Last Update: 08/01/2026 at 1:00 PM EST

Breaches Expose Identity And Access Risks

Coverage from BleepingComputer, Security Boulevard, and others

Articles

79

Active Days

702

The Topic

Breaches Expose Identity And Access Risks topic image

The topic centers on cyber incidents that expose personal information, employee records, credentials, or sensitive operational data across government, education, financial, and consumer-facing organizations. Repeated patterns include social engineering against identity and single sign-on systems, ransomware leak-site claims, insecure data handling, and the continued reuse of older breach data for phishing, account takeover, and identity theft. The scope and impact of several incidents remain under investigation, and some reported data exposures have not been independently confirmed by the affected organizations.

First Article: 08/26/24

Latest Article: 07/28/26

Summary

  • DHS investigated a compromise of the Homeland Security Information Network and a related SharePoint environment, while reporting no indication that classified networks were affected.
  • Social engineering and voice phishing against employee single sign-on accounts emerged as a route into cloud environments, including the reported ADT breach.
  • Ransomware groups are using leak sites and sample data to pressure organizations, but posted material does not always establish the full scope of a compromise.
  • Exposed identifiers, passwords, and Social Security numbers can remain useful for years through credential reuse, impersonation, and account-recovery fraud.
  • Higher-education systems remain exposed to account takeover when helpdesks rely on static personal information for verification and password resets.
  • Several incidents involve disputed victim counts, alleged stolen records, or incomplete forensic findings, limiting confidence in their final impact.

History

07/21/2026

The story has narrowed from a broad set of breach and leak cases to a more specific focus on identity-system compromise, especially DHS’s HSIN investigation and social-engineering-driven access to cloud environments. It also adds stronger uncertainty around several incidents, emphasizing disputed scope and incomplete confirmation.

07/21/2026

The story has shifted from broad breach fallout to a more specific pattern of named incidents involving government, enterprise, and extortion actors. It now emphasizes cloud and collaboration-system access paths, plus the fact that some leak claims remain unverified while still driving risk.

Full History

Featured

Timeline: 702 Days

2024Jan 1Mar 4May 27Jul 29Oct 21Dec 232025Jan 1Mar 5May 28Jul 30Oct 22Dec 242026Jan 1Mar 5May 28Jul 30Oct 22Dec 24

