August 2026 Data Breaches (So far)

03 Aug 2026

Top data breaches of August 2026

Last month, we saw some of the most concerning cybersecurity incidents, including a cyber attack on Hugging Face that was fully orchestrated by OpenAI’s autonomous AI model without any human intervention. We also saw some of the known and reputed names, like Microsoft and Accenture, become victims of data breach.  

 

As cybercriminals continue to become unpredictable and persistent using AI and regulators raise their expectations, organizations face increased pressure to step up their resilience and improve compliance.

 

Let us look at some of the top data breaches of August 2026:

August latest data breach news

Let us look at some of the top data breaches of August 2026:

Victim: Berlin’s Senate network

About

The Senate of Berlin is an executive governing body of Berlin comprising the Governing Mayor and ten senators.

 

Industry

Public sector

 

What happened?

Berlin’s Senate network was hit by a ransomware attack carried out by the Rhysida ransomware group.

 

Impact

The group has claimed to have stolen 5.79 TB of data, including 46500 contracts, emails passwords, phone numbers, and other classified data.

Source

Victim: Manchester Airports Group (including Manchester, Stansted, and East Midlands airports)

About

The Manchester Airports Group Ltd. is a Manchester-based airport operator that was founded in 2001. It operates under ten borough councils and IFM investors and is the largest UK-owned airport operator.

 

Industry

Aviation

 

What happened?

The Manchester Airports Group Limited became a victim of a ransomware attack that was carried out by the FulcrumSec ransomware group.

 

Impact

The group has claimed to have stolen 86 GB of data, including 200000 records related to upcoming travel data, FastTrack purchase history, booking & scheduled arrival times, terminals, amounts paid, purchase references, and trip purposes.

Source

Victim: McKesson

About

McKesson is a Texas-based pharmaceutical company that was founded in 1833. It was the ninth-largest company by revenue in the U.S. and the largest healthcare company.

 

Industry

Healthcare/Pharmaceuticals

 

What happened?

McKesson disclosed that the ShinyHunters ransomware group gained unauthorized access to its third-party applications and data.

 

Impact

The ransomware group has claimed to have stolen 284 million patient records. The complete impact of the cyber incident is currently under investigation.

Source

Victim: Eastlink

About

Bragg Communications, or Eastlink, is a Nova Scotia-based telecommunications company that was founded in 1969. It is known for its high-speed internet, digital television, and cellular services.

 

Industry

Telecommunications

 

What happened?

On 28 August, Bragg Communications reported to its customers that it became a victim of a cyber attack.

 

Impact

The company has reported that the data breach has exposed the data of 75000 internet, television, and landline services accounts, including customer names, contact details, account numbers, and PINs.

Source

Victim: Merrimack County

About

Merrimack County is a New Hampshire county that offers multiple informational and online services to its residents.

 

Industry

Public sector

 

What happened?

On 20th August, Merrimack County became a target of a cyber attack that affected some of its systems.

 

Impact

The cyber attack disrupted the county’s police data access and property record processing and forced the county to take its systems offline.

Source

Victim: STC TV Saudi Arabia

About

STC TV is a digital entertainment streaming platform in Saudi Arabia that is known for offering movies, series, documentaries, and sports content. It also offers premium content with its local and international partners.

 

Industry

Telecommunication

 

What happened?

STC TV became a victim of a ransomware attack carried out by an unidentified cybercriminal.

 

Impact

The complete impact of the cyber attack is currently under investigation.

Source

Victim: Air Liquide Korea Co. Ltd.

About

Air Liquide is a South Korea-based provider of industrial gases and related services that was founded in 1996. It is a known provider in the petrochemical, steel, and home healthcare industries.

 

Industry

Oil and gas

 

What happened?

Air Liquide became a target of a ransomware attack that was carried out by the SafePay ransomware group.

 

Impact

The complete impact of the cyber attack is currently under investigation.

Source

Victim: Maritime Industry Authority

About

The Maritime Industry Authority (MARINA) is a Philippine government agency that develops, promotes, and regulates the country’s maritime industry.

 

Industry

Public sector

 

What happened?

The Maritime Industry Authority (MARINA)got hit by a ransomware attack.

 

Impact

The ransomware attack caused a nationwide shutdown of the Maritime Industry Authority’s seafarer documentation system (Seafarer’s Identity Document (SID) and Seafarer’s Record Book System (SRB).

Source

Victim: Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF)

About

The Bureau of Alcohol, Tobacco, Firearms, and Explosives is a federal law enforcement agency of the United States that was founded in 1972. It comes under the United States Department of Justice.

 

Industry

Public sector

 

What happened?

On 26 August, the Department of Justice reported that the ATF was hit by a ransomware attack.

 

Impact

The nature and quantity of data exposed and the full impact of the incident are currently under investigation.

Source

Victim: Sotheby’s International Realty

About

Sotheby’s International Realty is a New Zealand-based brokerage firm that was founded in 1976. It is known for its real estate services focused on luxury homes.

 

Industry

Real estate

 

What happened?

On 18 August, a hacker who goes by the name 2019 claimed to have stolen the company’s data.

 

Impact

The hacker has claimed to have stolen customer data, including names, email addresses, and physical addresses.

