Data Breach Roundup (August 21 - 27, 2026)
SickKids data breach exposes employee and job applicant info
The Hospital for Sick Children (SickKids) has disclosed that the personal information of some current and former employees, as well as job applicants, was exposed in a "cybersecurity incident." The hospital says the breach stemmed from a flaw in third-party software. They have not disclosed what data was involved or how many people were impacted.

Private equity firm Apollo confirms data breach amid hacking wave targeting financial giants
Apollo is one of the largest private equity firms in the world. This was the result of a social engineering attack and access was gained between July 6 and July 10. Attackers took names, birth dates, contact information (including home addresses), and Social Security numbers. It's unclear how many people were impacted or if they were Apollo employees or an Apollo subsidiary.

Hospital operator Nutex Health says data stolen in cyberattack
Nutex Health is a for-profit healthcare company that operates 28 facilities across 12 states. Nutex has yet to determine the type of data that may have been compromised and if the impact includes patients, employees, or business partners.

LACMA data breach last year exposed social security and medical data
This breach occurred in July 2025 and exposed both customer and employee data. After concluding their investigation, the Los Angeles County Museum of Art has determined that the following information may have been accessed: full name, date of birth, Social Security number, driver's license or government-issued ID number, partial financial account numbers, partial payment card information, health insurance information, and medical information such as provider name, medical treatment, diagnosis, treatment dates, or treatment locations. The article did not specify how many people were impacted.

Carhartt data breach exposes information of 12.9 million accounts
Carhartt is an American apparel company best known for making clothes that hold up in heavy-duty, blue collar work environments. ShinyHunters claims to have breached the company on August 13 and stolen more than 50GB of data on customers, employees, and the company itself. This includes email addresses, names, phone numbers, and physical addresses.

Manchester Airports Group says hackers stole travelers' data
The Manchester Airports Group (MAG) disclosed that hackers breached its systems and stole customer data, including Wi-Fi sign-ups from Manchester, Stansted, and East Midlands airports. The intruder did not access customer payment details, and the attack had no impact on airport operations, the company said. the exfiltrated data also "relates to car park, lounge and Fast Track bookings." The list of compromised details includes customers' email addresses, phone numbers, vehicle registration numbers, and postcodes.


Community Discussion