers were inside the legacy Exact Sciences environment. Abbott confirmed the incident on July 16, describing unauthorized access to a limited number of internal systems in its Cancer Diagnostics business only, and stated that the legacy Exact Sciences systems are separate from Abbott's own. Roughly twelve weeks separated the closing of the deal from the compromise of the systems it brought in. That is not enough time to inventory, segment, and secure an acquired data estate of that size. A proposed federal class action followed on July 24. An extortion group called ShinyHunters has claimed responsibility for the Cancer Diagnostics intrusion, and its claims about the volume and content of the data taken remain unverified.
A second and unrelated claim landed in the same window. A threat actor calling itself ShadowByt3$ says it reached Abbott's Core Laboratory business through the LabCentral customer portal on July 4 using compromised customer credentials, taking product and regulatory documentation rather than customer data. Abbott says LabCentral is externally hosted and that there has been no known exposure of sensitive customer or business information.
Abbott has confirmed unauthorized access to a limited number of Cancer Diagnostics systems but has not disclosed the number. ShinyHunters claims 30 million customer records, including approximately 1 million Social Security numbers, more than 22 million doctor and patient notes, and more than 20 million medical orders. Nothing has been published, and no independent party has verified any part of the claim.
Abbott has not specified categories and continues to investigate what information the attackers accessed. The claimed data, unverified, includes:
- Names and contact information
- Dates of birth
- Social Security numbers
ShinyHunters says it gained access through a vishing campaign against several employees in mid-June, compromising a corporate Microsoft Entra single sign-on account and taking data from connected applications. Abbott has not confirmed the vector or named the group. The group's original publication deadline of July 18 was extended to July 21 after contact was made, and as of August 4 no data has been published.
Source: Abbott statement on cyber incident in Cancer Diagnostics business, abbott.com
Due diligence prices an acquisition's revenue with far more rigor than it maps the acquisition's data. A company closing a deal inherits every archive, every legacy database, and every retention practice the target ever had. It inherits them on day one, while integration runs for quarters. The separate legacy environment Abbott describes is the environment an attacker reached. Automated discovery across an acquired estate belongs in the first 30 days after close, not in the integration backlog, because regulated data is a liability from the moment the papers are signed.
NYC Health + Hospitals
Public health systemNYC Health + Hospitals, the largest public health system in the United States, confirmed in March that an unauthorized actor had accessed its network from late November 2025 through February 2026 following a compromise at a third-party vendor. It reported at least 1.8 million affected individuals to the Department of Health and Human Services, and it is offering 24 months of credit monitoring through Kroll to anyone who has been a patient or workforce member since 2020. The incident returned to the news on July 27, when an extortion operation calling itself LeakNet published a preview of what it claims is an 11-terabyte archive linked to more than 12 million people. No independent review has confirmed that figure, and the confirmed count remains 1.8 million.
At least 1.8 million individuals, according to the system's report to HHS. LeakNet's claim of more than 12 million remains unverified.
Categories vary by individual and include:
- Medical information, including record numbers, diagnoses, medications, test results, images, and treatment plans
- Health insurance information, including Medicaid, Medicare, and government payor ID numbers
- Billing, claims, and payment information
- Biometric information, specifically fingerprints and palm prints
- Social Security numbers, driver's license numbers, and taxpayer identification numbers
- Precise geolocation data
- Credit and debit card numbers, financial account information, and online account credentials
The health system says the actor may have gained access to its systems due to a security breach at a third-party vendor. It detected the activity on February 2, 2026.
Source: NYC Health + Hospitals, Notice of Data Breach, nychealthandhospitals.org. The affected count comes from the system's report to the HHS Office for Civil Rights.
Every downstream control arrives too late for a fingerprint. Cards get reissued, and passwords rotated, but a palm print is permanent, and the people in this breach carry that exposure for life. So, the question is not how to protect it. It is why a hospital system held it in a form that could be copied, which makes this minimization before encryption. Biometric identifiers belong in storage as irreversible templates, retained only as long as the access-control purpose lasts. A breach you have closed is not finished while the stolen data remains readable.
Archive
Every 2026 edition
Data Breaches from June 2026
June was dominated by data-theft extortion rather than ransomware. Researchers now describe ShinyHunters, the month’s principal actor, as a durable cybercrime brand rather than a single crew; it ran a pay-or-leak campaign across healthcare, insurance regulation, and entertainment using an Oracle PeopleSoft zero-day and social engineering, while a parallel pharmaceutical breach turned on a single developer credential. In nearly every case, the perimeter did not fail: attackers logged in with valid or inherited access, then took data usable the moment it left the perimeter. Knowing where sensitive data resides, minimizing what is retained, and protecting it at the data layer remain the best assurance against breaches.
One Medical (Amazon)
HealthcareAmazon-owned primary care provider One Medical confirmed a breach of a third-party file storage system holding archived records for its senior care division. It discovered the access on June 13, 2026, and determined that an unauthorized party reached the platform between June 8 and 11. One Medical said the incident was limited to legacy data for One Medical Seniors patients, formerly Iora Health, acquired in 2021, and did not touch its other systems or main electronic medical record. Days later, ShinyHunters claimed 8.8 terabytes and set a June 22 deadline before publishing.
