DATA BREACHES

Data Breaches

When companies leak your personal data — names, SSNs, passwords, health records. Who got hit and what to do right now.

22 posts published
DATA BREACHESPRIVACYAI THREATSVULNERABILITIESSCAMS
153 Million Driver's Licenses Are Being Sold on the Dark Web Right Now
BREACH5 min read

153 Million Driver's Licenses Are Being Sold on the Dark Web Right Now

153 million driver's license scans showed up for sale on the dark web. If you've ever rented a car, visited a FedEx store, or stepped into a dispensary, yours could be in the pile.

2026-09-08T08:03:13.929805+00:00READ →
Hasbro Kept Quiet for 5 Months While Hackers Had Workers' SSNs and Bank Info
BREACH5 min read

Hasbro Kept Quiet for 5 Months While Hackers Had Workers' SSNs and Bank Info

Hasbro's March cyberattack exposed employees' SSNs, bank accounts, and card numbers — and the company waited five months before telling them.

2026-09-05T08:04:13.891376+00:00READ →
Your Hospital Records Could Go Public: Ransomware Gang Hit 27 US Facilities
BREACH5 min read

Your Hospital Records Could Go Public: Ransomware Gang Hit 27 US Facilities

The Gentlemen ransomware group stole patient files and financial data from Nutex Health's 27 US micro-hospitals and is threatening to publish everything.

2026-09-03T08:04:32.922878+00:00READ →
Your Doctor Used This Company to Store Your Records. Hackers Took 9.5 Million of Them.
BREACH5 min read

Your Doctor Used This Company to Store Your Records. Hackers Took 9.5 Million of Them.

A healthcare data company you've never heard of stored your medical records — and hackers quietly stole 9.5 million of them last December.

2026-09-02T08:09:38.315513+00:00READ →
284 Million Health Records Stolen From the Company Behind Your Pharmacy
BREACH4 min read

284 Million Health Records Stolen From the Company Behind Your Pharmacy

Hackers claim to have stolen 284 million patient records from McKesson, a healthcare giant most people have never heard of but whose systems touch almost every American prescription.

2026-09-01T08:05:11.870373+00:00READ →
Carhartt Said No to a $3.3M Ransom. Now 12.9 Million Shoppers' Data Is Online
BREACH5 min read

Carhartt Said No to a $3.3M Ransom. Now 12.9 Million Shoppers' Data Is Online

ShinyHunters hackers leaked names, emails, and home addresses of 12.9M Carhartt customers after the brand refused to pay a $3.3M ransom. Here's what to do.

2026-08-30T08:03:15.707324+00:00READ →
The Company That Keeps Your Heart Beating Was Just Hacked
BREACH4 min read

The Company That Keeps Your Heart Beating Was Just Hacked

A cyberattack knocked out Boston Scientific's global systems on August 25, halting pacemaker and cardiac device shipments to hospitals worldwide.

2026-08-29T08:03:28.737523+00:00READ →
Free Airport WiFi Put 8.7 Million Travelers at Risk After Hackers Stole Their Personal Data
BREACH5 min read

Free Airport WiFi Put 8.7 Million Travelers at Risk After Hackers Stole Their Personal Data

Signing up for free WiFi at Manchester, Stansted, or East Midlands airports? Hackers may now have your phone number, email, and home postcode.

2026-08-28T08:03:07.836776+00:00READ →
If You Bought a SafePal Crypto Wallet, Hackers Now Know Where You Live
BREACH5 min read

If You Bought a SafePal Crypto Wallet, Hackers Now Know Where You Live

A flaw in SafePal's order system exposed 39,798 buyers' names, home addresses, and phone numbers — exactly what criminals need to rob crypto holders in person.

2026-08-27T08:02:34.414958+00:00READ →
Your SSN Was Inside a $1 Trillion Firm. Hackers Got It With a Phone Call.
BREACH5 min read

Your SSN Was Inside a $1 Trillion Firm. Hackers Got It With a Phone Call.

Apollo Global Management — a $1 trillion Wall Street giant — exposed Social Security numbers and home addresses after hackers tricked employees over the phone.

2026-08-26T08:02:31.822854+00:00READ →
3.7 Million Patients Had Their SSNs and Medical Records Stolen from a Health Software Company
BREACH5 min read

3.7 Million Patients Had Their SSNs and Medical Records Stolen from a Health Software Company

Your doctor may use CareCloud software. 3.7 million patients just learned hackers stole their SSNs, medical records, and bank details from it back in March.

2026-08-25T08:02:13.996325+00:00READ →
Hackers Tricked 1 Employee by Phone and Exposed 1.6 Million People's Contact Details
BREACH4 min read

Hackers Tricked 1 Employee by Phone and Exposed 1.6 Million People's Contact Details

ShinyHunters called one RingCentral employee, talked their way in, and dumped 1.6 million users' names, addresses, and phone numbers online.

2026-08-23T08:03:00.087105+00:00READ →
Hackers Got Your Home Address by Breaching the Shipping Company Behind Steam and ING
BREACH5 min read

Hackers Got Your Home Address by Breaching the Shipping Company Behind Steam and ING

A hack at shipping giant CEVA Logistics exposed names, home addresses, and order details for customers of Steam, ING Bank, and major retailers across Europe.