Source

Victim: Nutex Health

About

Nutex Health Inc. is a Texas-based healthcare company that offers its services via its Hospital and Population Health Management divisions.

 

Industry

Healthcare

 

What happened?

Nutex Health reported that an unauthorized third party exfiltrated information from its servers.

 

Impact

The nature and quantity of data exposed is currently under investigation.

Source

Victim: National Kidney Registry

About

The National Kidney Registry (NKR) is a Connecticut-based national registry of living kidney donors and recipients of kidney transplants. It was founded in 2007 and is known for its registry and facilitation of transplant processes.

 

Industry

Software and logistics

 

What happened?

National Kidney Registry became a target of a ransomware attack that was orchestrated by the Dire Wolf ransomware group.

 

Impact

The ransomware group has claimed to have stolen approximately 253 GB of data. The data exposed might contain patient- and donor-related data, including full names, medical and health-related information related to transplant status, and donor & recipient matching records.

Source

Victim: Boston Scientific

About

Boston Scientific Corporation (BSC) is a Massachusetts-based biotechnology and biomedical engineering firm that was founded in 1979. It is known for its Taxus Stent, which is used to open clogged arteries.

 

Industry

Medical device

 

What happened?

On 26 August, Boston Scientific reported that it was hit by a ransomware attack a week ago.

 

Impact

The cyber attack has disrupted the company’s access to company information systems and applications, including its shipment services. The complete impact of the cyber incident is currently under investigation.

Source

Victim: Gruppo Spaggiari Parma

About

Gruppo Spaggiari Parma is an Emilia-Romagna-based software solutions provider that was founded in 1926. It is known for its ERP solutions for the education sector.

 

Industry

Software

 

What happened?

Gruppo Spaggiari Parma became a target of a ransomware attack orchestrated by the Xpl0itrs ransomware group.

 

Impact

The nature and quantity of data exposed is currently under investigation.

Source

Victim: Target

About

Target Corporation is a Minnesota-based retail store chain that was founded in 1902. It is known for its small-format and large-format retail stores and hypermarkets.

 

Industry

Retail

 

What happened?

Target became a victim of a ransomware attack that was carried out by the Xpl0itrs ransomware group.

 

Impact

The group has claimed to have stolen 8.6 GHB of Target’s source code.

Source

Victim: BMW Group

About

Bayerische Motoren Werke AG is a Munich-based automotive manufacturer that was founded in 1916. It is known for the manufacturing of motorcycles, cars, and bicycles.

 

Industry

Automotive

 

What happened?

BMW Group became a target of a ransomware attack that was carried out by the Xpl0itrs ransomware group.

 

Impact

The group has claimed to have stolen over 800 documents containing sensitive corporate information, including BMW’s motorcycle and dealership information.

Source

Victim: CyrusOne

About

CyrusOne Inc. is a Texas-based data center operator that was founded in 2000. It is known for the operation of over 40 carrier-neutral data centers across North America, Asia, and Europe.

 

Industry

Data center

 

What happened?

CyrusOne Inc. became a target of a ransomware attack that was orchestrated by the ShinyHunters ransomware group.

 

Impact

The ransomware group has claimed to have stolen 640 GB of data containing 12.9 million Salesforce records, including more than 8300 employee records, email addresses, names, job titles, and phone numbers.

Source

Victim: BOK Financial Corporation

About

BOK Financial Corporation is a Tulsa-based financial services holding company that was founded in 1910. It is known for its retail and commercial banking services.

 

Industry

Banking

 

What happened?

BOK Financial Corporation became a victim of a cyber attack that was carried out by the ShinyHunters ransomware group.

 

Impact

The nature and quantity of data exposed is currently under investigation.

Source

Victim: NovoCure

About

Novocure is a Baar-based oncology company that was founded in 2000. It operates through its Portsmouth headquarters in the U.S.

 

Industry

Healthcare

 

What happened?

Novocure became a victim of a ransomware attack that was carried out by the ShinyHunters ransomware group.

 

Impact

The nature and quantity of data exposed is currently under investigation.

Source

Victim: ReliaQuest

About

ReliaQuest is a Florida-based cybersecurity company that was founded in 2007. It is known for its threat detection, investigation, and response services.

 

Industry

Cybersecurity

 

What happened?

ReliaQuest became a target of a ransomware attack that was orchestrated by the ShinyHunters ransomware group.

 

Impact

The nature and quantity of data exposed is currently under investigation.

Source

Victim: Lansing Urgent Care

About

Lansing Urgent Care is a healthcare provider that offers multiple healthcare services to the residents of Michigan. It is known for its urgent care services.

 

Industry

Healthcare

 

What happened?

Lansing Urgent Care became a victim of a cyberattack that affected its operations.

 

Impact

The full nature and impact of the incident are currently under investigation.

Source

Victim: Kingston

About

Kingston Technology Corporation is a California-based technology corporation that was founded in 1987. It is known for the manufacturing, selling, and support of computer memory products.

 

Industry

Computer data storage

 

What happened?

Kingston Technology Corporation became a target of a ransomware attack that was carried out by the Everest ransomware group.

 

Impact

The ransomware group has claimed to have stolen 138.49 GB of data containing 9438 files. The nature of the data compromised is currently under investigation.