ShinyHunters claimed 8.8 terabytes; One Medical described the affected group as a subset of legacy One Medical Seniors patients within a network serving more than 830,000 patients overall.
Demographic information and clinical records of legacy Iora Health and One Medical Seniors patients. No other One Medical or Amazon systems were involved.
Unauthorized access to a third-party archival file storage platform; ShinyHunters claimed responsibility, though One Medical has not named the group.
Source: HIPAA Journal reporting on the One Medical breach notice, hipaajournal.com
Legacy systems are healthcare security’s most common blind spot, and this is a clean example. The exposed data belonged to a practice acquired five years ago, parked in an archive that likely received less protection than the live record, yet it still contained clinical records on elderly patients, data with permanent identifiers, and a real risk of Medicare fraud. The fix is twofold: automated discovery that surfaces forgotten and migrated data, and persistent encryption so an archive breach yields unreadable files. Data you have stopped using is still your responsibility.
National Association of Insurance Commissioners (NAIC)
Insurance regulationThe NAIC, which coordinates insurance regulation across all fifty U.S. states, disclosed that an unknown third party had gained unauthorized access to its systems. It identified the access on or about June 11, 2026, traced it to its PeopleSoft environment, and posted notices on June 17 and 18. ShinyHunters claimed responsibility on June 18, listed the NAIC with a June 22 deadline, and published its claimed haul online around June 25. NAIC’s position is that the exposure reaches into the sector’s financial plumbing but is far narrower than the attacker first alleged, and that much of what was taken was already public.
ShinyHunters claimed 3.1 terabytes across more than 105,000 files, affecting the NAIC, all fifty state insurance departments, and thousands of licensed insurers.
The attacker’s initial claim, roughly 2.1 million insurer regulatory filing PDFs across systems including INSData, SERFF, and OPTINS, was later walked back by ShinyHunters itself, which revised the count to about 260,000 filing documents and removed the system references, saying its first statement was based on an AI-generated misinterpretation of its own data. NAIC’s outside experts concluded that SERFF, OPTINS, and the other named systems were not actually accessed, and that what was taken was largely already-public statutory financial reports and credit rating agency data, along with outdated logs and configuration files. NAIC states that no personally identifiable information or payment data was involved.
Unauthorized access to the NAIC’s PeopleSoft system; ShinyHunters claimed responsibility. The intrusion fits the group’s broader 2026 Oracle PeopleSoft zero-day campaign.
Source: The Insurer, Threat actor group ShinyHunters claims to have obtained NAIC data, theinsurer.com
This is a systemic-risk breach, not a consumer-records one: a single aggregator consolidated filings and identifiers from across the entire U.S. insurance industry, so a single intrusion exposed thousands of insurers at once. It is the sector’s version of the vendor problem: sensitive data funneled into shared platforms whose security becomes everyone’s. The lesson holds even after NAIC’s clarification that most of the data was already public, because the risk was never the sensitivity of any one filing; it was the concentration. Encryption and tokenization at rest, plus strict access governance, would have meant that reaching the system did not equal reading its contents.
Madison Square Garden Entertainment
EntertainmentShinyHunters published roughly 45 gigabytes stolen from Madison Square Garden Entertainment after it missed a June 15 ransom deadline; the group says it broke in on June 5, listed the company on June 12, and released the data on June 16. The striking element is its nature: MSG has used facial recognition across its venues for years, including to bar attorneys from firms litigating against it, and that surveillance apparatus is in the leak. Class action lawsuits followed within a day. It is MSG’s second major breach in under a year.
ShinyHunters claimed more than 26 million customer and corporate records in a roughly 45-gigabyte dump.
Customer account and ticketing details, support emails, and internal corporate documents tied to the Knicks and Rangers, alongside facial recognition surveillance records, threat-assessment ratings, and detailed guest profiles with fields such as “claim to fame” and “cost of talent.” Payment card numbers and Social Security numbers were not confirmed in this dump.
Data-theft extortion by ShinyHunters; the company declined to pay, and the data was published. MSG has not detailed the initial intrusion vector.
Source: The Next Web, ShinyHunters published 45GB of Madison Square Garden data, including facial recognition surveillance records, thenextweb.com
The biometric angle echoes last month’s NYC Health and Hospitals breach for the same reason: a face, like a fingerprint, cannot be reissued. Data collected to control building access is now in criminal hands, and the people in it cannot reset their exposure. Before encryption even applies, there is a data-minimization lesson: biometric and behavioral profiles should not be retained by default, and where kept must be encrypted and access-governed at rest.
DentaQuest
Dental benefitsDentaQuest, one of the largest U.S. dental and vision benefits administrators and a Sun Life Financial subsidiary, was hit by a ShinyHunters pay-or-leak campaign. After no agreement was reached, ShinyHunters published hundreds of gigabytes, which Have I Been Pwned analyzed in early June. DentaQuest acknowledged the incident in a June 1 notice describing unauthorized access to a limited portion of its network. As the largest U.S. Medicaid and CHIP dental benefits administrator, it has exposure to many low-income families and children.
2.6 million unique individuals, per Have I Been Pwned’s analysis of the leaked dataset; the company manages benefits for roughly 32 million Americans.
