Key developments
Centers Laboratory breach affects 542,377 people
SecurityWeek's Eduard Kovacs reported that Centers Laboratory, a New Jersey testing and laboratory-services provider, notified the U.S. government that an August 2025 intrusion affected 542,377 individuals. Attackers accessed systems from August 9 to August 14 and exfiltrated personal and protected health information, including names, dates of birth, Social Security numbers, government IDs, passport numbers, health insurance information, and medical data. The HHS breach tracker supplied the affected-population figure, while WorldLeaks listed Centers Lab in October 2025 and claimed theft of more than 1.6 million files totaling 720 GB.
Why it matters
The breach combines high-risk medical and identity data with a long disclosure timeline, raising exposure to identity theft, medical fraud, and targeted phishing.
Sources & driving stories
SECURITYWEEK · Eduard Kovacs
SecurityWeek coverageCYBERINSIDER
CyberInsider coverageLidl discloses multi-country online shop breach
BleepingComputer's Sergiu Gatlan and TechRadar reported that Lidl notified online-shop customers in Germany, Belgium, and the Netherlands after attackers accessed a separately stored customer-data file at a third-party IT service provider. Exposed data included names, phone numbers, email addresses, dates of birth, and customer numbers; Lidl said the online shop's main system and customer accounts were not affected. The number of affected customers remains undisclosed, and reporting diverged on whether Lidl has fully ruled out passwords, addresses, and payment data.
Why it matters
Even without confirmed financial-data exposure, the stolen profile data can support convincing phishing and identity-fraud attempts across multiple EU markets.
Sources & driving stories
BLEEPINGCOMPUTER · Sergiu Gatlan
BleepingComputer coverageTECHRADAR
TechRadar coverageCYBERNEWS · Anton Mous
Cybernews coverageCrashStealer macOS malware steals Keychain data
BleepingComputer's Bill Toulas reported that researchers began tracking a new macOS infostealer, CrashStealer, in May and observed it in attacks in early July. The malware impersonates Apple's crash-reporting tool as CrashReporter.app, uses a signed and Apple-notarized installer called Werkbit Setup to bypass Gatekeeper warnings, and displays a fake macOS password prompt to unlock the user's Keychain. Jamf researchers found it targets password managers, Keychain data, and more than 80 cryptocurrency wallet extensions, then encrypts stolen data with AES-256-GCM before exfiltration.
Why it matters
The campaign shows attackers using notarized macOS installers and system-tool impersonation to extract deeply sensitive credentials and wallet data from privacy-conscious users.
Sources & driving stories
BLEEPINGCOMPUTER · Bill Toulas
BleepingComputer coverageWorth noting
WORTH NOTING
Serviceaide settles health breach litigation
Human Rights Research Center reported that Serviceaide agreed to pay $1.8 million to resolve litigation over a 2024 Catholic Health breach affecting more than 400,000 patients, with claims payments up to $5,000 for documented losses.
WORTH NOTING
Chat Control renewal passes
Hungarian Conservative reported that European Parliament rejection of Chat Control 1.0 failed 314-276 because 361 votes were required, leaving voluntary scanning of private messages in force until April 2028.
WORTH NOTING
First American faces DataTree privacy suit
National Mortgage News' Andrew Martinez reported that four residents filed a California federal class action alleging First American's DataTree platform used homeowner identity and contact attributes in a commercial sales funnel without consent.
Still unclear
OPEN QUESTION
How large is Lidl's exposure?
Lidl has not disclosed the number of affected customers, and reports conflict on whether passwords, addresses, bank details, or payment information are definitively excluded.
OPEN QUESTION
Why are health-breach notifications so delayed?
Centers Laboratory's public affected-person count arrived nearly a year after the intrusion window, limiting victims' ability to quickly protect medical and identity data.