Additional Articles

⭐⭐⭐⭐⭐

WIRED / Lily Hay Newman02-18-2026
UpGuard researchers found a massive exposed US-focused dataset of credentials and Social Security numbers in January 2024 hosted on Hetzner; Hetzner removed it after notification.
Security Boulevard / Jeffrey Burt04-27-2026
ShinyHunters claimed an ADT breach in 2020s reporting, and ADT disclosed an April 20 cloud-environment intrusion tied to an Okta SSO vishing attack.
Claim Depot04-16-2026
Bank3 notified consumers in April 2026 after Qilin ransomware posted a dark-web claim, alleging exposure of Social Security, payment, and health insurance data.
Claim Depot06-04-2026
First Advantage Corp. disclosed a Nov. 2025 credential-based breach of Profile Advantage accounts, notifying affected residents in Maine, Texas, Massachusetts, and Montana during 2026.
Identity Theft Resource Center07-22-2026
Identity Theft Resource Center reported 1,803 data compromises in H1 2026, estimating 471.2 million victim notices and highlighting low attack-vector disclosure.
WISH-TV / Kendall Pierson07-28-2026
Identity Theft Resource Center reported 471.2 million victim notices in the first half of 2026, citing Canvas and rising insider misuse.
930 WFMD Free Talk05-01-2026
ADT reported unauthorized access starting April 20 that exposed customer names, phone numbers, and addresses, with limited subsets including birth dates and last-four SSN or tax IDs.
Insurance Business Australia / Roxanne Libatique06-12-2026
The University of Western Australia disclosed an online credential exposure breach in 2026, while an Australian privacy regulator cited rising human-error causes of notifiable breaches.
Almeida Law Group05-28-2026
First Advantage discovered a November 2025 phishing breach in a screening unit that processed Rich Products employee data, exposing SSNs and IDs for about 200 people.
TechCrunch / Zack Whittaker07-07-2026
In 2026, cybersecurity incidents exposed personal data across the Social Security Administration, the FBI surveillance system, education platforms, and identity verification services.
PR Newswire07-19-2026
Edelson Lechtzin LLP opened an investigation into a July 16, 2026 Bath Fitter Distributing data breach after Vermont notification of exposed Social Security and financial data.
JD Supra02-27-2026
UpGuard researchers uncover a misconfigured cloud database exposing billions of records in Germany, prompting FBI IC3 and Hetzner to take it down.
Forbes07-25-2026
Identity Theft Resource Center estimated 471.2 million breach victim notices in the first six months of 2026 after a May Canvas breach drove a large share of exposure.
Aol05-10-2026
In the United States, rising identity fraud losses and FTC reports show delayed fraud impacts after data compromises.
Arizona Republic06-14-2026
HaveIBeenPwned and FTC recovery guidance describe defenses against identity theft after data-breach exposure enabled password stuffing.
Dark Reading05-18-2026
Security incident trackers and survey results show rising US data-breach volume and widespread PII exposure alongside low adult follow-through on breach impact checks.
Wirecutter: Reviews for the Real World / Max Eddy06-25-2025
New York Times Wirecutter outlines in a 2020s U.S.-focused guide how individuals should respond when personal data is exposed in consumer data breaches.
WFMD05-02-2026
Texas Attorney General Ken Paxton cited a Conduent Business Services ransomware breach in February 2026, after exposure of Social Security numbers, addresses, and health data.
ILLUMINATION / Sharath Reddy06-29-2026
Security incident notifications arrive after data exfiltration, enabling credential stuffing that reuses stolen credentials across other websites.
The Five Quadrants of Risk07-14-2026
In 2013-2014, Senate staff analysis tied Target payment-card and customer-data theft to unaddressed FireEye alerts and compromised Fazio vendor credentials.
Steadyline / Ravi Mishra07-26-2026
U.S. consumer guidance explains what to document and do after a mental health app data breach, emphasizing notice preservation and account security actions.
Experian / Ben Luthi07-18-2026
When personal information is exposed in a data breach, criminals can commit identity theft, so individuals should monitor credit and use fraud alerts or credit freezes.
Experian / Tim Maxwell07-19-2026
Consumers can use breach-checking tools and credit bureau reports to detect exposure and take steps like multifactor authentication, fraud alerts, and credit freezes.
ExpressVPN / Chantelle Golombick12-16-2025
A privacy-focused guide explains how Facebook users worldwide can assess exposure from past data breaches and adopt stronger security, monitoring, and legal-response measures to mitigate ongoing identity risks.
The Lyon Firm07-14-2026
Child Care Resource Center, Inc. notified the California Attorney General in connection with a phishing incident that enabled internal file forwarding to an unauthorized external email account.
Emery Reddy07-14-2026
CCRC, a California child care nonprofit, notified affected individuals after unauthorized external email forwarding exposed case records dated 2016-2025, reported to the state on July 2, 2026.
The Register / Avram Piltch07-05-2026
In the US, a privacy-and-security column describes an account takeover using optional MFA gaps and Gmail manipulation, and argues passkeys should replace OTP-based authentication.
Troy Hunt / Troy Hunt07-03-2026
A privacy post says ShinyHunters breach leaks tied to JCPenney, Catalyst Brands, and Authentic Brands Group cannot be effectively deleted due to widespread redistribution.

