Data Breach Roundup (Aug 28 - Sep 3, 2026)
Toy-making giant Hasbro disclose data breach affecting employees
The company has not disclosed the number of people impacted, but said data affected potentially includes email, address, phone number, national ID number, or financial information. The breach also affected the Social Security numbers, financial account information, credit/debit card numbers, and driver's license information of 436 Hasbro employees in Massachusetts. The incident likely took place around March 28, as that's when Hasbro disclosed a cyberattack and temporarily took systems offline.

McKesson discloses breach after ShinyHunters claims patient data theft
McKesson is a US "healthcare and pharmaceutical distribution giant." This incident was discovered on August 25 with attackers claiming they stole 284 million patient data records. ShinyHunters claims the stolen information includes names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers, medical record numbers, medication and allergy information, illnesses, disabilities, appointment information, and physician information. The group also claims the data contains information related to deceased and terminally ill patients, prescriptions and medication shipments, invoices, employee information, Salesforce records, internal communications, and healthcare providers and clinics using McKesson's services. Investigation is ongoing.

FulcrumSec claims Manchester Airports hack, theft of 86 GB of data
Last week, the Manchester Airports Group disclosed that they had a data breach impacting customers at their Manchester, London Stansted, and East Midlands airports, but had little else to share. We now have a rough idea of the data taken, including consolidated profiles that combined customer identifiers with historical booking activity and marketing classifications, and nearly 200,000 records related to upcoming travel during the remainder of 2026. These records allegedly contain dates, times and booking information linked to personally identifiable information. Beyond the email addresses, phone numbers, vehicle registrations and postcodes disclosed by MAG, sampled records contained purchase and booking references, airport and product selections, prices, discounts, booking status, parking dates and times, historical spending, IP addresses, approximate locations, device information and customer-engagement data.

Berlin confirms data theft after Rhysida ransomware attack claims
The threat actor claims to have exfiltrated 5.79 TB of data, comprising approximately 1.44 million files, from Berlin’s administrative network. According to the attacker, they exfiltrated:
- Government, legal, financial, contractual, HR, infrastructure, health, and mapping records.
- Thousands of names, email addresses, phone numbers, and 148 IBANs.
- Plaintext credentials, database accounts, payment-system data, password vaults, and credentials belonging to senior officials.
- Personnel files, payroll information, administrative-offense records, email archives, SQL database dumps, identity documents, and banking information.\
- Documents related to disciplinary proceedings and other named cases.
- Allegedly classified or sensitive government material, including Bundesrat committee records and information about handling classified documents.
- Critical-infrastructure security assessments concerning Berlin’s water supply.
- More than 3,200 documents marked as nondisclosure agreements.

Novocure data breach affects more than 1,400 cancer patients
Novocure is a global oncology company knowing for inventing a non-invasive electromagnetic field therapy for cancer tumors. The attackers accessed over 1,400 U.S. patient records with ID numbers, but those records didn't contain patient names or other identifying data. However, for fewer than 50 other patients in the western U.S, the threat actors accessed identifying information and general contact information for healthcare providers. The data breach also exposed contact information for an undisclosed number of Novocure employees, including job titles and phone numbers.

Aesto Health says data breach affects over 9.5 million patients
Aesto provides software-as-a-service that healthcare organizations can use to migrate, archive, and access patient data when replacing electronic health record systems or acquiring medical practices. This intrusion occurred in December 2025 and impacted full names, dates of birth, medical information, driver’s license numbers, financial account numbers only, health insurance information, individual taxpayer identification numbers, other government identification numbers, and Social Security numbers. The incident indirectly impacts 29 healthcare providers, including VillageMD, Everside Health (Marathon Health), Marana Health, and Together Women’s Health.

FBI Probes Service Selling 153M+ Drivers Licenses
This week, investigative independent journalist Brian Krebs wrote about a service called Nexus that claimed to have more than 153 million drivers licenses for people in the US and Canada, as well as more than 10 million ID cards, more than 3 million "travel documents and/or international IDs," and at least 579,000 medical cards. The source of the breach seems to lead back to IDScan.net, an age verification service. The story has since been picked up by several mainstream outlets.

French hospital fined €500,000 after breach exposes data of 727,000
Hôpital privé de la Loire (HPL) is a general hospital in Saint-Étienne, part of the Ramsay Santé healthcare group, providing medical, surgical, maternity, cancer, intensive-care, and emergency services. HPL suffered a data breach in summer of 2025 affecting 524,000 patients and just over 200,00 "trusted third parties." CNIL's investigation found several shortcomings in the hospital's GDPR obligations such as lack of MFA or VPN requirements, inadequate access controls, lack of monitoring and alerting tools, and failure to notify the third parties of the breach.

Community Discussion