Data Breach Roundup (July 17 - 23, 2026)
Ernst & Young discloses data breach after support system hack
EY is one of the four largest auditing and "professional services providers," offering tax, consulting, and transaction advisory services to major companies in more than 150 countries. This breach took place over March and April. It's unclear exactly what data was taken or how many people were impacted, but it includes personal & financial data "contained in or used to prepare tax filings."

Abbott probes two cyber incidents amid extortion claims
Abbott Laboratories is an Americal medical devices & healthcare company that produces pharmaceuticals, diagnostic products, nutritional products, and medical devices. They operate in over 160 countries and are a Fortune 500 company. The first incident involves ShinyHunters and includes more than 30 million rows of customer names, email addresses, phone numbers, physical addresses, dates of birth, and more than one million Social Security numbers from their Cancer Diagnostics business. The second incident involves the ShadowByt3$ threat actor and Abbott's LabCentral customer portal, but only contains corporate data and not any personal or customer data.

Hugging Face confirms breach affected internal datasets and credentials, urges users to take action
Hugging Face is a platform that hosts AI models for public use. The company disclosed last week that a dataset that was uploaded abused a security vulnerability that resulted in privilege escalation. The company has urged users to rotate credentials and keys. OpenAI later owned up to the breach and claimed that it was an AI agent that escaped containment. Hugging Face claims to have fixed the vulnerability.

Hackers stole ‘significant’ amount of data from tech firm relied on by thousands of US hospitals and pharmacies
Craneware is a UK-based healthcare billing software maker. The company has said that a "percentage" of employee & customer data and partner records had been stolen by the attackers. There is no other information at this time.

Estée Lauder discloses data breach via Oracle E-Business flaw
Cosmetics giant Estée Lauder is notifying employees of a data breach that occurred in August but was only detected last month. Data includes full names, postal address, email address, date of birth, Social Security number, passport number, financial account information including bank account numbers, health information, and employment information including payroll & performance reports. The number impacted was not disclosed.

AI music generator Suno breach affects 55M users, per Have I Been Pwned
A recent article from 404 Media discussed how a Suno source code breach revealed that the company scraped sources like Deezer, Genius, and YouTube to train it's AI models. Among this breach, however, was also a significant amount of user data, including customer names, physic and email addresses, purchases, and partial payment card numbers & expiration dates. The company confirmed this when asked, but has not publicly made a statement or contacted users.

Chick-fil-A discloses data breach after credential stuffing attacks
Chick-fil-A is the third largest "quick-service" restaurant in the US and also has a presence in Canada, Puerto Rico, the UK, and Singapore. The breach occurred in June and impacted the website and mobile app. Impacted data includes customer names, email addresses, membership numbers & mobile pay numbers, QR codes, amount of Chick-fil-A credit, and last four digits of card number. In some cases attackers could've also access birth dates, phone numbers, and addresses.

South Korea discloses data breach impacting diplomats worldwide
Attackers breached South Koreas National Diplomatic Academy for 10 months and stole the personal data of current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. The incident occurred between April 2025 and February 2026 and impacts at least 6,000 individuals including 360 current government agents abroad. Information leaked includes IDs, names, email addresses, and hashed passwords. The MFA claims that no unique ID numbers, sensitive information, mobile numbers, photos, or home addresses were exposed.

Australian energy provider Origin says data breach exposes client data
The number impacted is unknown, but the article says that Origin has 4.8 million customers and is Australia's largest energy retailer. Impacted data includes full name, physical address, date of birth, phone number, "account information," last four digits of credit card, and/or last three digits of bank account.




Community Discussion