Source


Victim: Capgemini

About

Capgemini SE is a Paris-based information technology services and consulting company that was founded in 1967. It is known for IT and consulting services.

 

Industry

Information technology

 

What happened?

Capgemini SE became a victim of a ransomware attack that was orchestrated by the Everest ransomware group.

 

Impact

The nature and quantity of data exposed is currently under investigation.

Source


Victim: OZ Hair and Beauty

About

Oz Hair and Beauty is a Sydney-based cosmetics company that was founded in 1986. It is known for its premium haircare, skincare, makeup, styling tools, wellness, and salon-quality products.

 

Industry

Salon

 

What happened?

Oz Hair and Beauty became a victim of a ransomware attack that was carried out by the xpl0itrs ransomware group.

 

Impact

Personal data of over 2 million customers has been exposed, including their full name, contact information (mobile number and email address), and details of previous purchases with the retailer.

Source


Victim: Organization for Transformative Works (OTW)/Fanlore

About

The Organization for Transformative Works (OTW) is a nonprofit fan activist organization that was founded in 2007. It is run by fans for the preservation and protection of fanworks and fan cultures.

 

Industry

Non-profit

 

What happened?

On August 6, OTW discovered unauthorized access to its servers and spamming on the official Fanlore Discord server.

 

Impact

The cyber attack has exposed the Fanlore database, including email addresses, password hashes, and IP addresses

Source


Victim: Ryde Technology

About

Ryde is an Oslo-based micromobility company that was founded in 2019. It is known for its electric scooters across more than 75 cities in Europe.

 

Industry

Micromobility

 

What happened?

On August 2, Ryde discovered that an unauthorized party gained access to their systems and copied their customers’ data.

 

Impact

The data breach has exposed data of approximately 4.5 million customer accounts, specifically personal and financial information, including full names, email addresses, and card numbers.

Source

Victim: Bits of Gold

About

Bits of Gold is a Tel Aviv-based crypto broker that offers services to B2C and B2B operations. It is known for its B2C platform that serves over 250000 clients.

 

Industry

Cryptocurrency

 

What happened?

On August 16, Bits of Gold reported to customers that they are investigating a cyber attack based on the discovery of unauthorized access to their systems and data.

 

Impact

The data breach exposed data of over 200000 customers, including their names, bank account details, national ID numbers, emails, IP addresses, and public wallet addresses.

Source

Victim: Healthcare Highways

About

Healthcare Highways is a Texas-based medical provider network company that offers solutions to businesses and their employees built around high-quality hospital systems and physicians.

 

Industry

Healthcare

 

What happened?

Healthcare Highways became a victim of a ransomware attack that was carried out by the Chaos ransomware group.

 

Impact

The ransomware group has claimed to have stolen approximately 235 GB of sensitive company and client records.

Source

Victim: Quest Apartment Hotel

About

Quest Apartment Hotels is an Australia-based serviced apartment company. It operates across more than 120 locations in Australia, New Zealand and Fiji.

 

Industry

Hospitality

 

What happened?

Quest identified unauthorized access to a database system on August 17 through a third-party provider. The company immediately took steps to contain the incident.

 

Impact

The data exposed includes 1.5 million records, including names, contact details, and dates of birth.

Source

Victim: The French Ministry of Economy and Finance

About

The Ministry of the Economy and Finance is one of the primary ministries in the Government of Finance. It was formed in 1958 and is situated in Bercy.

 

Industry

Public sector

 

What happened?

The French Ministry of the Economy and Finance reported that an attacker accessed the General Directorate of Public Finances (DGFiP) and stole data.

 

Impact

Data belonging to 678000 individuals (including professionals) has been stolen, including tax income, family quotient, withholding tax rate, company name, and SIREN number.

Source

Victim: Colombia’s Ministry of Justice

About

The Ministry of Justice and Law is the national executive ministry that is responsible for the administration of law and justice in Colombia.

 

Industry

Public sector

 

What happened?

The Ministry of Justice of Colombia confirmed that it became a target of a ransomware attack that affected part of its technology infrastructure and some of its public-facing services on August 2.

 

Impact

The attack disrupted some of the ministry’s services around illicit drug monitoring and legal processes. The nature and quantity of data exposed is currently under investigation.

Source

Victim: Logitech

About

Logitech International S.A. is a Lausanne-based manufacturer of computer peripherals and software that was founded in 1981. It is known for its peripherals for PC including keyboards, music, smart homes, video communication, and smart homes.

 

Industry

Electronics/Technology

 

What happened?

Logitech became a target of a ransomware attack that was carried out by the ShinyHunters ransomware group.

 

Impact

The nature and quantity of data exposed is currently under investigation.

Source

Victim: Baxter International

About

Baxter International Inc. is a healthcare equipment manufacturer based in Illinois. It was founded in 1931 and is known for its products that are used for the treatment of chronic and acute medical conditions.

 

Industry

Medical equipment

 

What happened?

Baxter International Inc. became a victim of a ransomware attack that was orchestrated by the ShinyHunters ransomware group.

 

Impact

The ransomware group has claimed to have stolen more than 7.1 million Salesforce records, including PII.