Names, mailing addresses, gender, dates of birth, phone numbers, email addresses, and health insurance information, much of it in healthcare enrollment files, with some records containing Medicaid IDs.
ShinyHunters data theft and extortion; the company did not reach an agreement, and the data was published.
Source: Security Affairs, DentaQuest Breach: ShinyHunters Publish Data Impacting 2.6 Million People, securityaffairs.com
Medicaid IDs and enrollment records are exactly the regulated, durable data that should never sit in a form an attacker can read after exfiltration. Structured enrollment files point to large volumes of standardized, highly sensitive records, the precise case where field-level encryption and tokenization pay off. A benefits administrator is also a concentration point, holding data for states, insurers, and millions of members, so its posture becomes theirs. Encrypting the fields that carry Medicaid IDs would have changed what the leak was worth.
Novo Nordisk
PharmaceuticalThe Danish maker of Ozempic and Wegovy disclosed on June 11, 2026, that attackers had reached a limited number of internal IT systems and copied non-public data, including personal data. Two things stand out. First, the entry point: FulcrumSec, the group claiming responsibility, said it gained access months earlier through an exposed high-privilege developer credential, then moved laterally on credentials left in code repositories. They did not break the perimeter; they authenticated. Second, the outcome split by how data was protected: the clinical trial patient data was pseudonymized and could not identify participants without separately protected information, while healthcare professional records were directly identifying.
Novo Nordisk did not disclose a total; the claimant group referenced roughly 700,000 files and about 1.3 terabytes, including data on about 11,500 pseudonymized clinical trial participants. A second group separately claimed an intrusion targeting the company’s AI assets.
For trial patients, pseudonymized data: a random patient ID, trial details, sex, year of birth, biomarkers, and health and lifestyle factors. For healthcare professionals, directly identifying data: names, registration numbers, emails, phone and WhatsApp details, and office locations. The attacker also claimed source code, drug research, manufacturing records, and internal AI models.
Unauthorized access via an exposed high-privilege developer credential (a GitHub personal access token), followed by lateral movement using credentials found in repositories. Attributed to the claimant group FulcrumSec; no ransomware was involved.
Source: Dark Reading, Novo Nordisk Breach Exposes Software Development Pipeline Risk, darkreading.com
This is the month’s most instructive breach because it shows data-centric protection working and failing in the same incident. Because the trial data was pseudonymized, Novo Nordisk could credibly tell patients the records could not be tied back to them, de-identification doing exactly what it is designed to do. Everything not protected that way, the healthcare professional contact details, the source code, the AI models, left fully usable. The entry point cuts the other way: one developer token and credentials left in repositories were enough, which is why secrets management and non-human-identity inventory now matter. Protect and minimize the data, and a breach becomes a disclosure you can manage rather than one that defines you.
Data Breaches from May 2026
May 2026 made one thing clear: attackers did not break in; they logged in. Almost every major incident this month began with a person rather than a flaw, whether it was a help desk agent who talked out of a credential, an employee who phished into surrendering a single sign-on token, or a vendor whose access was simply inherited. Two patterns defined the month. The first was a sustained ShinyHunters extortion campaign targeting SaaS and CRM platforms, exfiltrating data at scale from Salesforce, Microsoft 365, and similar systems. The second was a wave of third-party vendor compromises in healthcare, in which the entry point lay entirely outside the breached organization. In both cases, the perimeter held, and the data still walked out the door because it was readable the moment an attacker reached it.
NYC Health + Hospitals
HealthcareThe largest public health system in the United States confirmed a months-long intrusion that originated at an unnamed third-party vendor. NYC Health + Hospitals detected suspicious activity on February 2, 2026, and later determined that an unauthorized actor had access to parts of its network from roughly November 25, 2025 through February 11, 2026, copying files during that window. The system serves a safety-net population that is largely on Medicaid, and it offered affected individuals 24 months of credit monitoring retroactive to any interaction since 2020. What sets this breach apart from a typical healthcare incident is the data type: alongside medical and financial records, attackers took biometric fingerprints and palm prints.
At least 1.8 million people confirmed; reported to the U.S. Department of Health and Human Services as one of the largest healthcare breaches of 2026.
Medical records (diagnoses, medications, test results), health insurance information, Social Security numbers, government-issued identification including driver’s licenses and passports, financial account details, online account credentials, precise geolocation data, and biometric fingerprints and palm prints.
Compromised unnamed third-party vendor; specific access vector not disclosed.
Source: TechCrunch reporting on the NYC Health + Hospitals breach notice, techcrunch.com
A stolen password can be changed, a Social Security number can be flagged, a credit card can be reissued. A stolen fingerprint cannot. Biometric exposure is permanent, which makes it the clearest possible case for protecting the data at rest rather than relying on the network around it. The breach also illustrates the vendor problem in its starkest form: the organization that hardened its own systems was compromised through one it did not run. Automated data discovery that flags where biometric and regulated data lives, combined with persistent encryption on that data, would have meant the exfiltrated files were unreadable to the attacker regardless of which vendor opened the door.
