Week 32

SecureFact – August 10, 2026

Major cybersecurity incidents impacted healthcare, financial services, retail, technology, and law enforcement organizations, exposing sensitive personal, medical, corporate, and law enforcement data while highlighting risks from cloud attacks, social engineering, and ransomware.

Unlimited Technology Systems breach impacts 3.8 million people

Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred between October 5-10, 2025. The company detected unauthorized activity in its commercial data center and launched an investigation with the assistance of a cybersecurity forensic firm. The breach exposed sensitive personal and medical information including full names, Social Security numbers, dates of birth, email and mailing addresses, phone numbers, demographic information, scans of driver’s licenses and government IDs, insurance cards, intake forms, health insurance policy numbers, claims and benefits information, medical record numbers, dates of service, and diagnosis information. The company notified law enforcement of the incident and began distributing data breach notices to affected patients on July 1, 2026. To mitigate the risk from the exposure of sensitive data, notice recipients were offered identity monitoring services through Kroll. No ransomware or data-extortion groups have publicly claimed responsibility for the breach.

(Source: Read full report)

Canadian pleads guilty to Snowflake cloud data-theft attacks

A Canadian man pleaded guilty to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. Between February and October 2024, the attacker and an accomplice accessed Snowflake accounts not protected by multi-factor authentication using logins stolen via infostealer malware. The unauthorized access was used to identify valuable information and steal terabytes of data from cloud storage instances. The stolen data included call and text history records, banking and financial information, payroll records, DEA registration numbers, driver’s license numbers, passport numbers, Social Security numbers, and other personally identifiable information. The attackers obtained at least $2.5 million in bitcoin from at least three victims through extortion, and an additional $495,000 through selling stolen information on hacker forums. More than 100 million individuals have been affected by the Snowflake attacks, with victim companies suffering more than $9.5 million in losses. Following these data breaches, Snowflake announced it would enforce MFA protection and require all passwords to be at least 14 characters long.

(Source: Read full report)

Levi Strauss & Co. says hackers stole corporate data in cyberattack

Levi Strauss & Co. disclosed that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines. The company filed a disclosure with the U.S. Securities and Exchange Commission stating that certain corporate information was accessed and exfiltrated as a result of the incident. The company’s rapid response efforts successfully contained and terminated the unauthorized access, and no consumer data was impacted according to the company’s statement. The investigation launched in response to the incident remains ongoing, with additional notifications to be provided to affected parties as required. Based on the findings of the investigation to date, Levi’s does not believe the incident will have a material impact on its business or financial position. The company has not experienced any operational disruptions as a result of this breach. Some media outlets have linked this incident to UNC6671, an extortion group associated with a recent wave of voice phishing attacks targeting hundreds of organizations. Until more information becomes available, holders of Levi’s shop accounts should monitor for suspicious activity and promptly report it to the firm.

(Source: Read full report)

ExfilSquad hackers leak info of over 100,000 UK police officers, staff

A cyberattack on the U.K.’s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals. The ExfilSquad threat actors were responsible for the breach and subsequently leaked the information. The compromised data includes contact information for police officers and criminal justice professionals across the United Kingdom. The breach represents a significant security incident affecting law enforcement personnel and the broader criminal justice system. The exposed contact data could be used for targeted phishing attacks, social engineering, or other malicious purposes against law enforcement and justice system personnel. The incident highlights the vulnerability of government databases to cyberattacks and the need for enhanced security measures to protect sensitive information about law enforcement personnel. Authorities have been notified of the breach and investigations are ongoing to determine the full scope of the compromise and implement remediation measures.

(Source: Read full report)

South Africa’s largest private security company suffers data breach

South Africa’s largest private security company, Fidelity Services Group, suffered a cyberattack in July 2026, with the ransomware/extortion group Ransomhouse claiming responsibility and publishing data allegedly stolen from the company. Fidelity confirmed that some of its systems were affected and said it isolated the impacted systems, launched an investigation with cybersecurity specialists, and notified South Africa’s Information Regulator under POPIA. The company stated that no customer or third-party information was compromised, although cybersecurity experts advised caution given the nature of the leaked information. The incident highlights the risks organizations face when sensitive operational and personal data is exposed and reinforces the importance of strong data protection, monitoring, access controls, and incident-response measures.

(Source: Read full report)

Stay updated with SecureFact™

Get weekly cybersecurity insights delivered to your feed.

Subscribe