Data Breach Roundup (August 14 - 20, 2026)

Data Breach Roundup (August 14 - 20, 2026)

RingCentral data breach exposed info of 1.6 million accounts

RingCentral is a cloud-based collaboration and communication platform used by businesses for services such as calling, messaging, and voicemail. The company discovered the incident on July 28, and ShinyHunters claimed to have taken over 280GB (compressed) of data. Have I Been Pwned confirmed the leak, which included names, email addresses, phone numbers, and physical addresses.

RingCentral data breach exposed info of 1.6 million accounts
The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned.

SafePal data breach impacts 39,798 customers, stolen info for sale

SafePal is a cryptocurrency hardware wallet provider. This breach impacts orders placed between March 2, 2025 and April 11, 2026 and exposed names, email addresses, shipping addresses, phone numbers, and purchase information. The company says the breach did not expose customers' wallet seed phrases, private keys, passwords, bank account information, payment card numbers, government-issued identification numbers, or other credentials.

SafePal data breach impacts 39,798 customers, stolen info for sale
Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data.

Pokémon Center data breach exposes customer info, cancels some orders

Pokémon Center appears to be the official site for ordering various Pokémon merchandise. Customers in the UK and Germany were impacted after a third-party data breach from CEVA Logistics (which we covered in a previous newsletter). Impacted data includes customers' full names, mailing addresses, phone numbers, email addresses, and details about the contents of their PokemonCenter.com orders. In some cases, orders were cancelled. Number of impacted customers was not disclosed.

Pokémon Center data breach exposes customer info, cancels some orders
Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics.

Hacker claims 3.6 million Azure account records stolen from major companies

A threat actor going by "TheHatman" is offering to sell the Azure infrastructure data from multiple Fortune 500 companies including McDonald's, Gap Inc., Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels (IHG), and Kyndryl. They claim to have 3.64 million data records, including employee records. In the case of McDonald's for example, data includes names, employee IDs, email addresses, job titles, phone numbers, postal addresses, service accounts, and other tenant account records.

Hacker claims 3.6 million Azure account records stolen from major companies
A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials.

Reverse-Lookup Service Exposed Millions of Photos of People’s Faces

ClarityCheck is a people-search tool that allows users to do reverse image searches of people's faces. According to security researcher Jeremiah Fowler, ClarityCheck left an exposed database of roughly 450GB of images (including children) in a publicly-accessible Amazon S3 bucket. A second misconfigured database included email addresses and phone numbers. It is secured now, but Fowler claims it was exposed for months and it's unknown if any malicious actors may have accessed it.

Reverse-Lookup Service Exposed Millions of Photos of People’s Faces
The people-search tool ClarityCheck says its reverse image search service is “private and secure”—but it left a database containing more than 9 million image files exposed.

Sakura Internet hack exposes data of up to 1.36 million accounts

Sakura is a cloud & data center provider. This breach impacts their sales management system, which includes customer contract and membership information. Details have been scant. We will update as we hear more.

Sakura Internet hack exposes data of up to 1.36 million accounts
Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored.

French tax authority data breach affects 678,000 individuals

An update to an older breach from August of last year. Previously we didn't know the number of people impacted, but we now know that a total of 678,000 individuals and professionals were impacted, including tax data such as reference tax income, family quotient, and withholding tax rate, and, for businesses, data such as their company name and SIREN number.

French tax authority data breach affects 678,000 individuals
The French Ministry of the Economy and Finance has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems and stole data belonging to 678,000 individuals.

CareCloud confirms 3.7M patients had their medical records stolen in data breach

Another update to a previous data breach. This breach was previously disclosed in March without any details. We now know that it's the fifth-largest healthcare data breach in 2026 so far.

CareCloud confirms 3.7M patients had their medical records stolen in data breach | TechCrunch
The cyberattack at CareCloud resulted in one of the largest reported data breaches in the U.S. healthcare industry this year.

Community Discussion