Instructure (Canvas)
Education techEducation technology company Instructure was breached twice within roughly two weeks by the extortion group ShinyHunters, in what is now considered the largest education-sector breach on record. The group gained initial access in late April 2026 by exploiting the Free-For-Teacher program, a feature that let educators create Canvas accounts without institutional verification. Instructure disclosed an incident on May 1 and said it had contained the issue by May 6. On May 7, ShinyHunters defaced Canvas login portals at roughly 330 institutions, including Harvard, Princeton, and the University of Pennsylvania, knocking the platform offline during final exam periods. On May 11, one day before the group’s deadline, Instructure paid a ransom and said it received “shred logs” confirming data destruction. Canvas is used by 41 percent of higher education institutions in North America.
ShinyHunters claimed to have exfiltrated 3.65 terabytes of data and roughly 275 million records across nearly 9,000 institutions; analysis identified approximately 231 million unique email addresses.
Names, email addresses, student ID numbers, and internal private messages. Instructure stated it found no evidence that passwords, dates of birth, government identifiers, or financial information were involved.
ShinyHunters’ extortion attack via a vulnerability in the Free-For-Teacher account program.
Source: Inside Higher Ed, Instructure Pays Ransom to Canvas Hackers, insidehighered.com
This is the breach that proves paying the ransom is not the same as protecting the data. Instructure paid and received a promise, but 275 million students and staff still had their information copied by a criminal group, and the inclusion of private messages makes this far more dangerous than a name-and-email leak. The “contained by May 6, defaced on May 7” sequence is a reminder that an organization’s belief that an incident is over is not evidence that it is. The durable defense is not negotiation after the fact, it is rendering exfiltrated data useless before it leaves: persistent encryption on student records and message stores, scoped access, and discovery that surfaces unverified account programs before an attacker finds them first.
Charter Communications (Spectrum)
TelecomOne of the largest broadband providers in the United States was compromised on April 1, 2026, when ShinyHunters used a voice phishing call to persuade an employee to share credentials for a Microsoft Entra account. The group used that access to reach Charter’s Salesforce environment and exfiltrate customer data, then listed the company on its leak site with a May 27 deadline. Charter did not pay, and the data was published. The company maintained that only sales tools were affected and that no sensitive personal information or customer proprietary network information was exfiltrated, while independent analysis told a more populated story. This incident is one node in a broader ShinyHunters Salesforce campaign that also touched Carnival, Canvas, CarGurus, Panera Bread, and 7-Eleven.
ShinyHunters claimed more than 42 million records; HaveIBeenPwned confirmed approximately 4.9 million unique email addresses, plus roughly 85,000 records from an internal employee directory.
Names, email addresses, home and company addresses, phone numbers, plan information, and support ticket details; the employee subset included job titles. Charter stated no passwords or payment information were in the dataset.
Voice phishing (vishing) compromise of an employee’s Microsoft Entra account, used to access the Salesforce CRM instance.
Source: SecurityWeek, Charter Communications Data Breach Could Impact Nearly 5 Million, securityweek.com
A single phone call gave an attacker a path into a CRM holding millions of customer records, which is the entire ShinyHunters playbook in one sentence. The gap between Charter’s “only sales tools” framing and the 4.9 million records confirmed in the wild is instructive: from a customer’s standpoint, the question is not how limited the breach felt internally, but whether the exposed data fuels phishing and fraud, and here it does. CRM platforms concentrate exactly the kind of personal data that should never sit in plaintext. Encrypting and tokenizing sensitive fields inside the CRM, paired with monitoring for anomalous bulk export volumes, would have blunted both the theft and its aftermath.
Carnival Corporation
TravelThe world’s largest cruise operator disclosed that a social engineering attack against a single employee account opened a path into its IT systems. Carnival identified the unauthorized activity on April 14, 2026, blocked it, and determined on April 22 that an attacker had copied personal information. The data the company itself confirmed is a near-complete identity toolkit, and an independent analysis of the leaked dataset identified millions of loyalty program accounts tied to Carnival’s Holland America brand. The company is offering affected individuals 24 months of TransUnion credit monitoring. For a company with a long and documented history of breaches, this incident adds another entry to an already lengthy record.
Approximately 6 million individuals notified by Carnival; ShinyHunters claimed 8.7 million records, and HaveIBeenPwned analysis indicated roughly 7.5 million Mariner Society loyalty accounts were affected.
Names, addresses, dates of birth, email addresses, phone numbers, and government-issued identification numbers, including driver’s license and passport numbers. The leaked loyalty dataset also included gender, geographic location, and loyalty program details.
Social engineering of a single employee account, used to access and exfiltrate files from company systems.
Source: SecurityWeek, Carnival Data Breach Exposed 6 Million People, securityweek.com
One deceived employee should not be able to expose 6 million people’s passport and driver’s license numbers, and the fact that it can is an architecture problem, not just a training problem. Passport and license numbers are exactly the kind of durable identifiers that enable identity theft for years, and unlike a password, they are not something a customer can rotate. Carnival’s repeated appearances in breach databases suggest the underlying issue is structural rather than a one-time failure. Persistent encryption of customer identity data, least-privilege access that limits what any single account can access, and bulk-export controls would have turned a single phished login into a contained incident instead of a 6-million-person disclosure.
