Data Breach Roundup (July 24 - 30, 2026)
OnTrac notifies customers of data breach after network hack
OnTrac is an American delivery company that operates in 35 states, covering roughly 70% of the US population. This breach took place in March. The article referenced notification letters but didn't share how many people or what data was impacted.

Tons of Peoples’ Claude Chats and Creations are Exposed on Google
When Claude users create a public share link, Claude warns them that anyone with the link can access the chat. However, these links are ending up in Google searches. These chats sometimes include sensitive information like API keys, login credentials, names, addresses, and phone numbers. Some of the data appears to have come from an AI-powered therapy app.

ShinyHunters claims Brinks Home breach, threatens to leak stolen data
The attackers claim to have stolen 4.9 million Salesforce records with personally identifiable information, as well as 3.8 million support chat logs. Brinks claims this did not impact their alarm monitoring capabilities. There's no other information at this time.

CareCloud begins to notify hundreds of thousands after hackers stole medical records
This is an update to a story that broke in March. We now know that it impacted just over 345,000 people so far, with the number expected to go up as more disclosures are filed. Data stolen includes names, postal address, Social Security numbers, government-issued ID numbers (such as passport and driver's license), financial information (such as bank account or card numbers), and medical & health-related information.

South Korea fines telco giant KT $39 million for customer data breach
This is an update to an ongoing story. We learned last year that South Korea's biggest telecommunication providers was compromised for nearly 11 months, exposing the data of over 16,000 subscribers and enabling over $167,000 USD of fraudulent mobile payments.

Data breach at medical billing firm MCBS affects 1.26 million people
This breach occurred in 2025 but was just disclosed last month without any details. In addition to number impacted, we now know that full name, physical address, Social Security number, date of birth, health plan beneficiary number, health insurance policy number, subscriber identification number, medical history, mental & physical condition, medical treatment information, and diagnosis information were potentially exposed.

Chick-fil-A data breach affects more than 13,000 customers
An update to a story from last week, we now know how many customers were impacted by the Chick-fil-A credential stuffing attack.


Community Discussion