SecureFact – August 17, 2026
Major cybersecurity incidents impacted cloud communications, healthcare, supply chain, manufacturing, financial services, and cryptocurrency organizations, exposing sensitive personal, medical, corporate, and customer data.
RingCentral data breach exposed info of 1.6 million accounts
The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July 2026 through a sophisticated social engineering campaign. The breach exposed names, email addresses, phone numbers, and physical addresses of affected customers. ShinyHunters claimed to have stolen 623GB of data and leaked a compressed archive containing 280GB of files on their dark web leak site after RingCentral refused to pay ransom. The company disclosed the incident on July 28, confirming that its systems were compromised but that the core RingCentral platform and services continued to operate without disruption. RingCentral stated that no new unauthorized activity has been detected since remediation efforts were implemented. The company is communicating directly with affected customers and has not experienced any impact to core platform operations. This incident represents one of the largest data breaches targeting a major cloud communications platform in 2026.
(Source: Read full report)
311,000 Impacted by Brown Health Medical Group-MA Data Breach
Brown Health Medical Group-MA is notifying more than 311,000 individuals that their personal, medical, and financial information was compromised in a cyberattack involving a historic file server at its Hawthorn location in December 2025. Although the organization’s electronic health record system was not affected, attackers accessed files containing sensitive information, including names, contact details, Social Security numbers, government IDs, medical records, financial account and payment card information, as well as employee payroll and credentialing data. Brown Health identified the unauthorized access in June 2026, isolated the affected server, implemented additional security measures, and began employee retraining. The breach affected 311,760 people, including more than 290,000 Massachusetts residents, who are being offered two years of free identity protection and fraud monitoring.
(Source: Read full report)
Wesco confirms security incident after ExfilSquad claims data theft
Global supply chain and distribution giant Wesco confirmed it is investigating a cybersecurity incident after data extortion group ExfilSquad claimed to have stolen sensitive information from the company’s cloud CRM environment. Wesco is a Fortune 500 company with approximately 21,000 employees operating more than 700 distribution centers across roughly 50 countries, generating about $24 billion in sales annually. ExfilSquad claimed to have stolen 2.6 million records containing customer and employee personally identifiable information, account and contact data, CRM user profiles, credit and business identifiers, authentication metadata, and access information. Wesco stated that it does not believe payment card information, financial account information, or other sensitive customer or employee data is at risk. The company detected the incident quickly and found no evidence of ransomware or other malicious software on its IT systems. Wesco has not experienced any business disruption, and all operations continue as normal. The company is working with its cloud CRM vendor on the matter and has notified data protection authorities in affected countries.
(Source: Read full report)
Hacking group claims mass data theft from Shell, Philips, GE, Fiserv and dozens of others
A hacking group known as Cl0p has claimed responsibility for a large-scale cyberattack campaign targeting nearly 50 companies worldwide, including Philips, Shell, GE, and Fiserv, alleging that it stole significant volumes of corporate data. Philips confirmed that an internal enterprise server was targeted but said customer environments were not affected, while Shell confirmed it was investigating a possible incident with cybersecurity experts. Fiserv reported no evidence of compromised customer, banking, transaction, or personal data, and GE has initiated its cyber-response procedures. The attacks appear to exploit vulnerabilities in PTC’s Windchill and FlexPLM software, rather than targeting specific companies, highlighting the growing risk of attackers exploiting widely used enterprise software to conduct large-scale data theft and extortion campaigns. Reuters noted that it could not independently verify the hackers’ claims about the amount or type of data stolen.
(Source: Read full report)
Trezor discloses data breach affecting nearly 14,000 customers
Hardware wallet manufacturer Trezor disclosed a data breach affecting 13,689 customers after ShipMonk, its shipping and logistics provider, was hacked. The attackers gained access to customers’ order data including full names, shipping addresses, email addresses, and phone numbers. The breach affected customers from the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received orders between May 10 and August 8, 2026. ShipMonk informed customers that attackers exploited a critical SQL injection zero-day vulnerability in Metabase, a third-party analytics platform, to access customer data. Trezor confirmed that its own systems were not compromised and that all Trezor devices remain secure. The company warned affected customers to be wary of phishing attempts, as scammers may use the leaked information to send fake emails, make fraudulent phone calls, or impersonate banks and crypto exchanges. Trezor has implemented additional security measures and is monitoring for any suspicious activity related to the breach.
(Source: Read full report)