SecureFact – June 15, 2026
Major breaches across e-commerce, healthcare, government, education, utilities, and financial services exposed millions of records and sensitive customer data worldwide.
Coupang hit with record $409 million data breach fine in Korea
South Korea’s Personal Information Protection Commission (PIPC) fined e-commerce giant Coupang a record 624.6 billion won (approximately $409 million) following a massive data breach affecting more than 37.55 million customers. The breach exposed personal information including names, addresses, phone numbers, and authentication credentials due to inadequate security practices, including failures in authentication key management and access controls. The primary suspect is a 43-year-old Chinese national who worked in Coupang’s IT department between 2022 and 2024 and retained access to the company’s systems. The attacker accessed millions of accounts but retained user data for only approximately 3,000 accounts, which was subsequently deleted from all devices. Coupang announced plans to pay 1.685 trillion won (approximately $1.17 billion) in compensation and distribute single-use purchase vouchers totaling 50,000 won (about $34) per customer to over 33 million affected customers. The PIPC also cited violations of data destruction and leak-notification requirements, interference with the independence of Coupang’s data protection officer, and obstruction of the investigation. This breach represents one of the worst data incidents in South Korea’s history, occurring in late June but discovered only in mid-November 2025.
(Source: Read full report)
Pharma giant Novo Nordisk discloses breach of clinical trials data
Danish pharmaceutical giant Novo Nordisk, the world’s largest producer of insulin and maker of viral GLP-1 drugs Wegovy and Ozempic, disclosed a data breach affecting patient information from clinical trials. Attackers gained access to internal IT systems and copied non-public data including patient IDs (random alphanumeric strings), trial participation information, sex, year of birth, biomarkers, health/immunogenicity data, and lifestyle factors such as smoking, alcohol use, and BMI. The company emphasized that the data was pseudonymized and cannot be used to identify affected patients by name, as identifying information was not exposed. Additionally, healthcare professionals’ names, registration numbers, email addresses, phone numbers, WhatsApp details, and office locations were compromised, making them potential targets for phishing attacks. Novo Nordisk took compromised internal IT systems offline but confirmed core business operations were not impacted. The company is investigating the incident with external cybersecurity experts to assess the full impact and scope. Novo Nordisk has yet to disclose when the breach was detected or how many individuals had their personal and patient data exposed.
(Source: Read full report)
Japanese energy firm loses drive with data of 10.9 million clients
Kyushu Electric Power Co., Inc., one of Japan’s major regional electric utilities, disclosed a physical security incident affecting private data of more than 10.9 million customers. On April 27, IT staff used an external storage device for backup purposes due to server storage capacity constraints. The drive was stored in a server room cabinet protected by multiple physical security layers, but on May 26, IT staff discovered the cabinet had been left unlocked and the drive was missing. The missing drive contained customer names, service location addresses, electricity usage data, telephone numbers, names of retail electricity providers, and other related information. The company clarified that no bank account information or credit card data was stored on the drive. Since the loss, the firm interviewed all 57 personnel who had access to the server room and conducted investigations but could not locate the device. Kyushu Electric filed a police report on June 4, suspecting unauthorized removal of the device. The Japanese Ministry of Economy, Trade, and Industry gave the firm until July 8 to report all details about the incident and preventative measures. The incident has been reported to Japan’s Personal Information Protection Commission and relevant government authorities.
(Source: Read full report)
Over 73,000 French govt employees affected in Tchap messenger breach
The French government revealed that a recent breach of its Tchap encrypted messaging platform affects the accounts of over 73,000 employees in the French public sector, representing approximately 9% of the platform’s 825,000 registered users. A threat actor gained access using a compromised user account through social engineering and was able to steal all data shared in public chat rooms, which are not encrypted. Exposed data includes users’ names, email addresses, avatar images, and the public sector organization they work for. The attacker also allegedly stole over 13.5GB of documents and media files shared by public servants, nearly 650,000 messages, and hardcoded LDAP credentials leaked via a PowerShell script. While private conversations remain encrypted and protected, the attacker accessed extensive metadata and organizational information. The compromised account was immediately blocked to remove persistent access and allow in-depth analysis. Tchap, developed by DINUM in collaboration with ANSSI (the French Cybersecurity Agency) in 2018, became the default app for work communications for all civil servants in early August 2025 and has over 500,000 downloads on Google Play Store.
