This website uses cookies

Read our Privacy policy and Terms of use for more information.

Sixteen breaches in one day's news is not a coincidence, it's a pattern. Third-party vendors keep being the way in: a logistics provider (CEVA) took down order systems at Pokémon Center, Bol, De Bijenkorf and Valve at once, and a support-ticket platform is how Ernst & Young lost tax documents. When one vendor gets popped, everyone downstream gets a breach notice.

ShinyHunters is having a very busy week. The group is claiming credit for RingCentral, DentaQuest, and EY, and between the DentaQuest haul alone, tens of millions of Social Security numbers and Medicaid records are now out there. Pair that with Anubis hitting Coca-Cola's Fairlife unit and PEAR dumping 3.3 terabytes from a medical billing firm, and it's clear extortion gangs are done asking nicely. They're leaking first and negotiating never.

The rest of the list is a reminder that basic hygiene still fails constantly: a hard-coded API key in South Korea, stolen employee credentials at Bank of Baroda and France's tax authority, social engineering at Apollo and RingCentral. None of these are exotic attacks. They're the same old doors left open, just at bigger companies with more sensitive data behind them.

Private equity firm Apollo has confirmed a cyberattack in which a threat actor used social engineering to gain access to its cloud environment between July 6 and July 10, 2026. The breach exposed names, dates of birth, contact information, home addresses, and Social Security numbers, though no financial account data was taken. Apollo is offering two years of free identity theft protection through Cyberscout, and the stolen data has not yet appeared on the dark web.

Healthcare technology company CareCloud has confirmed a data breach affecting more than 3.75 million people, up from the roughly 345,000 initially reported in an SEC filing back in March. An unauthorized third party accessed one of CareCloud's AWS environments between March 10 and 16, exfiltrating names, Social Security numbers, driver's license or passport numbers, medical records, health insurance information, and bank or credit card data, including CVV numbers, for some victims.

Pokémon Center has warned UK and German customers that a cyberattack on its logistics vendor, CEVA Logistics, beginning July 30, 2026, has disrupted order fulfillment and likely exposed names, addresses, phone numbers, emails, and order histories. Accounts and payment data remain unaffected. About a dozen organizations, including Bol, De Bijenkorf and Valve, have reported similar impacts from the CEVA breach, and no threat actor has claimed responsibility yet.

Business communications platform RingCentral suffered a breach in July that may have exposed personal data on 1.6 million people, the result of what the company called a "sophisticated social engineering campaign." The extortion group ShinyHunters claimed responsibility, listing RingCentral on its leak site and later publishing a 280GB archive after the company refused to pay; HaveIBeenPwned confirmed the leak includes roughly 1.6 million unique email addresses along with names, addresses, and phone numbers. RingCentral says only a limited set of customers was affected and has notified them directly, adding that its core platform was not disrupted.

Analog Devices, the semiconductor maker with roughly 24,500 employees and more than $11 billion in 2025 revenue, disclosed in an SEC filing that an unauthorized party accessed company systems and exfiltrated files on June 23. The company says business operations were not disrupted and it does not expect material financial impact, though it has not detailed what data was stolen. The disclosure follows claims from extortion group ExfilSquad, which briefly listed Analog Devices on its leak site before removing the entry; it remains unclear whether that intrusion is linked to the breach reported to the SEC.

The extortion group ShinyHunters has claimed the Ernst & Young data breach disclosed earlier this month, in which attackers stole tax-related client documents—including names, addresses, Social Security numbers, and payment card data—from a third-party support ticket platform between March 28 and April 12. EY hasn't disclosed how many people were affected or confirmed the attacker's identity, but ShinyHunters has listed the firm on its leak site and threatened to release the stolen data if EY doesn't respond by July 31.

Medical billing firm Medical Computer Business Services, based in Augusta, Georgia, disclosed that a network breach between September 22 and 26, 2025, exposed data on 1,261,464 people, including Social Security numbers, health insurance details, and medical treatment information. The ransomware group PEAR has claimed responsibility, saying it stole 3.3 terabytes of data covering seven healthcare clients, and has posted the full cache online, though its authenticity hasn't been verified.

DentaQuest, the largest Medicaid and CHIP dental benefits administrator in the U.S., is notifying more than 23 million people after hackers accessed its network between May 17 and 20, 2026, exposing names, Social Security numbers, Medicaid/Medicare IDs, and dental health records. The ShinyHunters extortion group claimed responsibility, saying it stole 234 GB of data and leaked it after ransom talks failed; researchers found 2.6 million unique email addresses and over 1.7 million Social Security numbers, many reportedly belonging to Texas children.

Coca-Cola confirmed that a ransomware attack on its dairy subsidiary Fairlife led to a data breach involving the theft of unspecified data. The Anubis ransomware group, active since December 2024 and linked to roughly 100 victims, claimed to have stolen 1 TB of confidential data and threatened to publish it unless paid. Coca-Cola said most Fairlife production has resumed at its four US facilities and that the incident is not expected to have a material financial impact.

Quick Hits

Reply

Avatar

or to participate