The Oncology Institute
HealthcareA publicly traded cancer care provider operating more than 100 clinics across five states confirmed that patient data was compromised through a third-party software vendor. The disclosure was a follow-up to a voluntary filing the company made in November 2025, when the vendor’s investigation was still ongoing, and patient impact was unconfirmed. On May 20, 2026, Kroll, acting as the third-party administrator for the vendor, notified The Oncology Institute that an unauthorized actor had accessed systems containing patient data. The company said the incident appears to have affected multiple other healthcare providers as well, and that its continuity plan allowed care and operations to continue. The vendor has not been named publicly, though reporting has pointed to billing-software providers in the healthcare supply chain that suffered breaches affecting millions.
Number of affected patients not yet disclosed; the company stated that the incident affected other healthcare service providers and that it is reserving rights against third parties.
Patient data confirmed affected; specific data types not yet disclosed. The company is offering credit monitoring and identity protection to impacted patients.
Unauthorized third-party access to a software service vendor’s systems; no threat actor has claimed responsibility.
Source: SecurityWeek reporting on the company’s SEC Form 8-K filing, securityweek.com
This breach is the quiet version of the month’s loudest theme: the breached organization did nothing visibly wrong, and its patients were still exposed because the failure occurred within a vendor’s systems. Healthcare runs on an interconnected web of billing, eligibility, and software providers, each of which becomes part of the provider’s actual attack surface the moment it is granted access to patient data. Medical records carry permanent identifiers that cannot be reissued, and a provider cannot encrypt data it has handed to a vendor in plaintext. The lesson is to push protection upstream: require that sensitive data shared with vendors is encrypted and policy-governed before it leaves your environment, and maintain a current map, through automated discovery, of which third parties hold which regulated data.
Data Breaches from April 2026
April 2026 was dominated by supply-chain compromises and OAuth abuse. Two major U.S. banks were hit through a shared third-party vendor, a French government identity agency had records on millions of citizens offered for sale, a medical device giant faced a ShinyHunters extortion claim, Adobe was reportedly breached through an Indian BPO contractor, and an AI productivity tool became the entry point into a major cloud platform. Attackers are no longer breaking down the front door; they are walking in through trusted third parties. Knowing where sensitive data resides and protecting it accordingly remains the best assurance for breach resiliency.
Citizens Financial Group & Frost Bank
BankingThe Everest ransomware group posted both U.S. banks on its dark web leak site on April 20. The same-day leak involving shared document-production data points to a single-vendor compromise. Both banks confirmed the breach originated at an unnamed third-party vendor, not their own networks. Class action lawsuits were filed within days.
3.4 million records claimed from Citizens; over 250,000 SSNs and TINs from Frost.
Citizens — names, addresses, account numbers. Frost — names, addresses, Social Security numbers, taxpayer identification numbers, mortgage interest records, W-2s, 1099s, and HSA contributions.
Everest ransomware via a shared third-party vendor.
Source: Massachusetts Attorney General Data Breach Notification, mass.gov
Two well-resourced banks blaming the same unnamed vendor on the same day means the vendor’s security posture became their security posture. The contrast between the datasets is instructive; Citizens’ exposure is largely to scams and profiling, while Frost’s is a near-complete identity-theft toolkit. Persistent encryption that travels with the data would have neutralized Frost’s exposure entirely; the hackers may have taken the files, but encrypted SSNs and tax records are useless without keys.
France Titres / ANTS (French Government)
GovernmentFrance’s official issuer of national ID cards, passports, and driver’s licenses detected a breach on April 15. The next day, a threat actor known as “breach3d” listed the data for sale on a hacker forum. ANTS confirmed 11.7 million accounts were impacted and took the portal offline on April 24.
11.7 million accounts confirmed; threat actor claims up to 19 million records.
Login IDs, full names, email addresses, dates of birth, account identifiers, and, in some cases, postal addresses, place of birth, and phone numbers.
Undisclosed; investigation ongoing under CNIL, Paris Prosecutor, and ANSSI.
Source: ANTS Official Security Notice (ants.gouv.fr), ants.gouv.fr
Government identity database breaches are categorically more dangerous than commercial breaches because the data carries implicit authority. A scammer who knows a victim’s name, birthdate, and address sourced from the agency that issued their passport can run impersonations that random scraped data cannot match. Critical identity systems require data minimization, encryption that stays with the data, and continuous monitoring for anomalies in bulk exports.
Medtronic
Medical devicesMedical technology giant Medtronic confirmed on April 24, alongside an SEC Form 8-K filing, that an unauthorized party had accessed corporate IT systems. ShinyHunters claimed up to nine million records. Medtronic emphasized that hospital networks running their devices were not exposed.
Up to 9 million records claimed by ShinyHunters; investigation ongoing.
Personal information and internal corporate data; specific types still being assessed.
ShinyHunters extortion attack; initial access vector not disclosed.
Source: SEC EDGAR — Medtronic Form 8-K Filing, sec.gov
Medical device manufacturers carry both corporate and clinical risk surfaces, and the corporate-only framing only holds if segmentation is real. Medical records contain permanent identifiers; unlike credit cards, you cannot cancel your medical history. Persistent encryption on corporate-held customer and partner data limits what attackers can monetize, and automated discovery ensures regulated data does not drift into unprotected systems.
