Data theft is the story today, not ransomware for once. ShinyHunters walked away with 12.9 million Carhartt accounts after the company refused to pay $3.3 million, and the group leaked the whole 50GB haul anyway, employee inboxes included. That's the pattern worth watching: attackers grab the data, ask for money, and dump it regardless of what happens next.
Two healthcare and cultural institutions are learning the same lesson on a slower timeline. Nutex Health is still figuring out what was taken from its network days after disclosing the breach to the SEC, and LACMA just told people that a breach detected back in July 2025 wasn't fully understood until this year. Both cases show how long "we're still investigating" can drag on, and how much personal data — medical records, Social Security numbers, financial details — sits exposed in the meantime.
Then there's Merrimack County, New Hampshire, where a security incident knocked police dispatchers off state criminal databases, cutting nearly 20 agencies off from driving records and warrant checks. No breach confirmed yet, no cause given, but it's a reminder that these incidents don't just mean stolen data. Sometimes they mean the systems police rely on stop working.