Source

Victim: Carhartt

About

Carhartt is a Michigan-based clothing company that was founded in 1889. It is known for its heavy-duty workwear including jackets, coveralls, vests, shirts, jeans, and dungarees.

 

Industry

Workwear

 

What happened?

Carhartt became a victim of a ransomware attack that was carried out by the ShinyHunters ransomware group.

 

Impact

The ransomware group has claimed to have stolen 50GB of data containing millions of customer records, employee information, customer metadata, loyalty-related information, and other sensitive information.

Source

Victim: University of Texas at San Antonio

About

The University of Texas at San Antonio is one of the largest universities in Texas and was established in 1969.

 

Industry

Education

 

What happened?

The University of Texas at San Antonio was forced to take its systems offline after detecting a cyber attack.

 

Impact

The incident disrupted account access, registration, payments, and phone service. The nature and impact of the data exposed is currently under investigation.

Source

Victim: Brazosport College, Texas

About

Brazosport College is a Texas-based public community college that was founded in 1968. It offers associate and some bachelor’s degrees.

 

Industry

Education

 

What happened?

On August 10, Brazosport College in Texas identified a cybersecurity incident that forced it to take its key systems offline.

 

Impact

The cyber attack forced the college to block coursework, limit its enrollment services, and delay its two fall terms by one week.

Source

Victim: McDonald’s Corporation

About

McDonald’s Corporation is a California-based fast food restaurant chain that was founded in 1940. It has over 45,356 restaurants worldwide in more than 100 countries.

 

Industry

Restaurant

 

What happened?

Between July 31st and August 16, a hacker who goes by the name TheHatman has stolen data from Azure tenants of multiple Fortune 500 companies.

 

Impact

The threat actor has claimed to have stolen over 1.7 million records, including full names, email addresses, phone numbers, and addresses.

Source

Victim: Tata Consultancy Services

About

Tata Consultancy Services Limited (TCS) is a Mumbai-based information technology services and consulting company that was founded in 1968. It operates in 150 locations across 46 countries.

 

Industry

Information technology

 

What happened?

Between July 31st and August 16, a hacker who goes by the name TheHatman has stolen data from the Azure infrastructure of multiple Fortune 500 companies.

 

Impact

The hacker has claimed to have stolen over 800,000 records, including full names, email addresses, titles, phone numbers, and addresses.

Source

Victim: Vodafone

About

Vodafone Group Public Limited Company is a Newbury-based telecommunications company that was founded in 1984. It operates in 17 countries with partner networks in 42 countries.

 

Industry

Telecommunications

 

What happened?

A hacker who goes by the name TheHatman has claimed to have stolen data from Azure infrastructure of multiple Fortune 500 companies.

 

Impact

The threat actor has claimed to have stolen over 425000 records, including full names, phone numbers, addresses, titles, and email addresses.

Source

Victim: Gap Inc.

About

The Gap Inc. is a California-based clothing and accessories retailer that was founded in 1969. It is one of the largest clothing retailers in the United States.

 

Industry

Retail

 

What happened?

A hacker who goes by the name TheHatman has claimed to have stolen data from Azure infrastructure of multiple Fortune 500 companies.

 

Impact

The threat actor has claimed to have stolen over 80,000 records, including full names, phone numbers, addresses, titles, and email addresses.

Source

Victim: HCL Technologies

About

HCL Technologies Limited is a Noida-based information technology and consulting company that was founded in 1991. It has offices across 60 countries with over 223,000 employees.

 

Industry

Information technology

 

What happened?

A hacker who goes by the name TheHatman has claimed to have stolen data from Azure infrastructure of multiple Fortune 500 companies.

 

Impact

The threat actor has claimed to have stolen over 250,000 records, including full names, phone numbers, addresses, titles, and email addresses.

Source

Victim: InterContinental Hotels

About

InterContinental Hotels Group PLC (IHG) is a Windsor-based hospitality group that was founded in 2003. It operates globally through a chain of 7,109 hotels.

 

Industry

Hospitality

 

What happened?

A hacker who goes by the name TheHatman has claimed to have stolen data from Azure infrastructure of multiple Fortune 500 companies.

 

Impact

The threat actor has claimed to have stolen over 185,000 records, including full names, phone numbers, addresses, titles, and email addresses.

Source

Victim: Wyndham Hotels

About

Wyndham Hotels & Resorts Inc. is a New Jersey-based hospitality company that was founded in 1981. It is one of the largest hotel franchisors in the world, operating across over 9,100 locations globally.

 

Industry

Hospitality

 

What happened?

A hacker who goes by the name TheHatman has claimed to have stolen data from Azure infrastructure of multiple Fortune 500 companies.

 

Impact

The threat actor has claimed to have stolen over 9000 records, including full names, phone numbers, addresses, titles, and email addresses.

Source

Victim: Hexaware

About

Hexaware is a Mumbai-based technology and business process services provider. It operates in 28 countries globally through 58 offices.

 

Industry

Information Technology

 

What happened?

A hacker who goes by the name TheHatman has claimed to have stolen data from Azure infrastructure of multiple Fortune 500 companies.

 

Impact

The threat actor has claimed to have stolen over 20,000 records, including full names, phone numbers, addresses, employee IDs, and email addresses.