(Source: Read full report)
Nottingham University data breach affects over 450,000 students
The University of Nottingham confirmed that a hacking group gained access to its student records system in a breach affecting both current students and alumni, with 454,600 individuals impacted according to breach notification service Have I Been Pwned. The ShinyHunters extortion gang claimed responsibility and shared an archive of allegedly stolen documents as proof, claiming to have stolen over 40GB of documents containing student finance data, billing and payment information, credit card and payment details, and campus portal exports from the University of Nottingham and its Malaysia and China campuses. Exposed data includes affected students’ full names, home addresses, IP addresses, phone numbers, dates of birth, email addresses, ethnicities, disabilities, passport numbers, and information relating to academic enrollments and fee payments. This attack is part of a widespread data theft campaign in which ShinyHunters has stolen data from over 100 organizations worldwide after breaching their cloud and on-premises Oracle PeopleSoft instances. The University of Nottingham is a public research university with 7,000 staff and over 46,000 students, ranking in the Top 20 in the United Kingdom and Top 100 worldwide. The university reported the incident to the UK’s Information Commissioner’s Office and Action Fraud.
(Source: Read full report)
ServiceNow discloses security incident exposing customer data
ServiceNow disclosed a security incident after attackers exploited an unauthenticated access flaw through a vulnerable API endpoint, allowing them to query data from customer instances. The company applied a security update to hosted customer instances on June 5, 2026, addressing a security issue that could allow unauthenticated users to gain greater access to ServiceNow instances than intended. The vulnerability pertained to a REST endpoint at ‘/api/now/related_list_edit/create’ that was configured with ‘requires_authentication=false’, potentially allowing unauthenticated requests to access instance data. ServiceNow confirmed that attackers exploited this flaw to successfully query customer instance tables. ServiceNow instances commonly store sensitive enterprise information including IT support tickets, employee records, internal documentation, asset inventories, security incident reports, workflow data, and configuration details for corporate systems and services. The issue primarily impacts customers running the Australia platform release or customers on older releases who made certain configuration changes. ServiceNow received a confidential bug bounty submission describing a similar issue on April 22, 2026, but did not apply the security update until June 5, after activity targeting customer instances reportedly began days earlier. The company later stated it believes the observed activity was likely tied to security researchers or customer-led research associated with bug bounty submissions rather than malicious threat actors.
(Source: Read full report)
SoFi confirms third-party data breach at Hong Kong subsidiary
SoFi Hong Kong, the Hong Kong subsidiary of U.S.-based financial technology company SoFi, disclosed a data breach after hackers gained unauthorized access to a database at a third-party vendor containing customer information. The company discovered the incident on April 30, 2026, after detecting unauthorized access to a database of SoFi Securities (Hong Kong) Limited via one of its vendors. After discovering the incident, SoFi engaged with a third-party cybersecurity firm to respond to the breach. The company’s investigation is ongoing and SoFi stated it does not yet know which specific data may have been exposed or the complete scope and impact of the incident. SoFi warned customers to remain vigilant for phishing attempts, suspicious communications, and unusual account activity. The company advised customers to update passwords, enable two-factor authentication where possible, monitor financial accounts for suspicious activity, and avoid opening links or attachments in unsolicited emails or messages. SoFi added additional safeguards and monitoring to affected accounts and may request additional verification information from customers who contact support or make account changes. The company declined to answer additional questions regarding the incident, including how many customers were affected, whether the company was extorted, or the identity of the third-party vendor involved.
(Source: Read full report)