A South Carolina loan company disclosed a data breach that exposed the financial information and Social Security numbers of nearly 750,000 people. According to reporting, the breach affects anyone who received a loan through the company or who inquired about a loan product through a third party, meaning the exposure reaches beyond direct customers. Social Security numbers combined with financial details are among the most useful data for identity theft and fraud, and such records frequently end up for sale on criminal marketplaces. Lending and debt-related companies remain a favored target because they concentrate exactly this kind of sensitive financial and identity data.
Cryptocurrency wallet maker SafePal disclosed that an authorization flaw in a third-party order-tracking plug-in exposed personal data of about 39,798 customers, and a threat actor is now selling it. The flaw worked like a parcel tracker that lets one customer see another's order simply by changing the order number, exposing names, email addresses, shipping addresses, phone numbers, and purchase details for orders placed between March 2025 and April 2026. Seed phrases, private keys, wallet passwords, and payment data were not affected. SafePal warned customers to expect phishing and impersonation, and noted that a fake firmware-update lure had already been seen. It has taken down more than 30 fraudulent sites.
Hardware wallet maker Trezor said a breach at its shipping provider ShipMonk exposed personal data of nearly 14,000 customers who ordered devices between May and early August. About 11,700 had full details exposed, including name, email, phone number, and shipping address, while roughly 1,900 had partial data taken. Trezor stressed that its own systems were not compromised and its devices remain secure, but warned customers to expect phishing. Exposed home addresses tied to cryptocurrency ownership carry an added risk, as physical attacks on crypto holders have risen this year. The company said it is introducing an anonymous delivery option in response.
Valve is notifying European Steam hardware customers that their personal data was likely exposed in a cyberattack on CEVA Logistics, the partner that ships Steam devices in the region. Attackers had access to CEVA systems between July 29 and August 1, reaching the delivery details CEVA keeps for up to ninety days: name, street address, postal code, city, country, phone number, the email tied to the Steam account, and the hardware ordered and its price. No Steam passwords, Steam Guard codes, or payment data were exposed, since CEVA never held them. Valve warned customers to expect phishing and delivery-impersonation scams and to treat such messages as fake.
Data from a breach at cancer-screening company Exact Sciences, now part of Abbott, was indexed by Have I Been Pwned with about 10.9 million unique email addresses. The extortion group ShinyHunters claimed the intrusion, saying it reached internal legacy systems and then pivoted from a corporate single-sign-on account into connected cloud services such as Microsoft 365, Salesforce, and others to steal data. It is part of a wider ShinyHunters wave hitting medical-technology companies. Abbott is investigating and disputed the attacker's characterization of some data. The pattern, one stolen sign-on unlocking many linked services, is now a recurring route to large healthcare breaches.
A data-leak forum listing is advertising an alleged dataset from Polish convenience-store chain Żabka for 5,000 euros, claiming roughly 541,000 Jira issues, about 230,000 IT service-desk tickets, and source code from 89 GitLab repositories. The post names real internal systems, including the chain's point-of-sale platform and SAP environment, and more than 20 outside vendors. A reviewer of the sample archive found the counts internally consistent and noted that a single GitLab access token appears across all 89 repository dumps, pointing to reused credentials rather than a code flaw. Żabka has not confirmed the breach, and the seller's account has no trading history.
Biotechnology company Amgen disclosed that attackers stole patient and corporate data from multiple cloud systems run by third-party providers, rather than from its own servers. In a securities filing, Amgen said it detected the intrusion in July, confirmed data was exfiltrated, and determined the incident material based on the volume and sensitivity of affected files. Confirmed stolen data includes proprietary company information and patient protected health information, and the company is still assessing whether intellectual property, research and development data, and further patient records were taken. Operations, product supply, and financial systems were not disrupted. Amgen has not named a provider, entry point, or responsible party.
Analog Devices, a major US semiconductor maker, confirmed in a securities filing that an unauthorized party accessed some internal systems and exfiltrated files in a June intrusion, while saying operations were not affected. The company has not named who was responsible. Days before the filing, an extortion group calling itself ExfilSquad listed Analog Devices on its leak site and claimed to hold about 570,000 customer records with personal information and home addresses, but Analog Devices has not linked the June breach to that group, and the claim is unverified. The filing also noted a second, separate security issue unrelated to the June intrusion.
A breach at SplitVPN, a service formerly called NotVPN that marketed itself as keeping no logs, exposed a 17GB database containing roughly 58 million connection logs. The logs record which device connected to which server and when, running continuously up to the day of the breach, directly contradicting the no-logs promise. Cross-referenced with user and device tables holding emails, last-seen IP addresses, and hardware identifiers, they can reconstruct who connected from where and when for tens of millions of people. The data also includes about 23 million user records and 2.6 million payment records with masked card details. Operator account hashes were exposed too.
Dental benefits administrator DentaQuest, part of Sun Life, is notifying more than 23 million people that their personal and health information was stolen in a May 2026 network intrusion. The company found unauthorized access on May 20 and determined attackers were in its network between May 17 and 20. Exposed data includes names, addresses, Social Security numbers, member, Medicaid, and Medicare identifiers, and dental and vision health details such as diagnoses, treatments, and billing. The extortion group ShinyHunters claimed responsibility and leaked roughly 234GB. DentaQuest has confirmed at least 15 million affected, with independent analysis putting the figure above 23 million, and is offering two years of monitoring.