Week 34

SecureFact – August 24, 2026

Major cyber incidents impacted healthcare, cloud services, government, enterprise technology, and financial organizations, exposing millions of records and sensitive personal, medical, and business information worldwide.

SickKids data breach exposes employee and job applicant info

Toronto’s Hospital for Sick Children disclosed a cybersecurity incident that exposed personal information of current and former employees, as well as job applicants. The breach stemmed from a vulnerability in third-party software used by SickKids and other organizations. Clinical systems and patient records were not affected. The hospital’s external Careers website was temporarily taken offline but has since been restored. The investigation is ongoing to determine the exact scope of the breach and number of affected individuals. SickKids has alerted all potentially impacted individuals and is offering 24 months of complimentary credit monitoring and identity protection services. The hospital has engaged outside cybersecurity experts to assist with the investigation and has notified relevant authorities of the incident.

(Source: Read full report)

Healthtech firm CareCloud data breach impacts 3.7 million patients

U.S. healthcare IT company CareCloud disclosed that a data breach incident suffered earlier in 2026 has impacted more than 3.7 million individuals. The unauthorized third party accessed one of CareCloud’s AWS environments between March 10 and March 16, 2026, and claimed to have exfiltrated data from databases within that environment. The compromised data includes full names and potentially other sensitive information, though the notification does not specify all data types exposed. CareCloud began distributing data breach notifications on July 25, 2026, providing details uncovered during the investigation. Affected individuals are being offered 12 to 24 months of identity protection service coverage through IDX, redeemable until December 17, 2026. The company has reported the incident to the U.S. Department of Health and Human Services and is working to mitigate risks for impacted patients.

(Source: Read full report)

Sakura Internet hack exposes data of up to 1.36 million accounts

Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system on August 9, 2026, potentially compromising up to 1,360,563 member accounts. The incident was discovered during investigation of a separate breach at the Sakura Rental Server service involving unauthorized logins to 583 accounts. The attackers accessed customer contract and membership information stored in the sales management system. Stored passwords are hashed and should be difficult to decipher even if stolen, and the compromised system does not store credit card information. No data exfiltration has been confirmed at this time. Sakura has invalidated all abused credentials and removed malware from its systems. The company has notified relevant authorities and is individually contacting affected customers about the exposure. Investigation continues to determine the full scope of the incident.

(Source: Read full report)

French tax authority data breach affects 678,000 individuals

The French Ministry of the Economy and Finance disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems and stole data belonging to 678,000 individuals and professionals. A threat actor using the handle “ZeroBytes” claimed the attack on August 12 and listed a stolen database for sale on the PwnForums hacking forum. The compromised data includes tax information such as reference tax income, family quotient, withholding tax rate, and for businesses, company names and SIREN numbers. Cadastral data relating to addresses and property sizes were also accessed. The attacker also claimed access to the Serveur Professionnel de Données Cadastrales (SPDC) platform with data on roughly 20 million French citizens, though only 252,149 records were allegedly stolen. Upon detection, the French tax administration shut down access to sensitive information systems and is investigating with the National Cybersecurity Agency of France (ANSSI). The ministry will contact all affected individuals starting the following week via email or letter.

(Source: Read full report)

Hacker claims 3.6 million Azure account records stolen from major companies

A threat actor using the alias “TheHatman” claimed to have stolen 3.64 million employee records from multiple Fortune 500 companies’ Microsoft Azure infrastructure using compromised credentials. The largest data dump allegedly contains 1.7 million employee records from McDonald’s, including names, employee IDs, email addresses, job titles, phone numbers, postal addresses, and service accounts. Additional breaches claimed include 800,000 records from Tata Consultancy Services, 425,000 from Vodafone, 250,000 from HCL Technologies, 185,000 from InterContinental Hotels, and records from Gap Inc., Wyndham Hotels, Hexaware, and Kyndryl. The attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue as attack vectors. Tata Consultancy Services investigated and found no credible evidence of a breach, stating the data appears to be at least four years old. Gap Inc. also found no evidence of a breach and stated the data is non-sensitive and dated back several years. Cybersecurity firm Hudson Rock confirmed the data contains authentic corporate directory attributes and service account information.

(Source: Read full report)

Apollo Global reveals data breach after hackers target financial firms

Apollo Global Management disclosed a data breach after hackers gained unauthorized access to some of its cloud platforms between July 6 and 10, 2026. The attackers accessed sensitive personal information, including names, dates of birth, contact details, home addresses, and Social Security numbers. The incident appears to have involved social engineering, with attackers reportedly impersonating IT or help-desk personnel to obtain employee credentials or MFA information. Apollo said it has not found evidence that the stolen data has been publicly released or used for fraud, but the investigation is ongoing. The breach highlights how attackers can exploit human vulnerabilities to access cloud environments and sensitive enterprise data, reinforcing the need for strong data discovery, access controls, monitoring, and protection across cloud environments.

(Source: Read full report)

Stay updated with SecureFact™

Get weekly cybersecurity insights delivered to your feed.

Subscribe