Adobe
SoftwareA threat actor known as “Mr. Raccoon” allegedly breached Adobe through an Indian Business Process Outsourcing (BPO) firm contracted for support operations. The attacker delivered a Remote Access Tool via phishing, pivoted to a manager’s account, and reached the helpdesk environment, where a single agent could export all tickets in one request. Adobe has not publicly confirmed or denied the breach.
13 million customer support tickets, 15,000 employee records, and all HackerOne bug bounty submissions claimed.
Customer names, email addresses, account IDs, internal technical notes, and unpublished vulnerability reports.
Supply-chain compromise via third-party BPO; phishing followed by privilege escalation.
Source: International Cyber Security News, cybersecuritynews.com
A single support agent being able to extract 13 million records in one query is an architectural gap, not a policy gap. The HackerOne submissions are the most damaging part; unpublished vulnerabilities could be weaponized before patches ship. Bulk export controls and DLP triggers on anomalous query volumes would have caught this. Persistent encryption on customer support data would have rendered the stolen tickets unusable after exfiltration.
Vercel (via Context.ai)
Cloud platformVercel disclosed on April 19 that a Vercel employee’s Google Workspace account was compromised via Context.ai, a third-party AI tool granted broad OAuth permissions. The Context.ai compromise traced back to a Lumma Stealer infection in February, a two-month dwell time. The breach was discovered when the attacker listed the stolen data for $2 million on BreachForums.
Limited customer subset; threat actor claims 580 employee records plus access keys, source code, and tokens.
Employee records, access keys, API keys, GitHub and NPM tokens, and non-sensitive environment variables.
OAuth supply-chain compromise via Lumma Stealer infection at Context.ai.
Source: Vercel Official Security Bulletin, vercel.com
One employee granting broad Workspace permissions to a third-party AI tool gave attackers an inherited trust path into Vercel. The breach was not discovered by Vercel’s security team; it was discovered when the attacker chose to monetize publicly. The OAuth graph is now the new perimeter, and most companies have no inventory of which third-party apps their employees have authorized. Tightening OAuth scope reviews and inventorying authorized third-party apps would have closed the lateral path before it was used.
Data Breaches from March 2026
March was a volatile month for data breaches and ransomware. The most prominent was the attack on Stryker. While that incident didn’t expose data, it still had a significant effect on the company. As always, knowing where sensitive data is and remediating it accordingly provides you with the best assurance for breach resiliency.
Stryker
Medical devicesStryker, a medical device company, was recently the target of a hack deployed by an Iran-linked group, Handala. It caused system outages throughout the organization. It was not a ransomware attack. Rather, this was a data theft and wipe strike. Windows-based devices, including laptops and mobile devices, were wiped. As of March 30, the company had restored most manufacturing sites.
Company applications and internal systems
Handala gained access to the company’s Active Directory Services, using the Microsoft endpoint management tool, Microsoft Intune.
This is a unique incident. Hackers didn’t steal data; they wiped in from internal systems, which triggered operational fallout. The attack on endpoint systems wasn’t to exfiltrate or hold for ransom; it was about disruption.
When there’s a compromise to endpoints, cyber criminals can deploy software to wipe, encrypt, or exfiltrate data as well as disable security mechanisms.
While you cannot eliminate this risk, you can do these things:
- Ensure automated sensitive data discovery, so you always know where data is.
- Use policy-based protection to determine what to do with the discovered data consistently (e.g., encrypt, mask, redact, etc.).
- Enable persistent encryption that stays with data regardless of where it goes.
Aura
Digital securityAura announced a data breach via a targeted phishing attack that led to the exposure of marketing data lists. The company identified the breach within an hour and activated its incident response plan. Aura announced that the hack did not expose any sensitive data.
records
Names and email addresses
ShinyHunters claimed responsibility via a phishing attack.
Source: Aura’s statement, aura.com
Aura did an excellent job of responding quickly. Often, it takes weeks or even months to detect unauthorized access. Even though data stolen wasn’t sensitive, it’s still a reminder that organizations should deploy data-centric encryption, which is “sticky.” It stays with the data no matter where it goes.
Data breach resiliency strategies can reduce the effects of ransomware. Such programs involve enterprise-wide visibility of sensitive data and preemptive protections, such as encryption, masking, and redaction.
Navia
Benefits adminAn exposed API was a weak link for an attacker to gain unauthorized access. The hackers stole personal and health-related data. Their investigation revealed that the threat actor acquired information from December 22, 2025, to January 15, 2026.
people
Social Security numbers, account data, names, dates of birth, phone numbers, email addresses, and health plan information
Exposed API
Source: Navia’s notice, naviabenefits.com
Perimeter defenses were insufficient to thwart unauthorized actors. They stole PII and PHI; data that should be encrypted at rest and in transit. Persistent encryption driven by enterprise-wide policies could have made a difference. The hackers may have taken the data, but with encryption, it would have been unusable.
