Week 31

SecureFact – August 3, 2026

Major cybersecurity incidents impacted healthcare, telecommunications, artificial intelligence, residential security, banking, and e-commerce sectors, exposing sensitive patient, customer, and financial data while highlighting the growing risks of cloud breaches, credential compromise, AI security testing, and large-scale data leaks.

Amgen says cloud data breach exposed patient health, proprietary info

Pharmaceutical company Amgen suffered a confirmed data breach after threat actors stole corporate data and patient information from multiple cloud systems operated by third-party service providers. The company detected unauthorized activity in July 2026 and immediately activated its cybersecurity response plan, implementing containment measures and hiring independent forensic experts to investigate. The investigation confirmed that attackers exfiltrated sensitive data including proprietary information, patient protected health information, and other confidential materials from cloud environments. Amgen is still determining the full scope of compromised information, including whether additional confidential business information, intellectual property, research and development data, and other patient information were accessed. The company determined the incident was material on July 29 after evaluating the volume of potentially impacted files and the possibility they contained sensitive information. Amgen is continuing its investigation with third-party cybersecurity experts and evaluating legal and regulatory notification requirements. The company will notify impacted patients where required by law.

(Source: Read full report)

South Korea fines telco giant KT $39 million for customer data breach

South Korea’s Personal Information Protection Commission (PIPC) fined telecommunications giant KT Corporation KRW 53.979 billion ($39 million) for data protection violations resulting from a confirmed breach. The breach exposed personal information of 16,647 KT subscribers and caused fraudulent mobile payments of KRW 240 million ($167,400) for at least 368 customers. The point of breach was a lost KT cellular base station (femtocell) containing a valid authentication certificate that attackers retrieved and installed on a self-made device, appearing as legitimate network infrastructure. Attackers intercepted cellular traffic from nearby devices, capturing mobile phone numbers, IMSI, and IMEI numbers, then combined this data with additional personal information and captured SMS and ARS authentication codes used for mobile micro-payments. The internal network compromise persisted for nearly 11 months between October 8, 2024 and September 5, 2025 without detection. PIPC also discovered that 38 KT IT service network servers had been compromised by BPFDoor malware in March 2024, which KT failed to report to authorities. The company deleted logs from compromised servers, preventing full determination of additional data theft.

(Source: Read full report)

ShinyHunters claims Brinks Home breach, threatens to leak stolen data

Residential security company Brinks Home disclosed a confirmed data breach after hackers breached some of its systems. The company identified the attack on July 20 and immediately activated its incident response procedure to contain the breach. ShinyHunters extortion gang claimed the attack, alleging they stole more than 4.9 million Salesforce records with personally identifiable information (PII). According to the threat actor, they breached Brinks Home on July 13 using a Microsoft Entra voice phishing (vishing) attack, where they impersonated IT support staff to convince an employee to complete authentication, gaining access to the victim’s account. ShinyHunters claimed to have exfiltrated more than 1.1 million rows of customer data from the Contacts Salesforce Object, more than 4,000 rows of PII data associated with Brinks Home employees (including full names, email addresses, job titles, and phone numbers), and more than 3.8 million customer support chat logs from the Brinks Care Cresta instance. Brinks Home confirmed the attacker threatened to release information and that such material may be posted publicly. The company stated it was investigating and had not yet confirmed exactly what information was involved or whose information was affected.

(Source: Read full report)

Coupang ordered to pay data breach victims $70 each

Coupang has been ordered by South Korea’s Consumer Dispute Settlement Committee to compensate victims of its 2025 data breach with 100,000 won (approximately US$70) per person, marking the first official recognition of the company’s liability for the incident. The breach affected 33.7 million customers and exposed sensitive personal information, including names, email addresses, home addresses, apartment entrance passwords, and order histories. The committee determined that the prolonged nature of the breach and evidence that hackers contacted some victims increased the risk of misuse of the stolen data. As part of the ruling, Coupang must notify the committee within 15 days whether it accepts the mediation decision. If accepted, the settlement will have the same legal effect as a court-approved agreement, and the committee plans to require Coupang to establish a broader compensation plan for other affected customers who were not part of the initial collective claim. Separately, South Korea’s Personal Information Protection Commission previously imposed a 624.68 billion won fine and a 16.8 million won administrative penalty on Coupang over the breach.

(Source: Read full report)

Customer data from India’s Bank of Baroda leaked online, source and researcher say

Bank of Baroda disclosed that a cyber incident resulted in the exposure of a dataset reportedly exceeding 700 GB, with some reports estimating the leaked data could be close to 1 TB, although the bank has not officially confirmed the exact size or the number of affected customers. The compromised information reportedly includes customer details, identification documents, loan records, internal audit files, Aadhaar information, bank account details, NetBanking user data, and corporate and NRI banking records. According to the bank, the breach was traced to a compromised employee email account, while its core banking systems remained unaffected. In response, Bank of Baroda implemented immediate containment measures, initiated a forensic investigation, and is working with relevant authorities to determine the full scope of the incident and investigate the unauthorized access.

(Source: Read full report)

Stay updated with SecureFact™

Get weekly cybersecurity insights delivered to your feed.

Subscribe