History
07/23/20260 new articles
The main update is a reframing of the Telus Digital incident: the claim is now attributed to ShinyHunters and the alleged theft is described as nearly 1 petabyte of customer and corporate data, although that scale remains unverified. The rest of the story is largely a clarification of already reported breach impacts and response activity.
07/21/20261 new articles
The story has broadened from a largely Lidl-centered vendor breach to a wider multi-organization incident set, with Loblaw and especially Telus Digital adding a new corporate-data-theft angle. The Telus case is the biggest new development because it introduces unverified but large-scale theft claims and a named threat actor, shifting the focus from exposed customer contact data to potentially extensive enterprise compromise.
- Loblaw reported unauthorized access to a contained network segment.
- Telus Digital confirmed unauthorized access to several systems.
- ShinyHunters was named in the Telus Digital claims.
- Claims include access to Salesforce, BigQuery, support data, source code, and financial information.
- The Telus data-theft scale remains unverified.
07/17/20268 new articles
The story has shifted from a broad pattern of retail and service-sector breaches to a much clearer current focal point: the Lidl breach, now reported across multiple outlets and countries, with a third-party IT provider identified as the exposure path. The update also adds concrete response steps—customer notices, regulator reporting, and police involvement—and sharpens the privacy risk around phishing and impersonation.
- Lidl is now the main disclosed breach across multiple outlets.
- A third-party IT provider is identified as the breach path.
- Authorities including the Dutch Autoriteit Persoonsgegevens were notified.
- Password and payment data are said not to be compromised.
- Phishing and impersonation are now the primary downstream risks.
05/11/2026Topic Formed
The cluster is centered on recent data breaches affecting retail and outsourced service organizations, with repeated exposure of customer or employee personal data. The dominant pattern is unauthorized access tied to credential compromise, cloud or vendor systems, and limited but consequential leakage of contact and identity-related information. Coverage also emphasizes breach notification, forensic investigation, and the longer-tail privacy risk of phishing or fraud after disclosure.