> ## Content Index
> Fetch the complete content index at: https://www.privacyguides.org/llms.txt
> Use this file to discover other available public pages before exploring further.

# Data Breach Roundup (August 14 - 20, 2026)
- URL: https://www.privacyguides.org/news/2026/08/21/data-breach-roundup-august-14-20-2026/
- Published: 2026-08-21T22:15:56.000Z
- Updated: 2026-08-21T22:15:56.000Z
- Description: The CEVA Logistics breach continues to impact companies, a people search site left their databases exposed, and a couple small updates on the scope of previously-disclosed breaches.
- Author: Nate Bartram
- Tags: News Briefs, Data Breaches

## RingCentral data breach exposed info of 1.6 million accounts

RingCentral is a cloud-based collaboration and communication platform used by businesses for services such as calling, messaging, and voicemail. The company discovered the incident on July 28, and ShinyHunters claimed to have taken over 280GB (compressed) of data. Have I Been Pwned confirmed the leak, which included names, email addresses, phone numbers, and physical addresses.

[RingCentral data breach exposed info of 1.6 million accountsThe ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned.![](https://www.privacyguides.org/content/images/icon/bleeping-b49973a7-f63d-4cc2-99b6-6acb12695636.ico)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/RingCentral-headpic-8c7a5ced-b041-4dd1-be7d-9868d786f2c2.jpg)](https://www.bleepingcomputer.com/news/security/ringcentral-data-breach-exposed-info-of-16-million-accounts/)

## SafePal data breach impacts 39,798 customers, stolen info for sale

SafePal is a cryptocurrency hardware wallet provider. This breach impacts orders placed between March 2, 2025 and April 11, 2026 and exposed names, email addresses, shipping addresses, phone numbers, and purchase information. The company says the breach did not expose customers' wallet seed phrases, private keys, passwords, bank account information, payment card numbers, government-issued identification numbers, or other credentials.

[SafePal data breach impacts 39,798 customers, stolen info for saleCryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data.![](https://www.privacyguides.org/content/images/icon/bleeping-2ad56f24-17d9-4b77-b897-782708ee9999.ico)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/safepal-header-6630e316-53ec-4e27-ab27-c66923cada28.jpg)](https://www.bleepingcomputer.com/news/security/safepal-data-breach-impacts-39-798-customers-stolen-info-for-sale/)

## Pokémon Center data breach exposes customer info, cancels some orders

Pokémon Center appears to be the official site for ordering various Pokémon merchandise. Customers in the UK and Germany were impacted after a third-party data breach from CEVA Logistics (which we covered in a previous newsletter). Impacted data includes customers' full names, mailing addresses, phone numbers, email addresses, and details about the contents of their PokemonCenter.com orders. In some cases, orders were cancelled. Number of impacted customers was not disclosed.

[Pokémon Center data breach exposes customer info, cancels some ordersPokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics.![](https://www.privacyguides.org/content/images/icon/bleeping-0be4b8af-ee11-4db6-81a2-f73986d047ce.ico)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/pokemon-center-3eec9a87-6d05-45e1-8711-e6e9bc0a666e.jpg)](https://www.bleepingcomputer.com/news/security/pokemon-center-data-breach-exposes-customer-info-cancels-some-orders/)

## Hacker claims 3.6 million Azure account records stolen from major companies

A threat actor going by "TheHatman" is offering to sell the Azure infrastructure data from multiple Fortune 500 companies including McDonald's, Gap Inc., Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels (IHG), and Kyndryl. They claim to have 3.64 million data records, including employee records. In the case of McDonald's for example, data includes names, employee IDs, email addresses, job titles, phone numbers, postal addresses, service accounts, and other tenant account records.

[Hacker claims 3.6 million Azure account records stolen from major companiesA threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials.![](https://www.privacyguides.org/content/images/icon/bleeping-6ab9b631-9e58-4ca3-90ab-c62ea645b1ae.ico)BleepingComputerIonut Ilascu![](https://www.privacyguides.org/content/images/thumbnail/DataLeak-625bf493-ffb8-44f6-954e-853e6df087cc.jpg)](https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/)

## Reverse-Lookup Service Exposed Millions of Photos of People’s Faces

ClarityCheck is a people-search tool that allows users to do reverse image searches of people's faces. According to security researcher Jeremiah Fowler, ClarityCheck left an exposed database of roughly 450GB of images (including children) in a publicly-accessible Amazon S3 bucket. A second misconfigured database included email addresses and phone numbers. It is secured now, but Fowler claims it was exposed for months and it's unknown if any malicious actors may have accessed it.

[Reverse-Lookup Service Exposed Millions of Photos of People’s FacesThe people-search tool ClarityCheck says its reverse image search service is “private and secure”—but it left a database containing more than 9 million image files exposed.![](https://www.privacyguides.org/content/images/icon/favicon-76fc0f2e-890a-4d42-8382-24a621471913.ico)WIREDLily Hay Newman and Matt Burgess![](https://www.privacyguides.org/content/images/thumbnail/Security_Data-20Broker-20Leak-20Exposes-208-20Million-20Photos-20of-20People-E2-80-99s-20Faces_v1-b62aad98-4b29-484b-84c2-17e7f47b18d8.jpg)](https://www.wired.com/story/reverse-lookup-service-exposed-millions-of-photos-of-peoples-faces/)

## Sakura Internet hack exposes data of up to 1.36 million accounts

Sakura is a cloud & data center provider. This breach impacts their sales management system, which includes customer contract and membership information. Details have been scant. We will update as we hear more.

[Sakura Internet hack exposes data of up to 1.36 million accountsJapanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored.![](https://www.privacyguides.org/content/images/icon/bleeping-58cc318b-8471-4356-af24-8fab1da48740.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/sakura-e5dc3a2a-d0db-4f0a-9a7a-68625fa60a0c.jpg)](https://www.bleepingcomputer.com/news/security/sakura-internet-hack-exposes-data-of-up-to-136-million-accounts/)

## French tax authority data breach affects 678,000 individuals

An update to an older breach from August of last year. Previously we didn't know the number of people impacted, but we now know that a total of 678,000 individuals and professionals were impacted, including tax data such as reference tax income, family quotient, and withholding tax rate, and, for businesses, data such as their company name and SIREN number.

[French tax authority data breach affects 678,000 individualsThe French Ministry of the Economy and Finance has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems and stole data belonging to 678,000 individuals.![](https://www.privacyguides.org/content/images/icon/bleeping-5b1b523c-39da-4aec-a8f6-18358712e66b.ico)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/flag-of-france-a09b4bce-c4cb-4bcd-a682-b164838b3430.jpg)](https://www.bleepingcomputer.com/news/security/french-tax-authority-data-breach-affects-678-000-individuals/)

## CareCloud confirms 3.7M patients had their medical records stolen in data breach

Another update to a previous data breach. This breach was previously disclosed in March without any details. We now know that it's the fifth-largest healthcare data breach in 2026 so far.

[CareCloud confirms 3.7M patients had their medical records stolen in data breach | TechCrunchThe cyberattack at CareCloud resulted in one of the largest reported data breaches in the U.S. healthcare industry this year.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-e4caa355-da26-4626-a42f-45309967b7ce.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/hacking-surveillance1-21890a68-7920-470c-a4fd-c5a75d3db0e3.png)](https://techcrunch.com/2026/08/19/carecloud-confirms-3-7m-patients-had-their-medical-records-stolen-in-data-breach/)