The extortion group ShinyHunters claimed on its dark web site that it breached the FBI and stole data on current and former employees and job applicants, naming Criminal Justice, HR, and Medlink services. A spokesperson told The Register the group exploited a new Oracle PeopleSoft zero-day to gain remote code execution and deface the FBI jobs site. The claim, first reported by 404 Media, is unverified, and the FBI has not confirmed any compromise. ShinyHunters framed it as retaliation for a May FBI advisory about its Canvas targeting, disputing those allegations and rejecting reported ties to the wider criminal collective. Treat the specifics as an attacker claim pending independent confirmation.
Texas utility CenterPoint Energy confirmed that an unauthorized party obtained customer personal information through an external-facing system. A threat actor claimed on a cybercrime forum to have pulled about 7.49 million records, including names, addresses, account and billing details, and partial Social Security numbers, through a company API that lacked authentication, rate limiting, and web-application-firewall protection. CenterPoint confirmed the incident in a regulatory filing but not the record count, and said energy services were unaffected. It is a textbook example of an exposed API being scraped at scale: without authentication and throttling, a public endpoint hands attackers a bulk export of customer data. The investigation is ongoing.
Identity-verification company IDScan confirmed that attackers accessed customer data in its cloud, behind a dark-web marketplace offering scans of more than 153 million US and Canadian driver's licenses, plus names and government-ID numbers. IDScan authenticates government IDs for businesses ranging from banks to car-rental agencies to cannabis and gun retailers, which makes it an aggregator of everyone's identity documents and a single point of mass failure. Investigative journalist Brian Krebs traced the marketplace back to IDScan by matching document scans to occasions when IDs were presented. The FBI is investigating and lawsuits have been filed. Because these are scanned government IDs, victims cannot simply rotate a leaked driver's license.
Aesto Health, a healthcare technology company that handles data migration, records exchange, and archiving for medical providers, disclosed that a breach of its Amazon Web Services infrastructure exposed the personal and health information of more than 9.5 million people. Attackers accessed the environment in December 2025, and the company later confirmed they took names, Social Security and driver's license numbers, dates of birth, financial account numbers, and detailed medical and insurance information. Because Aesto is a vendor serving many providers, the single breach cascades to roughly two dozen healthcare clients. It is the second-largest confirmed US healthcare breach reported this year, and the data enables identity theft and targeted fraud.
The extortion group ShinyHunters published data stolen from workwear maker Carhartt after the company refused a 3.3 million dollar ransom, but analysis showed the leak was smaller than it first appeared. The raw dump held nearly 25 million email addresses, yet breach-tracking service Have I Been Pwned found millions were synthetic records that matched no real people, leaving about 12.9 million genuine addresses along with names, phone numbers, and physical addresses. A researcher traced the data to Carhartt's customer analytics warehouse, contaminated with a standard retail benchmarking dataset used for testing. The detailed contact and identity profiles still create real risk of targeted phishing for those affected.
A South Carolina loan company disclosed a data breach that exposed the financial information and Social Security numbers of nearly 750,000 people. According to reporting, the breach affects anyone who received a loan through the company or who inquired about a loan product through a third party, meaning the exposure reaches beyond direct customers. Social Security numbers combined with financial details are among the most useful data for identity theft and fraud, and such records frequently end up for sale on criminal marketplaces. Lending and debt-related companies remain a favored target because they concentrate exactly this kind of sensitive financial and identity data.
Cryptocurrency wallet maker SafePal disclosed that an authorization flaw in a third-party order-tracking plug-in exposed personal data of about 39,798 customers, and a threat actor is now selling it. The flaw worked like a parcel tracker that lets one customer see another's order simply by changing the order number, exposing names, email addresses, shipping addresses, phone numbers, and purchase details for orders placed between March 2025 and April 2026. Seed phrases, private keys, wallet passwords, and payment data were not affected. SafePal warned customers to expect phishing and impersonation, and noted that a fake firmware-update lure had already been seen. It has taken down more than 30 fraudulent sites.
Analog Devices, a major US semiconductor maker, confirmed in a securities filing that an unauthorized party accessed some internal systems and exfiltrated files in a June intrusion, while saying operations were not affected. The company has not named who was responsible. Days before the filing, an extortion group calling itself ExfilSquad listed Analog Devices on its leak site and claimed to hold about 570,000 customer records with personal information and home addresses, but Analog Devices has not linked the June breach to that group, and the claim is unverified. The filing also noted a second, separate security issue unrelated to the June intrusion.
A breach at SplitVPN, a service formerly called NotVPN that marketed itself as keeping no logs, exposed a 17GB database containing roughly 58 million connection logs. The logs record which device connected to which server and when, running continuously up to the day of the breach, directly contradicting the no-logs promise. Cross-referenced with user and device tables holding emails, last-seen IP addresses, and hardware identifiers, they can reconstruct who connected from where and when for tens of millions of people. The data also includes about 23 million user records and 2.6 million payment records with masked card details. Operator account hashes were exposed too.
Dental benefits administrator DentaQuest, part of Sun Life, is notifying more than 23 million people that their personal and health information was stolen in a May 2026 network intrusion. The company found unauthorized access on May 20 and determined attackers were in its network between May 17 and 20. Exposed data includes names, addresses, Social Security numbers, member, Medicaid, and Medicare identifiers, and dental and vision health details such as diagnoses, treatments, and billing. The extortion group ShinyHunters claimed responsibility and leaked roughly 234GB. DentaQuest has confirmed at least 15 million affected, with independent analysis putting the figure above 23 million, and is offering two years of monitoring.