Data Breach Roundup (August 14 - 20, 2026)
RingCentral data breach exposed info of 1.6 million accounts
RingCentral is a cloud-based collaboration and communication platform used by businesses for services such as calling, messaging, and voicemail. The company discovered the incident on July 28, and ShinyHunters claimed to have taken over 280GB (compressed) of data. Have I Been Pwned confirmed the leak, which included names, email addresses, phone numbers, and physical addresses.

SafePal data breach impacts 39,798 customers, stolen info for sale
SafePal is a cryptocurrency hardware wallet provider. This breach impacts orders placed between March 2, 2025 and April 11, 2026 and exposed names, email addresses, shipping addresses, phone numbers, and purchase information. The company says the breach did not expose customers' wallet seed phrases, private keys, passwords, bank account information, payment card numbers, government-issued identification numbers, or other credentials.

Pokémon Center data breach exposes customer info, cancels some orders
Pokémon Center appears to be the official site for ordering various Pokémon merchandise. Customers in the UK and Germany were impacted after a third-party data breach from CEVA Logistics (which we covered in a previous newsletter). Impacted data includes customers' full names, mailing addresses, phone numbers, email addresses, and details about the contents of their PokemonCenter.com orders. In some cases, orders were cancelled. Number of impacted customers was not disclosed.

Hacker claims 3.6 million Azure account records stolen from major companies
A threat actor going by "TheHatman" is offering to sell the Azure infrastructure data from multiple Fortune 500 companies including McDonald's, Gap Inc., Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels (IHG), and Kyndryl. They claim to have 3.64 million data records, including employee records. In the case of McDonald's for example, data includes names, employee IDs, email addresses, job titles, phone numbers, postal addresses, service accounts, and other tenant account records.

Reverse-Lookup Service Exposed Millions of Photos of People’s Faces
ClarityCheck is a people-search tool that allows users to do reverse image searches of people's faces. According to security researcher Jeremiah Fowler, ClarityCheck left an exposed database of roughly 450GB of images (including children) in a publicly-accessible Amazon S3 bucket. A second misconfigured database included email addresses and phone numbers. It is secured now, but Fowler claims it was exposed for months and it's unknown if any malicious actors may have accessed it.

Sakura Internet hack exposes data of up to 1.36 million accounts
Sakura is a cloud & data center provider. This breach impacts their sales management system, which includes customer contract and membership information. Details have been scant. We will update as we hear more.

French tax authority data breach affects 678,000 individuals
An update to an older breach from August of last year. Previously we didn't know the number of people impacted, but we now know that a total of 678,000 individuals and professionals were impacted, including tax data such as reference tax income, family quotient, and withholding tax rate, and, for businesses, data such as their company name and SIREN number.

CareCloud confirms 3.7M patients had their medical records stolen in data breach
Another update to a previous data breach. This breach was previously disclosed in March without any details. We now know that it's the fifth-largest healthcare data breach in 2026 so far.


Community Discussion