Data Breach Roundup (Mar 6 - Mar 12, 2026)

Data Breach Roundup (Mar 6 - Mar 12, 2026)

Cognizant TriZetto breach exposes health data of 3.4 million patients

TriZetto makes software and IT services used by health insurers and healthcare providers. This breach was detected in October 2025 and the subsequent investigation revealed access dating back to November 2024. Data exposed includes full name, physical address, date of birth, Social Security number, health insurance member number, Medicare beneficiary identifier, provider name, health insurer name, and demographic, health, & insurance information.

Cognizant TriZetto breach exposes health data of 3.4 million patients
TriZetto Provider Solutions, a healthcare IT company that develops software and services used by health insurers and healthcare providers, has suffered a data breach that exposed the sensitive information of over 3.4 million people.

Ericsson US discloses data breach after service provider hack

Ericsson is a Swedish "networking and telecommunications giant." Their US arm is reporting that the data of over 15,000 employees and customers had been exposed including names, addresses, Social Security numbers, driver's license numbers, government-issued ID numbers (passports, state IDs, etc), financial information (account numbers, cred/debit card numbers, etc), medical information, and dates of birth.

Ericsson US discloses data breach after service provider hack
Ericsson Inc., the U.S. subsidiary of Swedish networking and telecommunications giant Ericsson, says attackers have stolen data belonging to over 15,000 employees and customers after hacking one of its service providers.

DOGE employee stole Social Security data and put it on a thumb drive, report says

An unnamed DOGE software engineer - who left in October of last year - says that he took two USB sticks with him containing two databases ("Numident" and "Master Death File") with the intention of re-using the data at his new company. The Social Security Administration disputes this claim.

DOGE employee stole Social Security data and put it on a thumb drive, report says | TechCrunch
A whistleblower is accusing a former DOGE member of stealing a large number of Americans’ personal data while he was working at the Social Security Administration, with the plan of using it at his new job.

Telus Digital confirms breach after hacker claims 1 petabyte data theft

Telus Digital is a "business process outsourcing" company. Details on this breach are still very limited. The company has confirmed that a breach but has not responded to any questions. ShinyHunters is claiming the breach, but BleepingComputer has not been able to confirm any of the samples. ShinyHunters claims to have impacted 28 "well-known" companies impacted by the breach, and says data incldes things like customer support agent rankings and fraud detection tools, but also more sensitive data like FBI background checks, financial information, voice recordings of support calls, and call metadata.

Telus Digital confirms breach after hacker claims 1 petabyte data theft
Canadian business process outsourcing giant Telus Digital has confirmed it suffered a security incident after threat actors claimed to have stolen nearly 1 petabyte of data from the company in a multi-month breach.

England Hockey investigating ransomware data breach

England Hockey is the governing board for field hockey in England. A threat actor is claiming to have stolen 129GB of data. No other details have been released yet, but typically in these cases the attacker turns out to be telling the truth so we'll likely have an update in a future newsletter.

England Hockey investigating ransomware data breach
England Hockey, the governing body for field hockey in England, is investigating a potential data breach after the AiLock ransomware gang listed it as a victim on its data leak site.

Canadian retail giant Loblaw notifies customers of data breach

The breach contains "basic customer information" like names, phone numbers, and email addresses. The company said that out of caution they logged all customers out of their accounts and recommend (but are not forcing) password changes.

Canadian retail giant Loblaw notifies customers of data breach
Still, out of an abundance of caution, Loblaw says it has automatically logged out all customers from their accounts. Account holders who need to access the company’s digital services will have to log in again.

Starbucks discloses data breach affecting hundreds of employees

This occurred after attackers gained access to 889 Starbucks Partner Central accounts, which employees use for managing personal details, benefits, and HR information. The article did not explain how this compromise occurred, but said exposed information includes names, Social Security numbers, dates of birth, and financial account information such as routing numbers.

Starbucks discloses data breach affecting hundreds of employees
Starbucks has disclosed a data breach affecting hundreds of employees after threat actors gained access to their Starbucks Partner Central accounts.

Viral 'Quittr' Porn Addiction App Exposed the Masturbation Habits of Hundreds of Thousands of Users

This is an update to a story from January. 404 wrote about an app that was leaking user data but declines to name the app because the security issues weren't resolved yet. The app had a misconfiguration that allowed anyone to query the user database. After initially denying the vulnerability and dodging reporters, the vulnerability has been fixed.

Viral ‘Quittr’ Porn Addiction App Exposed the Masturbation Habits of Hundreds of Thousands of Users
A couple of 20-year-old developers make $500,000 a month promising to help men to stop watching porn, but exposed their private porn watching habits.

Community Discussion