Source

Victim: Kyndryl

About

Kyndryl Holdings Inc. is a New York-based information technology company that was founded in 2021. It is known for designing, building, and managing enterprise infrastructure systems.

 

Industry

Information technology

 

What happened?

A hacker who goes by the name TheHatman has claimed to have stolen data from Azure infrastructure of multiple Fortune 500 companies.

 

Impact

The threat actor has claimed to have stolen over 170,000 records, including employee accounts, service accounts, and other tenant account records.

Source

Victim: Pokémon Center

About

Pokémon Center Co. Ltd. is a Tokyo-based retail company that was founded in 2011. It is known for its Pokémon-themed stores that sell a variety of Pokémon merchandise and products.

 

Industry

Retail/e-commerce

 

What happened?

Pokémon Center began notifying its UK- and Germany-based customers that they became a target of a cyber attack due to an attack on CEVA Logistics, its shipping vendor.

 

Impact

The data exposed includes full name, mail address, phone numbers, email address, and details of PokémonCenter.com order(s. The quantity of data exposed is currently under investigation.

Source

Victim: Sakura Internet

About

SAKURA Internet Inc. is an Osaka City-based data center, internet services, and cloud infrastructure provider that was founded in 1996. It is one of the oldest providers of hosting servers in Japan.

 

Industry

Information and communications

 

What happened?

SAKURA Internet discovered that hackers accessed their systems on August 9 during an investigation into another breach at the Sakura Rental Server service.

 

Impact

The cyber attack exposed data of up to 1,360,563 member accounts. The nature of the data exposed is currently under investigation.

Source

Victim: General Electric

About

General Electric is a New York-based MNC that was founded in 1892. It is known for playing a leading role in the development of electric power, aviation, home appliances, medical imaging, and lighting sectors.

 

Industry

Conglomerate

 

What happened?

General Electric became a target of a ransomware attack that was carried out by the Cl0p ransomware group.

 

Impact

The ransomware group has claimed to have exfiltrated 391 GB of data, including software backups, system files, and projects.

Source

Victim: Philips

About

Philips is an Amsterdam-based technology manufacturer that was founded in 1891. It is known for its health technology and consumer electronics products.

 

Industry

Health technology/Electronics

 

What happened?

Philips became a victim of a ransomware attack that was orchestrated by the Cl0p ransomware group.

 

Impact

The ransomware group has claimed to have stolen 13.5 GB of its data, including PDF drawings, diagrams, and blueprints.

Source

Victim: Shell

About

Shell is a London-based oil and gas company that was founded in 1907. It is the largest investor-owned oil company in Europe and is vertically integrated in every area of the oil and gas industry.

 

Industry

Energy/Petroleum

 

What happened?

The Cl0p ransomware group has claimed to have targeted Shell in a ransomware attack. On August 14th, Shell confirmed that it is investigating a potential cybersecurity incident.

 

Impact

Cl0p has claimed to have stolen 89 gigabytes of data, including engineering drawings, facility testing reports, and project plans.

Source

Victim: Sogang University

About

Sogang University is a Seoul-based private Jesuit research university that was established in 1960 by the Society of Jesus. It is the oldest and only Jesuit institution of higher education in South Korea.

 

Industry

Education

 

What happened?

Sogang University discovered unauthorized access to its systems and data. It immediately blocked the attacking IP address, restricted access to affected services, and isolated the network.

 

Impact

Personal information of approximately 180000 students, alumni, and staff was exposed, including student and staff ID numbers, affiliations, email addresses, mobile phone numbers, and encrypted passwords for integrated login systems.

Source

Victim: Darlington County, South Carolina

About

Darlington County offers multiple digital services to its residents, from paying taxes online and applying for permits online to offering information on meetings and employement opportunities.

 

Industry

Public

 

What happened?

on 5th August, Darlington county’s systems, phone lines and some of the government services were disrupted by a cybersecurity incident.

 

Impact

The cyberattack disrupted the county’s systems, phone lines, and some of its government services.

Source

Victim: Trezor

About

Trezor is a Czech Republic-based hardware wallet manufacturer for cryptocurrencies that was founded in 2013. It is known for its Bitcoin Hardware Wallet.

 

Industry

Hardware crypto wallet

 

What happened?

Trezor became a victim of a cyber attack due to an attack on its shipping and logistics provider, ShipMonk.

 

Impact

The data exposed includes personal information of customers, including names, email, phone number, and shipping addresses of 11742 and names, city, name, and email of 1947 customers.

Source

Victim: Tally

About

Tally is a Bengaluru-based technology company that was founded in 1986. It is known for its enterprise resource planning and accounting software, including TallyPrime, TSS, and Tally.ERP 9.

 

Industry

Accounting software

 

What happened?

Tally became a victim of an attack that involved the exploitation of a zero-day SQLi flaw in Metabase instances.

 

Impact

The cyber attack exposed customer records including email addresses and hashed passwords.

Source

Victim: Metabase

About

Metabase is a San Francisco-based software solutions developer. It is known for its data visualization and business intelligence platform, Metabase.

 

Industry

Software

 

What happened?

Attackers exploited a critical SQL injection flaw in versions 1.58 and above to target Metabase. The company disclosed on 6th August that its SaaS platform was compromised.

 

Impact

The data exposed includes phone numbers, email addresses, names, and physical addresses.