⭐⭐⭐

Cybernews07-07-2026
Unsafe claimed a ransomware breach at Deutsche Bank in Germany by posting alleged employee database extracts on a dark web leak site, with customer-data inclusion unconfirmed.
Aol05-01-2026
ADT confirmed an April 20 data breach involving names, phone numbers, and addresses, with reported Okta SSO and Salesforce access after vishing.
Help Net Security / Sinisa Markovic04-27-2026
ADT reported unauthorized access detected April 20 exposed limited customer PII, and ADT notified law enforcement and impacted individuals in Florida.
GovTech06-08-2026
Upper Township officials urged New Jersey residents to monitor credit reports after a Dec. 8, 2025 discovery of an Oct. 5, 2025 breach exposed personal data.
Claim Depot04-24-2026
Child and Family Services of the Upper Peninsula reported a 2025 employee email breach after unauthorized access potentially exposed Social Security, health, and payment data, with Massachusetts regulator notification on April 21, 2026.
Claim Depot06-24-2026
Bally's Interactive disclosed a Social Security number breach to the Vermont Attorney General on June 15, 2026, with limited public detail on timing and response.
Claim Depot06-25-2026
Eisen Inc. reported a December 12, 2025 data breach after impersonation of the California State Controller's Office led to exposure of unclaimed property compliance records.
Claim Depot07-16-2026
Florence Bank disclosed a data breach in Massachusetts, reporting to state regulators on July 15, 2026, and notifying affected customers on July 6, 2026.
Claim Depot07-17-2026
Bath Fitter Distributing disclosed a July 16, 2026 data breach to the Vermont Attorney General affecting at least 44 Vermont residents.
KSAT San Antonio06-28-2026
After a data breach involving Alamo Heights Independent School District in Texas, experts advised parents to freeze children's credit reports, change passwords, and monitor accounts for identity theft risk.
Privacy Guides / Nate Bartram04-17-2026
Privacy Guides reports April 10-16, 2026 data breach incidents at Booking.com, Basic-Fit, McGraw-Hill, Kraken, Express, and Fiverr involving consumer identifiers and account-related data.
Privacy Guides / Nate Bartram05-16-2026
Privacy Guides reported May 8-14, 2026 breaches including a Zara exposure of over 197,000 people and a UK ransomware fine involving South Staffordshire Water.
Privacy Guides / Nate Bartram06-12-2026
Organizations including IBM, Oxford University, ServiceNow, and Kyushu Electric Power disclosed privacy-relevant breaches and exposures across 2013-2016 incidents, platform compromises, and lost backups.
Privacy Guides / Nate Bartram07-03-2026
KDDI, NAIC, Nissan, Nidec, Aflac, Kubota, and Medtronic disclosed privacy-impacting breaches between Japan and the Americas, exposing login credentials, identifiers, and health-related data.
Privacy Guides / Nate Bartram07-10-2026
Accenture, AssuranceAmerica, Mount Royal University, Nextcloud, and KDDI disclosed breaches after data theft claims or misconfiguration exposed sensitive identifiers and credentials.
Cybersecurity Newswire07-07-2026
DHS began investigating a data breach in a U.S. information-sharing network after suspected intrusion activity starting in late May or early June.
ClassLawDC07-23-2026
Migliaccio & Rathod LLP investigates a reported Omnicell data breach flagged on dark web monitoring sites on July 23, 2026, citing potential identity theft risks.
Databreachtoday05-14-2026
U.S. lawmakers and multiple organizations reported personal-data exposures and patching risks tied to software flaws and third-party breaches across the United States, Germany, Armenia, and North America.
Doctor Of Credit / William Charles06-03-2026
Bask Bank notified account holders in 2026 after an April 27 incident involving names and Social Security numbers and offered Experian IdentityWorks.
TechNadu / Vishwa Pandagle06-27-2026
Brazil and U.S. regulators and companies addressed privacy-impacting cybersecurity events in 2026, including fake emergency alerts and third-party breaches affecting personal data.
Check Point Research05-11-2026
Instructure, Zara, Mediaworks, and Skoda disclosed breaches and security incidents in 2026, exposing personal data through compromised cloud systems, third-party access, and exploited vulnerabilities.
Check Point Research07-13-2026
AssuranceAmerica, Latvijas Valsts Meži, Injective Labs, and Moody Bible Institute disclosed privacy-impacting breaches and compromises in separate incidents.
Check Point Research07-20-2026
Check Point Researchs July 20 threat bulletin reports third-party platform breaches, a supply-chain compromise via npm, and ransomware disruption across the U.S.
FOX 13 Tampa Bay04-26-2026
