Week 28

SecureFact – July 13, 2026

Major cybersecurity incidents impacted telecommunications, insurance, higher education, and global enterprises, exposing millions of customer, employee, and sensitive business records.

Police suspect Dutch hackers were involved in Odido data breach

Odido, one of the largest Dutch telecommunications companies, suffered a major data breach affecting 6.2 million customers. The Dutch National Police found strong indications that Dutch hackers were involved in the February breach, with attackers using vishing tactics to impersonate IT employees and gain access to customer contact systems. The attackers accessed the system on February 7 and downloaded personal data of millions of users. The exposed information varies by customer but includes full names, addresses, cities of residence, mobile numbers, customer numbers, email addresses, IBAN (bank account numbers), dates of birth, and identification details such as passport or driver’s license numbers and validity dates. The ShinyHunters extortion gang claimed responsibility and released an 88GB archive containing over 15 million records. Odido has not disclosed specific mitigation steps beyond the initial breach response, though the company confirmed no call details, location data, billing data, or password information was exposed.

(Source: Read full report)

AssuranceAmerica data breach exposes records of 6.9 million drivers

American insurance company AssuranceAmerica disclosed a data breach impacting 6,998,886 drivers after attackers gained access to its systems on March 16, 2026. The company detected the suspicious activity on March 17 and found that unauthorized third parties had accessed and copied certain data files from the IT environment. The stolen documents contained a combination of affected individuals’ names, contact information, automobile insurance policy or insurance account information, driver or vehicle information, claims-related information, and driver’s license numbers. The breach investigation was completed on June 15, 2026, and notification letters were sent to affected customers on Friday. In response to the incident, AssuranceAmerica disabled the compromised credentials, removed threat actors from the network by disabling unauthorized sessions, isolated affected systems, and notified law enforcement agencies. The company also implemented additional security measures including password resets, enhanced monitoring and threat detection tools, and provided additional cybersecurity training to personnel. Affected customers were advised to monitor credit reports and financial statements for suspicious activity.

(Source: Read full report)

Mount Royal University confirms breach as hackers claim attack

Mount Royal University in Calgary confirmed a data breach following a cyberattack on June 17, 2026, that disrupted a broad range of university systems including online services, internet access, and internal systems. The investigation confirmed that attackers stole data stored on the H drive used by students and employees for file storage, and the original copies were wiped to disrupt recovery operations. The affected data includes information on current and former students, current and former employees, and other individuals, with specific details varying by person. The attackers also wiped a separate J drive containing departmental data, with no evidence that this data was accessed before deletion, though full recovery may not be possible. The threat group CMD Organization claimed responsibility and demanded a 30 BTC ransom (approximately $1.9 million), publishing samples of stolen data including passport scans and sensitive documents. In response, Mount Royal University reported the incident to the Alberta Information and Privacy Commissioner and law enforcement authorities. The university is offering two years of credit monitoring and identity theft protection to all current employees and those employed in the past five years. System recovery is expected to take between several weeks and months.

(Source: Read full report)

Telco giant KDDI says data breach affects over 12 million people

Japanese telecommunications giant KDDI revealed that millions of people had their email addresses and passwords exposed after attackers breached an email platform used by five internet service providers on May 16, 2026. The attackers exploited a zero-day vulnerability in third-party software that was not recognized by the software vendor at the time of the breach. The incident may have exposed the email addresses and passwords of up to 14.22 million current and former customers, as well as inactive accounts. Specifically, attackers gained access to email addresses of 12,233,087 people and passwords of 7,616,173 others. Some passwords were stored in hashed and/or encrypted form, making them harder to use for account hijacking, though the company did not specify how many accounts had plaintext passwords or what encryption type was used. In response, KDDI is working to change passwords of affected customers’ email accounts, with many customers who regularly use email services already having changed their passwords. The company is working with ISP providers to complete mandatory password changes within one or two days for customers who do not frequently use email services. KDDI deployed Endpoint Detection and Response (EDR) software to detect future breach attempts and notified Japan’s Personal Information Protection Commission and the Ministry of Internal Affairs and Communications.

(Source: Read full report)

Accenture confirms breach after hacker offers stolen data for sale

IT services giant Accenture confirmed a security breach after a threat actor known as “888” claimed to have stolen 35 GB of source code and other sensitive data from the company in July 2026. The threat actor began offering the data for sale on a cybercrime forum, claiming the breach resulted in the theft of just over 35GB of source codes from the company. According to the threat actor, the stolen data includes source code, RSA keys, SSH keys, Azure PAT (personal access tokens), Azure Storage access keys, and configuration files. The threat actor provided a screenshot appearing to show them cloning an Azure DevOps repository named “121123_AtriasTalentAcademy” hosted under an Accenture.com hostname to support their claims. Accenture confirmed the breach in a statement to BleepingComputer, saying, “We are aware of this isolated matter, and we have remediated its source. There is no impact to Accenture operations and service delivery.” However, the company did not comment on the threat actor’s claims regarding the amount or type of data accessed, nor did it disclose how attackers gained access or whether customer data was affected. The same threat actor previously attempted to sell Accenture employee data following a third-party breach in 2024, and Accenture suffered a previous data breach in 2021 from the LockBit ransomware gang.

(Source: Read full report)

Stay updated with SecureFact™

Get weekly cybersecurity insights delivered to your feed.

Subscribe