Source

Victim: Winnipeg’s Health Sciences Centre

About

Health Sciences Centre is Manitoba’s largest healthcare facility covering over 39 acres of land, with 8000 staff, physicians, and volunteers offering care to patients.

 

Industry

Healthcare

 

What happened?

Winnipeg’s Health Sciences Centre got hit by a ransomware attack.

 

Impact

The attack affected the hospital’s door access, heating, ventilation, and air conditioning systems.

Source

Victim: MyDr

About

MyDr is a Polish medical software developer that was founded in 2017. It is known for its MyDr EDM product that is used by over 10thousand clinics for daily work.

 

Industry

Software

 

What happened?

MyDr became a victim of a ransomware attack by unknown attackers. The attackers have threatened to publish the sensitive information.

 

Impact

The attackers have claimed ot have stolen information of over 18 million Poles (roughly half of the country’s population). The actual nature and impact of the incident are currently under investigation.

Source

Victim: Hong Kong Baptist University

About

Hong Kong Baptist University (HKBU) is a Kowloon Tong-based public university that was founded in 1956. It is known for its Christian education heritage and operates through five main campuses in Hong Kong.

 

Industry

Public

 

What happened?

Hong Kong Baptist University became a target of a ransomware attack that was orchestrated by TheGentlemen ransomware group.

 

Impact

The data exposed includes 1900 credentials, 130 staff accounts, 1170 user accounts, and 260 third-party employee credentials.

Source

Victim: Wesco

About

Wesco International Inc. is a Pittsburgh-based electrical distribution and services company. It is known for its electrical, maintenance, repair, and operating (MRO), OEM products, construction, and shipping services.

 

Industry

Maintenance/Repair operations

 

What happened?

Wesco became a victim of a ransomware attack that was carried out by the ExfilSquad ransomware group.

 

Impact

The ransomware group has claimed to have stolen 40GB of data containing 2.6 million records, including customer and employee PII, account and contact data, CRM user profiles, credit and business identifiers, authentication metadata, and access information.

Source

Victim: Woodhaven Lakes

About

Woodhaven Lakes is an Illinois-based private, gated recreational resort. It offers 1756 acres of lakes, woodlands, and prairies for hiking, recreation, cross-country skiing, and snowmobiling.

 

Industry

Public

 

What happened?

Woodhaven Lakes discovered on 6th August that attackers had encrypted their Microsoft Office files and documents on their on-premises storage devices.

 

Impact

The ransomware knocked out the phones and internet service, limited payments, and forced closure of some of its facilities. The nature and quantity of data exposed is currently under investigation.

Source

Victim: Beaver County, Pennsylvania

About

Beaver County offers multiple services to its citizens, from information related to important meetings to its administrative services.

 

Industry

Public sector

 

What happened?

On August 4, Beaver County said that a hacker took control of its systems used for behavioral health and developmental services. The county paid a $175,000 ransom after hackers encrypted their health records and blocked access to patient files.

 

Impact

The data stolen and encrypted includes behavioral health records and other sensitive patient information. The hackers also blocked access to patient files.

Source

Victim: The Shrewsbury and Telford Hospital Charity

About

Shrewsbury and Telford Hospital NHS Trust is a provider of acute and specialist healthcare services based in Shrewsbury. It is the main provider for Telford, Wrekin and Powys, and Shropshire.

 

Industry

Healthcare

 

What happened?

On 3rd August, Shrewsbury and Telford Hospital was affected by a data breach due to a data breach of its third-party provider, Beacon CRM.

 

Impact

The organization reported that the data involved may include names, addresses, email addresses, phone numbers, and details of membership and donations.

Source

Victim: 3Pro TV

About

3Pro is a financial and investment media outlet based in Seoul. It was founded in 2018 and is one of the most prominent Korean financial content platforms.

 

Industry

Media

 

What happened?

E-Broadcasting, the parent company of 3ProTV, reported that an external actor gained unauthorized access to their 3Pro TV application.

 

Impact

More than 460000 personal data records were exposed, including bank account and credit information.

Source

Victim: Suisun City

About

Suisun City is a city based in Solano County, California. It offers multiple digital services to its citizens, including information about the governmental departments and housing-related & other services.

 

Industry

Public sector

 

What happened?

On August 7th, Suisun City IT systems discovered that it had been hit by a cyber attack that forced it to shut down some of its services.

 

Impact

The cyber attack affected its critical public safety operations, including 911 routing, police and fire dispatch records, and city services.

Source

Victim: City of Coweta

About

Coweta is an Oklahoma-based city in Wagoner County. It offers multiple information services to its citizens.

 

Industry

Public sector

 

What happened?

On August 5, Coweta experienced a cyber attack and immediately contacted its IT provider and coordinated with cybersecurity experts to contain its systems.

 

Impact

The cyber attack affected its computers, files, and computer-based services. The full nature of the impact is currently under investigation.

Source

Victim: Beacon CRM

About

Beacon is a London-based software development company that was founded in 2017. It is known for its charity-focused Beacon CRM that offers specific features for charity organizations.

 

Industry

Software

 

What happened?

Beacon CRM reported that it became a victim of a cyber attack and that unauthorized actors gained access to its systems and stole data.

