Data Breach Roundup (July 24 - 30, 2026)

Data Breach Roundup (July 24 - 30, 2026)

OnTrac notifies customers of data breach after network hack

OnTrac is an American delivery company that operates in 35 states, covering roughly 70% of the US population. This breach took place in March. The article referenced notification letters but didn't share how many people or what data was impacted.

OnTrac notifies customers of data breach after network hack
OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers.

Tons of Peoples’ Claude Chats and Creations are Exposed on Google

When Claude users create a public share link, Claude warns them that anyone with the link can access the chat. However, these links are ending up in Google searches. These chats sometimes include sensitive information like API keys, login credentials, names, addresses, and phone numbers. Some of the data appears to have come from an AI-powered therapy app.

Tons of Peoples’ Claude Chats and Creations are Exposed on Google
Claude users are creating public share links, but probably don’t realize that means their chats are now ending up in Google searches where anyone can dig through them.

ShinyHunters claims Brinks Home breach, threatens to leak stolen data

The attackers claim to have stolen 4.9 million Salesforce records with personally identifiable information, as well as 3.8 million support chat logs. Brinks claims this did not impact their alarm monitoring capabilities. There's no other information at this time.

ShinyHunters claims Brinks Home breach, threatens to leak stolen data
Residential security company Brinks Home has disclosed that hackers breached some of its systems and are threatening to leak allegedly stolen data.

CareCloud begins to notify hundreds of thousands after hackers stole medical records

This is an update to a story that broke in March. We now know that it impacted just over 345,000 people so far, with the number expected to go up as more disclosures are filed. Data stolen includes names, postal address, Social Security numbers, government-issued ID numbers (such as passport and driver's license), financial information (such as bank account or card numbers), and medical & health-related information.

CareCloud begins to notify hundreds of thousands after hackers stole medical records | TechCrunch
The health tech data giant, which handles vast amounts of patients’ medical data, said hackers struck one of its protected health data stores.

South Korea fines telco giant KT $39 million for customer data breach

This is an update to an ongoing story. We learned last year that South Korea's biggest telecommunication providers was compromised for nearly 11 months, exposing the data of over 16,000 subscribers and enabling over $167,000 USD of fraudulent mobile payments.

South Korea fines telco giant KT $39 million for customer data breach
South Korea’s Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53.979 billion ($39 million) over data protection violations.

Data breach at medical billing firm MCBS affects 1.26 million people

This breach occurred in 2025 but was just disclosed last month without any details. In addition to number impacted, we now know that full name, physical address, Social Security number, date of birth, health plan beneficiary number, health insurance policy number, subscriber identification number, medical history, mental & physical condition, medical treatment information, and diagnosis information were potentially exposed.

Data breach at medical billing firm MCBS affects 1.26 million people
Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people.

Chick-fil-A data breach affects more than 13,000 customers

An update to a story from last week, we now know how many customers were impacted by the Chick-fil-A credential stuffing attack.

Chick-fil-A data breach affects more than 13,000 customers
Chick-fil-A has confirmed that over 13,000 customers had their accounts breached in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19.

Community Discussion