ADT detected a breach on Monday exposing mostly names, phone numbers, and addresses of current and prospective customers.
Security Magazine07-07-2026
DHS investigated a suspected cyber breach in a government information-sharing network starting between late May and early June in the USA.
Security Magazine07-08-2026
Security reporting summarized six recent data breaches involving healthcare, pharmaceuticals, major event operators, and state licensing systems.
Notebookcheck / Sam Medley04-25-2026
ADT confirmed an April 20 data breach affecting more than 10 million U.S. customers after ShinyHunters claimed theft and threatened a leak by April 27.
Privacy Guides / Nate Bartram02-27-2026
PayPal and other organizations disclosed data breaches exposing personal data between July 2025 and December 2025 across multiple regions including the United States and France.
Privacy Guides / Nate Bartram05-22-2026
Tabiq, NYC Health + Hospitals, 7-Eleven, and Trump Mobile faced privacy-impacting exposures between 2025 and 2026 in Japan and the USA.
The Tennessean08-26-2024
Victims in 2024 in the United States, including Tennessee, face a data breach exposing Social Security numbers and other personal data.
Experian / Karen Axelton05-13-2026
Experian advises families in the USA to check minor credit files and place bureau-specific security freezes after child data breaches.
The Derrick06-14-2026
Consumer guidance recommends password resets, two-factor authentication, and credit freezes at Experian, TransUnion, and Equifax after multiple breach notices.
Malwarebytes07-10-2026
A review compares dark web scanning services that detect exposed emails and passwords and differ in monitoring, alerting, and breach response guidance.
Cybersecurity Insiders / Naveen Goud06-24-2026
After cyberattacks, organizations often cannot verify deletion of stolen data, so breach response emphasizes forensics, takedowns, legal action, and identity protections.
Cybersecurity Insiders / Holger Schulze07-11-2026
ShinyHunters, Icarus, and open-source supply-chain backdoors enabled 2026 enterprise data breaches by exploiting stale credentials, weak identity verification, and access-lifecycle gaps.
Check Point Research06-08-2026
DentaQuest and WFP disclosed privacy-impacting data exposures during June 1 cyber research findings, with accounts and Gaza self-registration data exposed via unauthorized access.
DeXpose07-08-2026
Norton, Aura, LifeLock, NordVPN, KELA, and DeXpose offer dark web monitoring products for personal exposure alerts and enterprise threat intelligence.
Class Action U06-04-2026
DHK Architects notified consumers on May 26, 2026 of a data security incident potentially exposing Social Security numbers and offered Cyberscout identity protection.
Class Action U07-02-2026
After a credit card data breach, consumers are advised to cancel cards, freeze credit at Equifax, Experian, and TransUnion, and report fraud to the FTC.
Class Action U07-05-2026
Have I Been Pwned, Mozilla Monitor, Breachsense, and other services provide dark web monitoring alerts after credential and data breach exposure.
BlackFog / Rebecca Harpur04-27-2026
Jaguar Land Rover, Change Healthcare, Coinbase, Synnovis, and AT&T were linked to major 2024-2025 ransomware or exposure events driven by stolen credentials, insider access, and misconfigured vendor or cloud environments.
PCWorld / Alaina Yee07-21-2026
While traveling, a hotel guest received breach notification after hotel management system intrusion exposed guest name, email, and stay dates.
GiaSpace04-30-2026
Frost Bank and Citizens Financial data were exposed after third-party vendor compromise, while Middlesex County and Vercel reported separate ransomware and tool-breach incidents in April.
Service One Credit Union06-10-2026
In the United States, guidance on data breach response emphasizes MFA, password de-duplication, and credit report monitoring to reduce identity theft risk.
Kaseya06-24-2026
Klue, Texas Parks and Wildlife Department, Cherry Health, Xsolis, and Nintendo of America disclosed breaches involving third-party access, phishing, and integration data exposure during 2026.
Total Defense07-02-2026
Google notes that exposed credentials from third-party breaches can enable rapid account takeover, so breach notifications require immediate password changes and 2FA.
Morgan & Morgan06-10-2026
Community Connections, TriZetto Provider Solutions, Mister Guns, Clarinda Regional Health Center, and RCI Hospitality announced 2025-2026 data breaches involving unauthorized access and IDOR vulnerabilities.
Emery Reddy06-03-2026
First Advantage Corporation disclosed a phishing attack on an employee email account in November 2025, with affected individuals notified starting April 2026 and offered Cyberscout credit monitoring services.