 

Impact

The cyber attack exposed data of at least 1,500 UK charity organizations, including names, email addresses, phone numbers, genders, dates of birth, donation/payment histories, and information supplied to charities.

Source

Victim: Framework

About

Framework Computer Inc. is a California-based personal computer manufacturer. It is known for its laptops that are easy to disassemble with replaceable parts.

 

Industry

Computer hardware

 

What happened?

Framework reported to its customers that an attacker exploited a zero-day flaw in Metabase to access customers’ information.

 

Impact

Customer data has been exposed, including names, email addresses, login IP, physical addresses, phone numbers, company names, VAT, and Employer Identification Numbers.

Source

Victim: Valve/Steam hardware

About

Valve is a Washington-based video game development, publishing, hardware, and digital distribution company. It was founded in 1996 and is known for its game franchises, including Counter-Strike, Portal, Left4Dead, and Dota.

 

Industry

Video games

 

What happened?

Valve notified Steam hardware customers that hackers have targeted their shipping partner CEVA Logistics.

 

Impact

Data exposed includes information needed to ship hardware orders like names, addresses, phone numbers, email addresses, and type & price of ordered products.

Source

Victim: Levi Strauss

About

Levi Strauss & Co. is a Delaware-based clothing company that was founded in 1853. Its corporate headquarters are located in San Francisco. It is known globally for its denim blue jeans.

 

Industry

Textile

 

What happened?

In its Form-8K filing with the US Securities and Exchange Commission (SEC), Levi’s reported that it became a target of a cyber attack.

 

Impact

Based on a preliminary investigation with the help of cybersecurity experts, the company found that corporate information was accessed and exfiltrated by the hackers. The complete nature and quantity of data exposed is currently under investigation.

Source

Victim: Alcon eye care company

About

Alcon is a Texas-based technology company that was founded in 1945 in Fort Worth, Texas. It is known for its surgical and vision care technology.

 

Industry

Med-tech

 

What happened?

Alcon became a target of a ransomware attack that was orchestrated by the ShinyHunters ransomware group.

 

Impact

The ransomware group has claimed to have stolen 218000 unique email addresses, names, phone numbers, and physical addresses.

Source

Victim: Swiss Federal IT Office

About

The Federal Office of Information Technology, Systems, and Telecommunications FOITT is the largest IT service provider in Switzerland’s Federal Administration. It offers around 50,000 workstation systems and operates over 1000 specialist applications on its own modern data centres.

 

Industry

Public sector

 

What happened?

FOITT discovered that it became a victim of a cyber attack that forced it to block internal access for external users. An investigation found that the attackers exploited vulnerabilities in Microsoft SharePoint software.

 

Impact

The cyber attack compromised around 200 user and technical accounts. The full impact of the incident is currently under investigation.

Source

Victim: English National Ballet (ENB)

About

The English National Ballet is a London-based classic ballet company that was founded in 1950. It is one of the five major ballet companies in Great Britain.

 

Industry

Public sector

 

What happened?

The English National Ballet became a victim of a supply chain attack when its customer service provider, Beacon CRM, experienced a cybersecurity incident.

 

Impact

ENB reported that the email addresses, business phone numbers, and business addresses have been compromised. The quantity of data exposed is currently under investigation.

Source

Victim: ProHealth Medical Group Ltd.

About

ProHealth Medical Group Ltd. is a Singapore-based private primary healthcare group. It provides services like general practice consultation, health screening, and other complementary specialist medical care services.

 

Industry

Healthcare

 

What happened?

ProHealth became a victim of a ransomware attack orchestrated by the Krybit ransomware group.

 

Impact

The nature and quantity of data exposed is currently under investigation.

Source

Victim: UK Police

About

Law enforcement is divided into 48 police forces in the United Kingdom, each responsible for a separate legal system – 1England, Wales, Scotland, and Northern Ireland.

 

Industry

Public sector

 

What happened?

A ransomware group called ExfilSquad leaked data from the Ministry of Defense, the Home Office, the National Crime Agency (NCA), and the Crown Prosecution Service (CPS) on the dark web.

 

Impact

The data of over 100000 police staff has been compromised, including their full names and contact details.

Source

Victim: Freedom Claims Management

About

Freedom Claims Management is a Kansas-based healthcare plan provider that caters to businesses, offering both group and individual coverage options.

 

Industry

Insurance

 

What happened?

Freedom Claims Management became a target of a ransomware attack carried out by the Qilin ransomware group.

 

Impact

The nature and quantity of data exposed is currently under investigation.

Source

Victim: Unitel S.A

About

Unitel S.A. is a mobile phone company based in Angola that was founded in 2001. It is the largest telecom company in Angola. With a staff of over 2000 employees, it offers network coverage of nearly all municipalities in the country.

 

Industry

Telecommunications

 

What happened?

Unitel got hit by a cyber attack on July 30th that caused widespread outages across the telecom’s network.

 

Impact

The attack caused significant disruption in the company’s operations, including the availability of its networks and digital services.

Source

Victim: Freedom Claims Management

About

Freedom Claims Management is a Kansas-based healthcare plan provider that caters to businesses, offering both group and individual coverage options.

 

Industry

Insurance

 

What happened?