Pathstone Family Office
Wealth managementPathstone Family Office, a wealth management firm, was the victim of a data breach perpetrated by ShinyHunters. The theft included 641,000 records of sensitive and proprietary information. The group attempted to extort Pathstone Family Office, threatening to release data.
records
Social Security numbers, dates of birth, addresses, and potentially detailed financial profiles of clients
ShinyHunters ransomware
Attorneys filed a class action against Pathstone, alleging inadequate cybersecurity practices and noncompliance. Those claims will have to play out in court. Pathstone has yet to issue breach notifications or public responses. Any breach indicates a gap in perimeter security; access controls likely failed. Modern encryption that stays with data could have rendered it useless to the cyber criminals.
University of Hawaiʻi
EducationThe University of Hawaiʻi was the victim of a ransomware attack. It impacted research systems, exposing personal information.
individuals
Social Security numbers, driver’s license details, and health-related research information
Ransomware
Source: University of Hawaiʻi statement, hawaii.edu
An unauthorized user was able to encrypt and exfiltrate data during the attack. UH said that they have no reports of hackers publishing any stolen data. They continue to investigate the root cause. This incident brings to the forefront the discussion on knowing where all sensitive data resides.
The breached files were part of a subset and were collected between 1993 and 2007. This was likely old data that UH may no longer have needed to keep. It could have been “forgotten data,” which carries risk. Having policies in place to delete or remove old data would have potentially prevented this.
Data Breaches from February 2026
Even though February is a short month, there were numerous 2026 data breaches. Healthcare, fintech, marketplaces, and publishing platforms all experienced incidents. Many involve lawsuits from customers.
BridgePay
PaymentsBridgePay, a payments platform, confirmed a ransomware attack that led to a system disruption. City governments are a large part of the company’s customer base, and many reported outages. As of February 28, BridgePay had restored all its infrastructure.
The company stated there was no exposure of credit card numbers.
Unknown
Ransomware
Source: BridgePay’s statement
Ransomware continues to be a risk for any organization. Proactively securing data against it is your best approach. Key components of a proactive data security program include automated data discovery and protection. Discovery is a critical first step since you must know where all sensitive information is to protect it.
Using policy-driven protection controls enables you to define them centrally and apply them consistently across your enterprise. You can also ensure secure data exchange with certificate-free, modern encryption.
University of Mississippi Medical Center
HealthcareThe University of Mississippi Medical Center closed clinics after a ransomware attack in February. The impact included IT systems and EHRs, requiring manual processes for patient care. They were able to reopen clinics on March 2.
Impacted data included phone and email access. It also forced clinicians to move to downtime procedures.
The organization has not disclosed whether there was any breach of PII or PHI.
Ransomware
Source: The organization has yet to send any data breach notifications. They announced the issue on their social media profiles and published a statement on March 2 about reopening clinics.
Healthcare remains an attractive target for ransomware. Few are ready, as almost 40% of organizations facing an incident took a month or more to recover.
Data breach resiliency strategies can reduce the effects of ransomware. Such programs involve enterprise-wide visibility of sensitive data and preemptive protections, such as encryption, masking, and redaction.
Marquis Health
HealthcareOver 780,000 people had their information stolen in this healthcare data breach. The company detected the breach in 2025. It only recently came to light when the organized issued breach notifications in multiple states. Marquis stated that the SonicWall hack was to blame and has since filed suit against them.
individuals
Names, addresses, Social Security numbers, dates of birth, account numbers, credit/debit card numbers, and taxpayer identification numbers
Ransomware breach on SonicWall cloud backup hack
Source: New Hampshire, Maine, Massachusetts
The source of the breach was Marquis’s cybersecurity partner, SonicWall, as alleged in their lawsuit. Marquis’s investigation found that the attacker leveraged configuration data extracted from SonicWall’s cloud backup infrastructure tied to an API code change.
Marquis also stated its firewall was up to date and had other security controls in place, including MFA.
This incident underscores the importance of auditing partners that support technology, networks, or other infrastructure. Additionally, companies must take steps to ensure exfiltrated data isn’t usable by encrypting, masking, or redacting it properly and consistently.
Substack
PublishingSubstack, a subscription-based publishing platform, suffered a data breach that exposed subscriber information. The company confirmed that no passwords, payment card data, or financial records were part of the incident.
Unknown
Email addresses and phone numbers
Unauthorized third-party access
Source: The company sent this email to users.
Since the hacker had limited account access, there was no PII or PHI breached. However, this incident serves as a warning against depending too much on perimeter controls as the last line of defense. Unfortunately, weaknesses are common here. The best way to bolster defenses is with data-centric protections that are always present. When data has persistent protection, if stolen, data is typically unusable.
CarGurus
MarketplaceCarGurus, an online automotive marketplace, revealed a data breach affecting over 12 million users. An Australian cybersecurity consultant, Troy Hunt, was the first to report this after finding published PII data.
The company reported a system compromise involving stored customer account information. They investigated, secured the impacted platforms, and implemented more safeguards in response. Victims have filed class action lawsuits.
users
Names, email addresses, physical addresses, IP addresses, and phone numbers
ShinyHunters claimed responsibility via social engineering.
Source: One lawsuit alleges that CarGurus did not provide a data breach notice. There are no formal notices, but the company did acknowledge it, stating it was “limited in scope.”
Employees can be a weak link in cybersecurity. While training helps, hackers have become very sophisticated in their social engineering attacks. As such, you can’t always count on employees to recognize and report phishing.
