Last updated: August 19, 2026 at 1:47 AM UTC
All 741 Vulnerability 286 Breach 129 Threat 319 Defense 7
Tag: data-breach (42 articles)Clear

South Carolina loan company breach exposes Social Security numbers of 750,000

A South Carolina loan company disclosed a data breach that exposed the financial information and Social Security numbers of nearly 750,000 people. According to reporting, the breach affects anyone who received a loan through the company or who inquired about a loan product through a third party, meaning the exposure reaches beyond direct customers. Social Security numbers combined with financial details are among the most useful data for identity theft and fraud, and such records frequently end up for sale on criminal marketplaces. Lending and debt-related companies remain a favored target because they concentrate exactly this kind of sensitive financial and identity data.

Check
Anyone who took out or inquired about a loan through the affected company should watch for identity-theft signs, consider a credit freeze, and beware fraud referencing their financial details.
Affected
Nearly 750,000 people who obtained or inquired about a loan through the company, including via third parties; their Social Security numbers and financial information were exposed, raising identity-theft risk.
Fix
Affected people should freeze credit and monitor accounts; organizations holding financial and identity data should minimize what they retain, control access tightly, and extend protections to third-party partners.

SafePal order-tracking flaw exposed data of nearly 40,000 wallet buyers

Cryptocurrency wallet maker SafePal disclosed that an authorization flaw in a third-party order-tracking plug-in exposed personal data of about 39,798 customers, and a threat actor is now selling it. The flaw worked like a parcel tracker that lets one customer see another's order simply by changing the order number, exposing names, email addresses, shipping addresses, phone numbers, and purchase details for orders placed between March 2025 and April 2026. Seed phrases, private keys, wallet passwords, and payment data were not affected. SafePal warned customers to expect phishing and impersonation, and noted that a fake firmware-update lure had already been seen. It has taken down more than 30 fraudulent sites.

Check
Affected SafePal customers should be alert to phishing and calls impersonating the company, never enter a seed phrase or approve a firmware update prompted by an unsolicited message, and verify notices independently.
Affected
About 39,798 SafePal customers whose names, emails, phone numbers, and shipping addresses were exposed; wallets and keys are safe, but the data supports convincing phishing, including fake firmware-update scams already observed.
Fix
Anyone who shared a seed phrase or keys through a scam should move funds to a new wallet now; organizations should audit third-party plug-ins for authorization flaws limiting customer data.

Chipmaker Analog Devices confirms a breach and stolen files, says operations are fine

Analog Devices, a major US semiconductor maker, confirmed in a securities filing that an unauthorized party accessed some internal systems and exfiltrated files in a June intrusion, while saying operations were not affected. The company has not named who was responsible. Days before the filing, an extortion group calling itself ExfilSquad listed Analog Devices on its leak site and claimed to hold about 570,000 customer records with personal information and home addresses, but Analog Devices has not linked the June breach to that group, and the claim is unverified. The filing also noted a second, separate security issue unrelated to the June intrusion.

Check
Organizations that share data with Analog Devices should watch for a notification and monitor for phishing, while treating the extortion group's specific claims as unverified until the company confirms details.
Affected
Analog Devices and parties whose data sat in its systems; the company confirms files were stolen in June, while an extortion group's claim of 570,000 customer records with home addresses remains unverified.
Fix
Affected parties should watch for official notice and be alert to targeted phishing. Organizations should segment sensitive data, limit what vendors can reach, and prepare for extortion-driven leaks and unverified claims.

No-logs VPN breach exposes 58 million connection logs it promised not to keep

A breach at SplitVPN, a service formerly called NotVPN that marketed itself as keeping no logs, exposed a 17GB database containing roughly 58 million connection logs. The logs record which device connected to which server and when, running continuously up to the day of the breach, directly contradicting the no-logs promise. Cross-referenced with user and device tables holding emails, last-seen IP addresses, and hardware identifiers, they can reconstruct who connected from where and when for tens of millions of people. The data also includes about 23 million user records and 2.6 million payment records with masked card details. Operator account hashes were exposed too.

Check
SplitVPN or NotVPN users should assume their connection history and account details are exposed, change reused passwords, and watch for phishing and extortion referencing their VPN use.
Affected
Tens of millions of SplitVPN users whose connection logs, emails, IP addresses, device identifiers, and masked payment details were exposed, despite the service's advertised no-logs policy, enabling activity reconstruction and targeted fraud.
Fix
Treat no-logs claims as unverifiable marketing rather than a guarantee, prefer providers with independent audits or verifiable architectures, and where anonymity matters, avoid a single centralized intermediary that decides what to log.

DentaQuest notifies more than 23 million people after a data theft attack

Dental benefits administrator DentaQuest, part of Sun Life, is notifying more than 23 million people that their personal and health information was stolen in a May 2026 network intrusion. The company found unauthorized access on May 20 and determined attackers were in its network between May 17 and 20. Exposed data includes names, addresses, Social Security numbers, member, Medicaid, and Medicare identifiers, and dental and vision health details such as diagnoses, treatments, and billing. The extortion group ShinyHunters claimed responsibility and leaked roughly 234GB. DentaQuest has confirmed at least 15 million affected, with independent analysis putting the figure above 23 million, and is offering two years of monitoring.

Check
People with DentaQuest or associated Medicaid or Medicare dental coverage should watch for a notification, enroll in the offered monitoring, consider a credit freeze, and be alert to health-themed phishing.
Affected
More than 23 million DentaQuest members whose names, Social Security numbers, government program identifiers, and dental and vision health records were exposed and leaked, supporting identity theft and targeted fraud.
Fix
Affected people should freeze credit and monitor benefits statements. Organizations holding health data should segment it, enforce phishing-resistant MFA, monitor for bulk data access, and prepare for extortion-driven leaks.