Freedom Claims Management became a target of a ransomware attack carried out by the Qilin ransomware group.

 

Impact

The nature and quantity of data exposed is currently under investigation.

Source

Victim: Unitel S.A

About

Unitel S.A. is a mobile phone company based in Angola that was founded in 2001. It is the largest telecom company in Angola. With a staff of over 2000 employees, it offers network coverage of nearly all municipalities in the country.

 

Industry

Telecommunications

 

What happened?

Unitel got hit by a cyber attack on July 30th that caused widespread outages across the telecom’s network.

 

Impact

The attack caused significant disruption in the company’s operations, including the availability of its networks and digital services.

Source

Victim: Unitel S.A

About

Unitel S.A. is a mobile phone company based in Angola that was founded in 2001. It is the largest telecom company in Angola. With a staff of over 2000 employees, it offers network coverage of nearly all municipalities in the country.

 

Industry

Telecommunications

 

What happened?

Unitel got hit by a cyber attack on July 30th that caused widespread outages across the telecom’s network.

 

Impact

The attack caused significant disruption in the company’s operations, including the availability of its networks and digital services.

Source

Victim: Updoc

About

Updoc is a New South Wales-based technology company that is known for its healthcare platform. The platform provides on-demand, accessible healthcare to over 1000000 Australians.

 

Industry

Telehealth

 

What happened?

Updoc notified its patients that it had experienced a data breach and that their personal information had been exposed.

 

Impact

The breach has exposed names, addresses, and postal addresses of account holders.

Source

Victim: Liechtenstein (Register of economic beneficiaries)

About

Liechtenstein is a landlocked country in the Central European Alps located between Switzerland and Austria. It is Europe’s fourth smallest country and the smallest country to border two countries.

 

Industry

Public sector

 

What happened?

Liechtenstein’s government discovered unauthorized access to the register of economic beneficiaries.

 

Impact

The government found that the cyberattack exposed data of 31000 people behind companies and foundations in the wealthy principality.

Source

Victim: Hyundai Motor Türkiye

About

Hyundai Motor Türkiye is one of the leading automotive manufacturers that began production in 1997. It has one of the longest-serving overseas plants outside Korea, with a production capacity of 230000 units.

 

Industry

Automotive

 

What happened?

Hyundai Motor Türkiye became a victim of a cyber attack that was orchestrated by the CRPx0 ransomware group.

 

Impact

The ransomware group has claimed to have stolen over 1.5 GB of sensitive recruitment and personnel data.

Source

Victim: Questal

About

Questal is a Paris-based IT services provider known for its end-to-end intellectual property solutions, serving over 20000 organizations in over 30 countries.

 

Industry

IT services

 

What happened?

Questal became a target of a ransomware attack that was carried out by the ShinyHunters ransomware group.

 

Impact

The ransomware group has claimed to have stolen over 21 million Salesforce records, including PII, with 147 GB of internal corporate data.

Source

Victim: Alcon

About

Alcon Inc. is a Geneva-based pharmaceutical and medical device company that has its main operational base in Texas. It is known for its eye care products.

 

Industry

Ophthalmology

 

What happened?

Alcon Inc. became a victim of a ransomware attack that was carried out by the ShinyHunters ransomware group.

 

Impact

The ransomware group has claimed to have stolen over 25 million Salesforce records containing PII.

Source

Victim: Lumenis

About

Lumenis is an Israel-based medical technology manufacturer known for its solutions for skin, body, and eye care treatment. It primarily operates through its base in California.

 

Industry

Medical device

 

What happened?

Lumenis became a target of a ransomware attack that was orchestrated by the ShinyHunters ransomware group.

 

Impact

The ransomware group has claimed to have stolen over 1.1 million records, including customer and employee PII and over 176 GB of internal corporate data.

Source

Victim: Butcher Brothers

About

The Butcher Brothers is a Woonsocket based provider of beef, pork, poultry, and specialty meats. They are known for offering handcrafted special meats for burgers and meat pies.

 

Industry

Meat

 

What happened?

On 1st August, Play ransomware group listed The Butcher Brothers on its public leak site stating that they have exfiltrated their data.

 

Impact

The nature and quantity of data exposed is currently under investigation.

Source

Victim: ProHealth Medical Group Singapore

About

ProHealth Medical Group is a Singaporean healthcare group that was founded in 1990. It is known for offering primary medical care through a range of healthcare services across 11 clinics in the country.

 

Industry

Healthcare

 

What happened?

ProHealth Medical Group became a victim of a ransomware attack that was carried out by the Krybit ransomware group.

 

Impact

The ransomware group has claimed to have stolen over 114 GB of data. The nature and quantity of data exposed is currently under investigation.

Source

To be continued

In July, we saw how some of the most devastating data breaches impacted some of the biggest companies.

 

Keep checking this space as we update our list of August’s top data breaches with a closer look at how they happened and their impact.

 

Note: Our list only highlights the breaches that have either occurred in 2026 or been reported/disclosed in 2026. All breaches reported in previous years, as of 2026, will be excluded from the list.

List of Data Breach September 2026

Here are some of the biggest data breaches of September 2026. Let us understand their impact through insights like how much data is compromised, the entities affected, regulatory fines, and ransom paid.

Read More