To further safeguard data against such a breach, persistent, modern encryption should be part of a data protection program. When it is, it never leaves the data, so anything hackers steal won’t be of value if they can’t decrypt it.
Data Breaches from January 2026
We’re kicking off 2026 data breaches with a review of January. The incidents in January cover multiple industries. What’s unique about this batch is that there was exposure of both consumer and corporate data. Explore the cases in January and the key insights into preventing these in your organization.
Illinois and Minnesota Department of Human Services
GovernmentBoth Illinois and Minnesota experienced a system failure that exposed the personal data of nearly one million people. In the Illinois incident, sensitive information was on display publicly and was visible for four years.
The Minnesota breach was the result of excessive internal access, leading to improper disclosure.
individuals
Names, addresses, case numbers, case status, and referral information (Illinois); names, addresses, email addresses, dates of birth, phone numbers, Medicaid ID, the first four digits of Social Security numbers, and other protected information (Minnesota).
In Illinois, an error caused patient data to be publicly viewable. In Minnesota, the culprit was unauthorized access to data that was outside the scope of employee work assignments.
Source: Report from HIPAA Journal (Illinois)
It's imperative for every organization to have complete visibility of where sensitive data resides. Automated discovery provides this visibility enterprise-wide and centralized, policy-based protection ensures consistent security of data. For four years, the data of Illinois residents was available online. Having an always-up-to-date inventory with data-centric protection can prevent such exposure.
Identity access control (IAC) plays a key role in thwarting unauthorized access, but relying on it as the last line of defense has shortcomings. IAC doesn't truly protect your critical data and sensitive data can be exposed if data moves or credentials are compromised. Protecting data through encryption, masking, or redaction secures data at rest and in motion and ensures that exfiltrated data is useless to bad actors.
Ledger and Global-e
CryptoLedger, a crypto wallet platform, confirmed a customer data breach related to its e-commerce payment partner, Global-e. While there were no crypto assets stolen, hackers later used this information in phishing campaigns.
Unknown
Name, addresses, email addresses, phone numbers, and order details.
The company identified unusual activity in its cloud systems and moved to secure it. They did not disclose the root cause.
Source: Global-e Statement
Companies should adopt persistent encryption and protection across all environments. With such a proactive strategy in place, organizations can protect across the enterprise. When security is data-centric, it reduces the effect of breaches.
Cloud-Sharing Sites
Cloud storageThe threat actor Zestix has been selling corporate data stolen from multiple companies. They are acting as an initial access broker (IAB) on the dark web. The hack occurred due to stolen credentials. ShareFile, Nextcloud, and OwnCloud were all victims of the attack. There were impacted organizations across many sectors, including aviation, defense, healthcare, utilities, mass transit, telecom, legal, real estate, and government.
Unknown
Highly sensitive corporate data, including health records and government contracts.
Stolen credentials and lack of multi-factor authentication
Source: Infostealers published a detailed analysis of the hacks.
Cloud exposure has been a risk component for many years. MFA has become mandatory in many regulations. Will this alone be enough to reduce unauthorized access? No, but enterprise-wide data encryption, redaction, and masking limit the fallout of such an attack.
Nike
ApparelOn January 24, Nike launched an investigation into a possible cyber attack. This action came after WorldLeaks claimed it had stolen and posted 1.4 terabytes of internal company data.
of company data
Product development intellectual property and supply chain logistics
Not defined, but threat intelligence firms have suggested a connection to supply chain infrastructure.
Source: The National CIO Review provided an extensive review of the attack and leak.
This data breach involves corporate data versus customer data. Investigators did not find personal identifiers. However, the leak of IP and other trade secrets could have been of value to competitors.
Organizations should enforce security controls and cybersecurity best practices with supply chain vendors. Additionally, security embedded into data follows it wherever it goes.
Crunchbase
Business dataCrunchbase confirmed a data breach in January after a hack. ShinyHunters, a cybercrime group, claimed responsibility. The company revealed there was file exfiltration but said there were no operational disruptions. The incident is still under investigation, and they have yet to send any notifications to customers.
records
PII and corporate data (e.g., contracts and internal documents)
Social engineering campaign using voice phishing techniques
Source: SecurityWeek was the first to report the story and received confirmation from Crunchbase.
Social engineering, especially deepfakes, is much more sophisticated than ever before. They are emerging as a key way for hackers to compromise credentials. While you can't eliminate all breach risk, you can take proactive steps to minimize the impact. Examples include:
- Identifying older files and enforcing data retention policies
- Using encryption mechanisms that stay with data
- Applying data discovery and classification solutions to build an inventory of sensitive information
Match Group
Dating appsThe family of Match dating apps finishes out the list of the major 2026 data breaches in January. ShinyHunters was also the cyber criminal in this case. The group claimed they have millions of documents, while Match called it a “security incident” that is still under investigation.
records
User and corporate data
According to ShinyHunters dark web leak site, it cited AppsFlyer as the entry point. AppsFlyer is a marketing analytics company for apps.
Source: The Register published a review of the breach and exposures.
It appears this is another third-party system failure. Data sharing for analytics is essential to any business but carries risk. Secure data exchange, internally or externally, with modern encryption allows for access while safeguarding data.