Skip links

Data breach guidance for individuals

data breaches

Lexington-Richland 5 school district in South Carolina suffered a June attack that delayed summer school, disrupted teacher and staff pay, and exfiltrated more than 1TB of data including personal information of more than 31,000 individuals. Cherokee County School District in South Carolina was struck by Interlock in March 2025, with systems affected for around a week and 624GB of data allegedly stolen, with over 46,000 individuals confirmed impacted in September 2025. The vast majority of incidents occurred in the US, which accounted for 130 attacks, over half of all ransomware activity logged globally across the education sector.

  • Multiple US county and municipal governments reported ransomware incidents throughout the year, with a common thread of underfunded IT departments, legacy systems past their end-of-support dates, and limited incident response capacity.
  • Under Armour disclosed a ransomware incident in which attackers accessed internal corporate systems, claiming to have accessed data linked to millions of records, though Under Armour had not confirmed the scale at the time of initial disclosure.
  • Third-party CRM providers, identity verification services, analytics platforms, and MFT infrastructure each store financial customer data at enterprise scale and represent a single point of compromise that can bypass the security controls financial institutions themselves have spent hundreds of millions building.
  • Stay ahead of data breaches and prevent data leaks with strong passwords, encryption, and regular security updates.

Klarna’s breach was notable primarily for its vendor origin; the same identity verification provider was confirmed to have been involved in multiple fintech breaches throughout the year, suggesting a single systemic point of failure across the buy-now-pay-later and digital lending sectors. A threat actor had been selling 400GB of stolen Finastra data on dark web forums since October 2024, including sensitive financial transaction records, client credentials, and operational banking data. While not a breach of Zelle’s own systems, the combination of social engineering attacks targeting Zelle users and the platform’s irreversible transaction model made it the payments sector’s most consequential fraud vector of the year.

data breaches

A threat actor claims to have breached BENY New Energy and leaked 13,600 user records, publishing database screenshots and sample data that remain unverified. Users should pay careful attention to the issue of duplicate reporting when making use of this data or making assertions based on this data. Rather, it reflects the data breach notifications themselves that have been reported and made publicly available in the United States. The Data Breach Chronology is based on publicly available information and should not be considered a complete and accurate representation of every data breach in the United States. The scope of data breach reporting—thousands of notifications across multiple agencies—creates a significant challenge for a small nonprofit organization.

Notable Data Breaches in History

Separately, Verizon’s 2025 DBIR dataset included 12,195 confirmed data breaches, but that is a research dataset count, not a full global total. The strongest 2026 prediction is that AI will shape both attacks and defense, while fraud, phishing, and supply-chain risk stay major concerns. ITRC survey findings in its 2025 report show 88% of respondents who received a breach notice experienced at least one negative consequence, and only 9.7% reported ignoring the notice or doing nothing. Verizon’s 2025 DBIR says ransomware remained a major issue and was present in 44% of reviewed breaches, up from 32%, with a 37% increase from the prior report year. These combined services create stronger visibility, faster detection, and tighter protection around sensitive data. Bright Defense helps organizations cut down the conditions that lead to data breaches.

  • Upon detection, Red Hat reported that it promptly launched an investigation, removed the unauthorized party’s access, isolated the affected instance, and contacted appropriate authorities.
  • At the same time, they must also ensure that the organization’s network is safe from attackers through firewalls, intrusion detection systems, and other commonly used data protection methods.
  • No breach in 2025, or in any prior year, came close to the scale of the credential dataset uncovered by Cybernews researchers in June.
  • Malicious or criminal attacks remained the largest source of data breaches, accounting for 59% of notifications and 308 incidents.
  • According to reports, names, dates of birth, phone numbers, and email addresses may have been exposed, while a group of customers may have also had their physical addresses and documents like driving licenses and passport numbers accessed.
  • This is not a unique headcount, as the same person affected by multiple breaches is counted multiple times.

A new court filing alleges that four months ago, background check company National Public Data (NPD) was breached by hacking group USDoD. This is after suspicious activity indicative of an intrusion was detected on its computer network. Information including names, Social Security numbers, driver’s license numbers, financial account https://consultprofound.com/top-10-technology-trends-to-watch-2025.html?noamp=mobile information, medical information, health insurance information, and dates of birth was compromised.

Misconfigurations and legitimate tool abuse often bypass traditional security detection. They are credential-based breaches, https://errefom.info/6-lessons-learned-3/ misconfiguration exposures, and targeted cyberattacks like ransomware or malware intrusions. It detects third-party apps used by employees or clients and scans cloud accounts for excessive permissions and high-risk users, enabling you to revoke access when necessary.

How do I prevent data breaches?

Digital extortion group Clop, aka Cl0p, has been tied to a fresh spate of supply-chain attacks, this time targeting users of popular Windchill and FlexPLM product life cycle management software from PTC. Its clients must notify the DPA and the individuals depending on the data that was processed by the data processor. Company must notify clients and they may then have to notify the DPA and individuals A cloud service loses several hard drives containing personal data belonging to several of its clients. In that case, there would be doubts about whether the hospital has implemented appropriate technical and organisational protection measures. Organisation must notify the DPA and individuals The data of a textile company’s employees has been disclosed.

data breaches

Instructure also falls victim to ShinyHunters’ disruptive hacking campaigns

In November 2025, the ITRC asked 1,040 consumers selected at random via the online survey platform SurveyMonkey if they had received a data breach notice in the past 12 months, and their attitudes and actions following receiving the notice. For purposes of reporting, the ITRC aggregates data events based on the date the breach, exposure, or leak was entered into the database rather than the date the event occurred. The ITRC does not sell or share any information about individual users.

Anduril reportedly in talks to raise funding at $100B valuation, more than 3x last year’s mark

“A data breach comes as a result of a cyberattack that allows cybercriminals to gain unauthorized access to a computer system or network and steal the private, sensitive, or confidential personal and financial data of the customers or users contained within.” The stolen information can be exploited for financial gain or used in further attacks, making data breaches a significant threat to both individuals and businesses. In fact, it is speculated that a properly configured WAF would have prevented the major data breach attack on Equifax in 2017.

data breaches

Discord hasn’t disclosed the exact amount, calling it “limited” – however, the platform has 200 million monthly active users, so even a small fraction could impact millions. The breach was reported to the California Attorney General in October, but took place in late 2024 and early 2025. Compromised information includes addresses, dates of birth, social security numbers, and health insurance numbers.

That positioning means its data stores contain medical charts, diagnostic codes, clinical encounter records, and health plan membership information for millions of individuals across its client network. Texas alone reported 15.4 million affected individuals, while Oregon reported another 10.5 million. Although the vulnerability was reported over two years ago, CloudSEK’s investigation revealed that the endpoint exploited by the attacker had not been updated since 2014 and was in active use as recently as February 17, 2025. The vulnerability, originally reported in December 2022, allows unauthenticated attackers to compromise Oracle Access Manager instances.

BENY Allegedly Breached as Threat Actor Claims 13,600 User Records Leaked

These requirements may include notification of affected individuals, notification of relevant authorities, and implementation of a plan to prevent future breaches. By implementing these measures, enterprises can significantly reduce the risk of data breaches and protect their systems and data from potential threats. Enterprises can stay ahead of data breaches by implementing several security measures. By identifying these challenges to data breaches, security leaders can direct their efforts to where the enemy tends to infiltrate.

Leave a comment