Week 29

SecureFact – July 20, 2026

Major cybersecurity incidents impacted healthcare, professional services, retail, transportation, and enterprise SaaS platforms, exposing sensitive customer, employee, and business data while disrupting critical operations worldwide.

Abbott probes two cyber incidents amid extortion claims

Abbott Laboratories confirmed unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business. ShinyHunters extortion gang claimed responsibility and threatened to publish allegedly stolen data. According to the threat actor, attackers exfiltrated more than 30 million rows of customer personally identifiable information (PII) including names, email addresses, phone numbers, physical addresses, dates of birth, and more than one million Social Security numbers. The group also claimed to have stolen over 22 million client notes containing doctor-patient conversations, more than 20 million medical orders, and customer agreements and NDAs. The attack was conducted via vishing targeting Abbott employees in mid-June, compromising a Microsoft Entra single sign-on (SSO) account. Abbott activated incident response procedures, engaged cybersecurity experts, and notified law enforcement. A second incident involved ShadowByt3$ claiming breach of Abbott’s LabCentral portal through compromised customer credentials, though Abbott disputed the sensitivity of the stolen data, stating it contains only publicly available technical product reference documents.

(Source: Read full report)

Ernst & Young discloses data breach after support system hack

Ernst & Young notified customers of a data breach caused by compromise of a third-party support ticket system used by its IT personnel. An unauthorized third party accessed the platform between March 28 and April 12, 2026, and downloaded multiple documents. The affected information included personal and financial data contained in or used to prepare tax filings for clients. The company detected anomalous activity on April 23 and initiated investigation with external cybersecurity experts. EY secured its systems and notified federal law enforcement authorities. The company has not disclosed the exact number of affected customers or whether the incident impacts only U.S. customers or other countries as well. EY is offering affected clients 24 months of identity monitoring and restoration service through Experian. No data extortion or ransomware groups have claimed responsibility for the attack at the time of reporting.

(Source: Read full report)

Coca-Cola says Fairlife ransomware attack halts US dairy production

The Coca-Cola Company disclosed a ransomware attack impacting its Fairlife dairy subsidiary that disrupted operations and temporarily suspended production of Fairlife products across the United States. Fairlife detected unauthorized access to some of its systems, including production-related systems, in connection with the ransomware attack. The company promptly activated incident response and business continuity protocols with assistance from outside advisors and cybersecurity experts. Law enforcement was notified. Product quality and safety were not affected by the attack. Production at Fairlife’s U.S. facilities was temporarily suspended while the company responded to the incident and restored impacted systems. Canadian production operations were not currently affected. At the time of disclosure, Coca-Cola had not disclosed whether any data was stolen during the attack, whether the company was being extorted, or which ransomware operation was responsible. No ransomware gang had claimed responsibility for the attack.

(Source: Read full report)

Lidl discloses online shop breach after service provider hack

German discount supermarket chain Lidl notified customers in Germany, Belgium, and the Netherlands that attackers stole personal information in a breach at a service provider. The breach was discovered last week, with attackers stealing data from customers who used Lidl’s online shop. Despite high IT security standards, unknown individuals briefly gained access to a separately stored file containing customer data, and part of the data was stolen. The stolen data contains customer information including salutation, first and last name, telephone number, email address, date of birth, and customer number. Lidl confirmed the threat actors did not gain access to the online shop’s systems and ruled out the possibility that the breach involves affected customers’ passwords, payment information, and addresses. The supermarket giant notified the Dutch Data Protection Authority and advised affected customers to be wary of potential phishing attacks. The hacked IT service provider filed a police report and engaged IT forensic experts to investigate the full scope and impact of the incident.

(Source: Read full report)

Japan’s largest taxi operator shuts systems after cyberattack

Japan’s largest taxi operator, Nihon Kotsu, announced that its systems were compromised in a cyberattack, forcing the company to shut down part of its infrastructure. The incident occurred over the weekend, early Saturday morning, and impacted operations including the company’s taxi dispatch system, which remained offline. The company confirmed unauthorized external access and malware infection. Immediately after detecting the unauthorized access, Nihon Kotsu implemented emergency measures including disconnecting systems to prevent further damage. As a result, car hire, web booking, reservation management, telephone dispatch service, and some internal systems remained unavailable. The firm engaged external cybersecurity experts to help with investigation and system recovery and was investigating the possibility of data having been leaked. At the time of initial reporting, no data leak had been confirmed, but the company considered this possibility. The attack was later claimed by AiLock ransomware group, which threatened to leak the stolen data “soon” without setting a specific date.

(Source: Read full report)

Scope of Salesforce Attacks Expands as Icarus Leaks Data

The scope of the Salesforce data-theft campaign has expanded after attackers breached Klue, a third-party application vendor, and abused its OAuth tokens to access customers’ Salesforce data. The extortion group Icarus has claimed responsibility and begun leaking stolen information from affected organizations, with companies including Huntress, LastPass, HackerOne, Recorded Future, Jamf, Snyk, OneTrust, Tanium, and others reporting exposure. In addition to Salesforce data, the attackers may have accessed limited user information from Gong for customers that had connected Klue with Gong. While several affected companies stated that their core products, infrastructure, passwords, payment data, and customer vaults were not impacted, the incident raises concerns about exposed business contacts, sales records, API tokens, and other sensitive information stored in CRM systems. The main risk now is targeted phishing and social-engineering attacks using the leaked customer and business data.

(Source: Read full report)

Stay updated with SecureFact™

Get weekly cybersecurity insights delivered to your feed.

Subscribe