2026-08-19T08:17:25.120489+00:00READ →
France's Tax Authority Hacked: 678,000 Taxpayers' Financial Data Stolen
BREACH5 min read

France's Tax Authority Hacked: 678,000 Taxpayers' Financial Data Stolen

A hacker stole income and property records from France's tax authority using one stolen password — exposing 678,000 people's financial lives.

2026-08-18T08:01:58.565359+00:00READ →
Healthcare Billing Giant Hacked: 3.8 Million Patients' SSNs and Medical Records Exposed
BREACH5 min read

Healthcare Billing Giant Hacked: 3.8 Million Patients' SSNs and Medical Records Exposed

A billing software vendor you've never heard of just exposed your SSN, diagnoses, and scanned ID — 3.8 million patients are at risk.

2026-08-17T21:44:41.427215+00:00READ →
Framework Laptop Breach: Hackers Stole Customer Data Through a Vendor's Zero-Day
BREACH5 min read

Framework Laptop Breach: Hackers Stole Customer Data Through a Vendor's Zero-Day

Framework, the maker of repairable laptops, told every customer their name, email, phone, and address were stolen after hackers exploited a zero-day in a data-analytics vendor it uses.

2026-08-16T08:02:50.763827+00:00READ →
Trezor Customer Data Exposed After Shipping Partner Breach — Here's What to Watch For
BREACH5 min read

Trezor Customer Data Exposed After Shipping Partner Breach — Here's What to Watch For

A breach at Trezor's shipping provider exposed the names, addresses, and contact details of nearly 14,000 hardware wallet customers, opening the door to targeted phishing.

2026-08-15T16:50:11.156698+00:00READ →
Hackers Breached the Swiss Government's SharePoint Servers — Here's What Happened
BREACH5 min read

Hackers Breached the Swiss Government's SharePoint Servers — Here's What Happened

Attackers exploited two Microsoft SharePoint flaws to steal login credentials for roughly 200 Swiss federal accounts. No confirmed data leak — but the technique used to keep access even after patching is the real lesson.

2026-08-15T12:50:57.155051+00:00READ →
What To Do Immediately After a Data Breach (2026 Guide)
BREACH6 min read

What To Do Immediately After a Data Breach (2026 Guide)

Got a breach notification email? The first 48 hours matter most — and almost everything that protects you is free. Here's exactly what to do, in order.

2026-06-18T09:00:00+00:00READ →
Iran-linked Hackers Breach California Water Utility, Exposing 2 Million Customers
BREACH4 min read

Iran-linked Hackers Breach California Water Utility, Exposing 2 Million Customers

An Iran-linked group breached Cal Water, potentially exposing your billing details and personal information to two million customers.

2026-06-17T08:02:44.141562+00:00READ →
Hackers Stole 1.8 Million People's Fingerprints From a Hospital. You Can't Change Your Fingerprints.
BREACH5 min read

Hackers Stole 1.8 Million People's Fingerprints From a Hospital. You Can't Change Your Fingerprints.

NYC Health + Hospitals confirmed hackers accessed the biometric data, medical records, SSNs, and bank details of 1.8 million patients. Unlike a password, your fingerprints are permanent.

2026-06-06T14:00:46.16698+00:00READ →
How the Canvas LMS Breach Exposed 275 Million Students
BREACH6 min read

How the Canvas LMS Breach Exposed 275 Million Students

ShinyHunters breached Canvas LMS in May 2026, stealing data on 275 million students and educators. Here's exactly what was taken and what to do right now.

2026-06-06T14:00:45.865396+00:00READ →
// FAQ

Data Breach Questions Answered

What is a data breach and how does it happen?

A data breach occurs when unauthorised individuals access, copy, or expose personal information stored by a company. Common causes include phishing attacks on employees, unpatched software vulnerabilities, weak or reused passwords, insider threats, and misconfigured cloud storage. Once inside, attackers typically spend weeks quietly harvesting data before detection.

What should I do immediately after a data breach affects me?

Change your password for the affected service and any other account where you reused that password. Enable two-factor authentication. Monitor your bank and credit card statements for unusual activity. Consider placing a free credit freeze with Equifax, Experian, and TransUnion. If your Social Security number was exposed, file an identity theft report at IdentityTheft.gov.

How long do companies have to notify me after a data breach?

In the US, notification timelines vary by state — typically 30 to 90 days after a breach is confirmed. Under GDPR in Europe, companies must notify regulators within 72 hours. Many states require individual notification "in the most expedient time possible." Companies often delay notification while investigating, so public reports sometimes come before individual emails.

Should I freeze my credit after a data breach?

Yes. A credit freeze (also called a security freeze) prevents new accounts from being opened in your name without your explicit unfreeze. It is completely free at all three major bureaus, does not affect your credit score, and does not impact existing accounts or credit cards. Unfreeze temporarily when you need to apply for credit, then refreeze immediately.

How do I check if my email was included in a data breach?

Visit HaveIBeenPwned.com (run by security researcher Troy Hunt) and enter your email address. It cross-references your email against hundreds of known breach databases. If you appear in results, it shows which breaches and what data was exposed. Set up free alerts to be notified of future breaches involving your email.

← ALL POSTS