Suno breach exposes 55 million accounts eight months after a developer was compromised

Data from a November 2025 breach at AI music platform Suno surfaced publicly in July, with Have I Been Pwned indexing 55,282,226 unique email addresses. Alongside the addresses, the corpus held names, phone numbers, physical addresses, and purchase records, plus tens of thousands of Stripe entries containing partial card data: card type, expiry date, and the last four digits. Reporting indicates the intrusion started with malware delivered through third-party code on a developer's machine, which yielded credentials for private repositories and internal databases. Suno has said no sensitive personal information was compromised and has not notified affected users.

Check
Suno users should check Have I Been Pwned, change the password there and anywhere it was reused, and be alert to phishing that references their account or past purchases.
Affected
Roughly 55 million Suno users whose email addresses, names, phone numbers, physical addresses, and purchase records were exposed, with partial card data for a subset; most have not been notified.
Fix
Use unique passwords and enable multi-factor authentication where offered. Organizations should treat developer workstations as high value targets, since third-party code running there can hand over repository and database access.

Estée Lauder says attackers took personal data from its Oracle HR system

Estée Lauder is notifying people that personal information was stolen after attackers reached the Oracle E-Business Suite environment it uses for human resources. The company says an unauthorized third party gained access on or around August 9, 2025, and that it confirmed on June 19, 2026 that personal information had been taken, a gap of more than ten months between intrusion and confirmation. The notice does not name the vulnerability exploited, though the timing lines up with the mass exploitation campaign against Oracle E-Business Suite that ran through last year. Affected people are being offered two years of identity monitoring.

Check
Organizations running Oracle E-Business Suite should confirm the environment is patched against last year's exploited flaws and review access logs from that period, since intrusions there went undetected for months.
Affected
People whose personal information sat in Estée Lauder's Oracle E-Business Suite human resources environment; the data was taken in 2025 and only confirmed in June 2026, leaving a long window for misuse.
Fix
Affected people should enroll in the offered monitoring and consider a credit freeze. Organizations should patch and segment enterprise resource platforms, limit the personal data they hold, and monitor for unusual access.

Glendale College breach exposes data on 793,000 students and applicants

Glendale Community College has had data on roughly 793,000 people exposed after the extortion group ShinyHunters stole files from its student information systems. Have I Been Pwned indexed 793,925 accounts, and the attackers claim to have taken more than 62GB across roughly 304,000 files, including student records with personal identifiers, financial aid exports, immunization logs, admission checklists, and transcripts dating back to 2020. The theft came from the college's PeopleSoft Campus Solutions environment, tying it to the wider ShinyHunters campaign against Oracle PeopleSoft that has hit numerous universities and companies. The breadth of academic and personal data raises the risk of identity theft and targeted phishing against students, applicants, and staff.

Check
People connected to Glendale Community College as students, applicants, or staff should watch for a breach notice, check Have I Been Pwned, monitor financial accounts, and be alert to college-themed phishing.
Affected
Around 793,000 Glendale Community College students, applicants, and staff whose personal, academic, financial aid, and health-related records were exposed; the depth of data supports identity theft and convincing targeted phishing.
Fix
Affected people should consider a credit freeze and monitor accounts. Organizations using Oracle PeopleSoft should apply its mitigations, review access logs, and enforce phishing-resistant MFA against this ongoing campaign.

AssuranceAmerica breach exposes driver's license data of 6.9 million people

US auto insurer AssuranceAmerica has confirmed a breach affecting nearly 6.9 million people, the largest known exposure of Americans' driver's license data this year. The company detected the intrusion on March 17 after attackers compromised a single employee's credentials the day before and copied data files, but a lengthy review of the files was not finished until June 15, delaying notifications until now. The stolen data includes names, contact details, driver's license numbers, auto insurance policy and claims information, and, for some people, Social Security numbers. AssuranceAmerica has not detailed how the employee's credentials were taken, though such incidents are often tied to phishing or credential-stealing malware.

Check
People insured by AssuranceAmerica should watch for a breach notification, monitor bank and credit accounts and credit reports for fraud, and be wary of messages referencing their policy or claims.
Affected
Roughly 6.9 million AssuranceAmerica customers whose driver's license numbers, contact details, and insurance information were exposed, along with Social Security numbers for some; the data enables identity theft and convincing targeted phishing.
Fix
Affected people should consider a credit freeze given exposed license and Social Security numbers, monitor financial accounts, and treat insurance-themed messages cautiously. Organizations should enforce phishing-resistant MFA on employee accounts.

Accenture confirms breach as attacker offers source code and keys for sale

Accenture, one of the world's largest IT consulting firms, has confirmed a data breach after a threat actor advertised stolen data for sale on a hacking forum. The seller claims to have taken about 35GB of source code along with RSA keys, SSH keys, Azure access tokens and storage keys, and configuration files, and shared a screenshot appearing to show them cloning an internal Azure DevOps repository. Accenture confirmed the breach but did not comment on the amount or type of data involved. If the stolen keys and tokens are valid, they could give attackers a path into Accenture's development systems or cloud infrastructure.

Check
Organizations that work with Accenture or share infrastructure with vendors should watch for supplier notifications, and check how their own source code, keys, and cloud tokens are stored and rotated.
Affected
Accenture and, potentially, its clients; stolen source code, SSH and RSA keys, and Azure tokens could let attackers reach development systems or cloud infrastructure if the credentials are still valid.
Fix
Rotate any exposed keys and tokens, keep secrets out of source code and repositories, enforce short-lived credentials and least privilege for cloud and DevOps access, and monitor development systems for unauthorized use.