Week 30

SecureFact – July 27, 2026

Major cybersecurity incidents impacted logistics, retail, energy, financial services, government, and transportation organizations, exposing sensitive customer, employee, and government data while highlighting the growing threat of ransomware, fraud, and data extortion.

OnTrac notifies customers of data breach after network hack

OnTrac, a major parcel delivery company operating 102 locations across 35 states, confirmed a data breach affecting its customers after hackers breached its corporate network between March 20-22, 2026. The attacker accessed customer personal details including names, though the company redacted specific data elements in notification letters. OnTrac operates as a last-mile e-commerce delivery service with over 7,000 independent delivery contractors. The company contracted third-party specialists to determine the breach scope and took steps to secure exposed data. OnTrac is offering affected customers 12 months of free credit monitoring and identity protection services through CyberScout with a 90-day enrollment deadline. Customers are advised to review credit reports, place fraud alerts, or freeze credit if necessary. No ransomware groups have claimed responsibility for the attack, though the company’s statement suggests possible ransom payment to prevent data leakage.

(Source: Read full report)

Chick-fil-A data breach affects more than 13,000 customers

Chick-fil-A confirmed that over 13,000 customers had their accounts breached in credential stuffing attacks targeting its website and mobile app between June 17-19, 2026. Threat actors used automated tools and credentials obtained from third-party sources to compromise Chick-fil-A One loyalty accounts. Exposed data included customer names, email addresses, Chick-fil-A One membership numbers, account credit amounts, mobile pay numbers, and last four digits of credit/debit cards. Additional data potentially exposed included birth dates, phone numbers, and addresses if stored in compromised accounts. In response, Chick-fil-A logged out all impacted accounts, removed payment methods, restored account balances, and added rewards as compensation. The company advised customers to change passwords immediately. This represents the second major breach for Chick-fil-A, following a 2023 incident affecting over 71,000 customers in similar credential stuffing attacks.

(Source: Read full report)

Australian energy provider Origin says data breach exposes client data

Origin Energy, Australia’s largest energy retailer with 4.8 million customers, confirmed a data breach by an unknown threat actor exposing customer personally identifiable information. Exposed data includes full names, physical addresses, dates of birth, phone numbers, account information, last four digits of credit cards, and last three digits of bank account numbers. The company noted that exposed financial details are incomplete and cannot be used for unauthorized account access or charges. A threat actor claiming to be “John Doe” contacted media outlets claiming to hold data for 2 million Origin customers and threatened to leak it within two weeks unless ransom negotiations occurred. Origin CEO Frank Calabria apologized to customers and assured them the company is blocking further unauthorized access. Affected customers are being contacted directly and offered support through a dedicated portal. Origin has informed Australian Federal Police, the Australian Cyber Security Centre, and the Office of the Australian Information Commissioner about the incident.

(Source: Read full report)

Upbound says hack caused $13 million in fraudulent Acima leases

Upbound Group disclosed that threat actors stole non-sensitive customer information and documents from its systems, which were then used to commit fraud in lease-to-own agreements resulting in approximately $13 million in losses in the Acima segment during Q2 2026. Attackers used stolen customer data to obtain goods through Acima’s lease-to-own system under fraudulent agreements, with participating retailers paid for merchandise that fraudsters took without making required lease payments. Upbound immediately implemented mitigation measures including enhanced authentication controls, additional fraud-detection mechanisms, and improved monitoring with help from external cybersecurity experts. Federal law enforcement authorities were notified of the incident. The company continues investigating and will take additional action based on findings. Evidence indicates the cyberattack was not significant enough to affect investment decisions. No ransomware groups or data extortion actors have publicly claimed the attack.

(Source: Read full report)

South Korea discloses data breach impacting diplomats worldwide

South Korea disclosed that hackers breached the National Diplomatic Academy’s online education system for ten months (April 2025 to February 2026) after exploiting a server vulnerability, stealing personal information of at least 6,000 individuals including 350 current government attachés dispatched abroad. Exposed data includes IDs, names, email addresses, and encrypted passwords of individuals enrolled in the education system. The company noted that no unique identification numbers, sensitive information, mobile phone numbers, photographs, or home addresses were exposed. The breach remained undetected for ten months because the compromised server was located inside MFA headquarters and excluded from regular security scrutiny. South Korea’s National Intelligence Service discovered the breach in February 2026 and alerted the MFA. The ministry blocked access to the online education system and implemented additional security measures. Affected individuals are advised to watch for suspicious communications and report them to the ministry’s security department.

(Source: Read full report)

Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack

Swiss rail vehicle manufacturer Stadler Rail confirmed that the Everest ransomware gang breached a data exchange platform shared with one of its suppliers in mid-July 2026 and demanded approximately $12.3 million (10 million Swiss francs) in ransom. Stadler publicly rejected the ransom demand and filed a criminal complaint with Thurgau cantonal police, stating it will not pay under any circumstances. The company confirmed that neither its IT systems nor production operations were impacted and continue normally globally. Hackers stole only technical information from the supplier that is not security relevant, with no relevant personal data compromised. Stadler’s rail vehicles operating worldwide are unaffected by the data theft. Everest is a threat group that emerged in 2020 as a ransomware operation but now focuses on data theft extortion rather than encryption. The gang has not yet listed Stadler on its extortion site. Stadler previously suffered a cybersecurity incident in 2020 involving malware infection and data theft.

(Source: Read full report)

Stay updated with SecureFact™

Get weekly cybersecurity insights delivered to your feed.

Subscribe