A South Carolina loan company disclosed a data breach that exposed the financial information and Social Security numbers of nearly 750,000 people. According to reporting, the breach affects anyone who received a loan through the company or who inquired about a loan product through a third party, meaning the exposure reaches beyond direct customers. Social Security numbers combined with financial details are among the most useful data for identity theft and fraud, and such records frequently end up for sale on criminal marketplaces. Lending and debt-related companies remain a favored target because they concentrate exactly this kind of sensitive financial and identity data.
Cryptocurrency wallet maker SafePal disclosed that an authorization flaw in a third-party order-tracking plug-in exposed personal data of about 39,798 customers, and a threat actor is now selling it. The flaw worked like a parcel tracker that lets one customer see another's order simply by changing the order number, exposing names, email addresses, shipping addresses, phone numbers, and purchase details for orders placed between March 2025 and April 2026. Seed phrases, private keys, wallet passwords, and payment data were not affected. SafePal warned customers to expect phishing and impersonation, and noted that a fake firmware-update lure had already been seen. It has taken down more than 30 fraudulent sites.
Analog Devices, a major US semiconductor maker, confirmed in a securities filing that an unauthorized party accessed some internal systems and exfiltrated files in a June intrusion, while saying operations were not affected. The company has not named who was responsible. Days before the filing, an extortion group calling itself ExfilSquad listed Analog Devices on its leak site and claimed to hold about 570,000 customer records with personal information and home addresses, but Analog Devices has not linked the June breach to that group, and the claim is unverified. The filing also noted a second, separate security issue unrelated to the June intrusion.
A breach at SplitVPN, a service formerly called NotVPN that marketed itself as keeping no logs, exposed a 17GB database containing roughly 58 million connection logs. The logs record which device connected to which server and when, running continuously up to the day of the breach, directly contradicting the no-logs promise. Cross-referenced with user and device tables holding emails, last-seen IP addresses, and hardware identifiers, they can reconstruct who connected from where and when for tens of millions of people. The data also includes about 23 million user records and 2.6 million payment records with masked card details. Operator account hashes were exposed too.
Dental benefits administrator DentaQuest, part of Sun Life, is notifying more than 23 million people that their personal and health information was stolen in a May 2026 network intrusion. The company found unauthorized access on May 20 and determined attackers were in its network between May 17 and 20. Exposed data includes names, addresses, Social Security numbers, member, Medicaid, and Medicare identifiers, and dental and vision health details such as diagnoses, treatments, and billing. The extortion group ShinyHunters claimed responsibility and leaked roughly 234GB. DentaQuest has confirmed at least 15 million affected, with independent analysis putting the figure above 23 million, and is offering two years of monitoring.
Data from a November 2025 breach at AI music platform Suno surfaced publicly in July, with Have I Been Pwned indexing 55,282,226 unique email addresses. Alongside the addresses, the corpus held names, phone numbers, physical addresses, and purchase records, plus tens of thousands of Stripe entries containing partial card data: card type, expiry date, and the last four digits. Reporting indicates the intrusion started with malware delivered through third-party code on a developer's machine, which yielded credentials for private repositories and internal databases. Suno has said no sensitive personal information was compromised and has not notified affected users.
Estée Lauder is notifying people that personal information was stolen after attackers reached the Oracle E-Business Suite environment it uses for human resources. The company says an unauthorized third party gained access on or around August 9, 2025, and that it confirmed on June 19, 2026 that personal information had been taken, a gap of more than ten months between intrusion and confirmation. The notice does not name the vulnerability exploited, though the timing lines up with the mass exploitation campaign against Oracle E-Business Suite that ran through last year. Affected people are being offered two years of identity monitoring.
Glendale Community College has had data on roughly 793,000 people exposed after the extortion group ShinyHunters stole files from its student information systems. Have I Been Pwned indexed 793,925 accounts, and the attackers claim to have taken more than 62GB across roughly 304,000 files, including student records with personal identifiers, financial aid exports, immunization logs, admission checklists, and transcripts dating back to 2020. The theft came from the college's PeopleSoft Campus Solutions environment, tying it to the wider ShinyHunters campaign against Oracle PeopleSoft that has hit numerous universities and companies. The breadth of academic and personal data raises the risk of identity theft and targeted phishing against students, applicants, and staff.
US auto insurer AssuranceAmerica has confirmed a breach affecting nearly 6.9 million people, the largest known exposure of Americans' driver's license data this year. The company detected the intrusion on March 17 after attackers compromised a single employee's credentials the day before and copied data files, but a lengthy review of the files was not finished until June 15, delaying notifications until now. The stolen data includes names, contact details, driver's license numbers, auto insurance policy and claims information, and, for some people, Social Security numbers. AssuranceAmerica has not detailed how the employee's credentials were taken, though such incidents are often tied to phishing or credential-stealing malware.
Accenture, one of the world's largest IT consulting firms, has confirmed a data breach after a threat actor advertised stolen data for sale on a hacking forum. The seller claims to have taken about 35GB of source code along with RSA keys, SSH keys, Azure access tokens and storage keys, and configuration files, and shared a screenshot appearing to show them cloning an internal Azure DevOps repository. Accenture confirmed the breach but did not comment on the amount or type of data involved. If the stolen keys and tokens are valid, they could give attackers a path into Accenture's development systems or cloud infrastructure.