Editor's Message

Welcome to DBD. On March 8th 2026, DBD celebrated it's sixth anniversary and PRiSM celebrated it's third anniversary. Both projects have made a huge impact on my life and I'd like to thank each and everyone of you who have supported me, with special thanks to those individuals and communities who have helped me build up my knowledge on cybercrime and ransomware over the years. Thanks again for all your continued support. Stay safe. :)


“Data Breaches Digest and its PRiSM portal provide Dentons Global Security Team with valuable insights into the ransomware landscape, from the latest incidents to trends over time, as well as the ability to customize visual analytics. Timely reports and tracking by Data Breaches Digest help inform cyber intelligence for the world’s largest law firm and thus our cybersecurity posture across more than 80 countries worldwide.”
Dentons Senior Analyst, Washington D.C.



Monday, 20 July 2026

Data Breaches Digest - Week 30 2026

Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 20th July and 26th July 2026.


21st July

79% of ransomware attacks now originate from compromised identities

79% of Ransomware Attacks Start with Compromised Identities

A New Ransomware Threat Actor Emerges Every Week

AgentBaiting: Fake AI Skills Trick Claude Code, Gemini, and ChatGPT Into Spreading Malware

AI agents are still logging in as humans

AI agents tricked into recommending malicious GitHub repositories

AI music generator Suno breach affects 55 Million users, per Have I Been Pwned

AI-generated reports push GNOME to shorten its disclosure window

Akamai Warns of Fraudulent AI Agent Activity Aimed at E-Commerce Sites

ApolloMD Agrees to Pay $4.02 Million to Settle Data Breach Lawsuit

Asia-Pacific cyber threats rise on AI & geopolitics

Australia: GO2 Health medical clinic in Brisbane waited almost three months to alert patients it was hacked

Australia: New South Wales (NSW) accounting and advisory firm allegedly hit by SafePay ransomware

AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code

Coca-Cola Fairlife hack claimed by Anubis ransomware

Coca-Cola Fairlife ransomware attack halts production as cyber threats to operations grow

Craneware Confirms Data Theft After Cyberattack, Investigations Underway

Craneware Exposes Significant Data Theft in Monday Data Breach

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public Proof-of-Concept (PoC)

Critical wp2shell WordPress flaws exploited to install webshells

Cyberattack Halts Coca-Cola’s Fairlife Productions

Ernst & Young breach exposes client tax data - find out if you're at risk and what to do next

Estée Lauder Confirms Data Breach: SSNs, Passport Numbers, and Health Data Exposed via Oracle EBS Exploit

Estée Lauder Confirms Cyberattack Affecting Personal Information

Estée Lauder discloses data breach tied to Oracle EBS vulnerability

Fake FBI agents target people who already got scammed

Fake FBI Agents Use Internet Crime Complaint Center (IC3) Complaints to Target Scam Victims

Fake Troubleshooting Prompts Trick Online Banking Users in Spain and Portugal into Installing Trojans

FBI Warns of Deepfake Videos Impersonating Internet Crime Complaint Center (IC3) Leadership

Global car rental service data leak exposes thousands of drivers

Got an email from X about a suspicious login? It can be a phishing scam

Government ransomware attacks rose 13% globally to 187 incidents in first half of 2026, with The Gentleman most active

Hacked! Ernst & Young informs clients of third-party data breach

Hackers Already Exploiting Newly Patched WordPress Flaws, Researchers Warn

Hackers Exploit Palo Alto PAN-OS Flaw to Deploy Qilin Ransomware

Hackers Exploiting Palo Alto’s PAN-OS Vulnerability to Deploy Qilin Ransomware

Healthcare Software Provider Craneware Announces Data Breach

Here’s How A Hacker Allowed Google’s AI To Do 89% of the Crime

How AI and ransomware are reshaping cybersecurity

How ransom attacks on small businesses open doors to larger organisations

Hugging Face confirms data breach by AI agent: Why it has sparked a debate on cyber guardrails

JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data

JadePuffer returns with ransomware built to target AI models and infrastructure

Kentucky part of multi-state 23andMe data breach settlement

Kenya probes hack of president's website after bitcoin ransom demand

Major US hospitals partner Craneware confirms data breach

Makeup giant Estée Lauder says hackers accessed Social Security numbers

Malaysia: Telco identifies suspect in data breach as Malaysian Communications and Multimedia Commission (MCMC) demands full report

New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

New Zealand: Ministry apologises after data breach affects 276 student records

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

Paidwork Data Breach Exposes 23.3 Million Accounts, Banking Data and bcrypt Password Hashes

PhishByte warns Essential Eight misses phishing risk

PR3TACK preemptive framework maps threats before attackers use them

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

Ransomware detections among Indian SMBs rise in Q1 2026

Received a ‘KrisFlyer Anniversary Draw’ e-mail? It could be a phishing scam, Singapore Airlines warns

Research says JadePuffer Ransomware wipes off data on AI Model Infrastructure

Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Pros

Reynella East College updates parents, carers following June data breach

Russian Hacker Turns Jailbroken Claude Into Pentest Platform

Scammers Are Impersonating Internet Crime Complaint Center (IC3) Using Fake Profiles and AI-Generated Videos, FBI Updates Warning

Singapore Airlines warns against phishing scam in 'KrisFlyer Anniversary Draw' emails

SonicWall SMA zero-days were exploited weeks before disclosure

South Korea: Seoul Notifies 4.62 Million of Ttareungyi Data Breach, Offers Free Passes

South Korea: Seoul to compensate 4 million bike-sharing users after data breach

South Korea Confirms Cyberattack on Diplomatic Academy, Data of 6,000 Diplomats at Risk

Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack

Suno Data Breach: 55 Million Emails and Stripe Records Exposed

UK government scraps plans for digital ID cards after millions of Brits opposed

US Hospital Finance Software Provider Craneware Reports Data Theft

'Was this you?': Scammers using phishing techniques to hijack X accounts

Windows LegacyHive zero-day flaw gets free, unofficial patches

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

20th July

23andMe Pays $18 Million to Settle Multistate Data Breach Lawsuit

271 million Uber Eats and Starbucks records surface on hacker forum: Should you be worried?

AI agents just doubled inside the enterprise. Confidence rose faster than control did

An AI agent breached Hugging Face before an AI defender caught it: What users should do next

Attackers Combo Up Evasion Tactics for BEC Phishing

Australia: Crypto scam losses of $1.47 million in five days sparks Queensland police alert to new phishing threat

Centers Laboratory Discloses Data Breach Affecting 542K Individuals

Chinese police repatriate key suspect in phishing and Trojan virus case from Vietnam

Clover Health hit with data breach

Clover Health reveals data breach in SEC filing

Coca-Cola Company’s Fairlife targeted in ransomware attack

Coca-Cola’s Fairlife halts U.S. production after ransomware attack

Community College of Beaver County (CCBC) Data Breach Exposes Social Security Numbers and More

Craneware confirms data breach after cyberattack

Craneware Confirms Data Breach, Employee Records Among Exposed Data

Craneware reveals cyber attack with employee and customer data stolen

Critical ServiceNow code execution flaw now exploited in attacks

Cruciferra Crypter Uses Process Ghosting to Evade Detection

CVE-2026-42533 Exposes Critical Pre-Auth nginx RCE Flaw

Cyber Attack Against Major Milk Producer Could Lead To A Milk Shortage

Cyberattack hits Coca-Cola's $4 billion dairy brand, suspends US production

Cyberattack pauses Fairlife’s production, working to learn about impact on Webster plant

Data breach hits well-known AI company: ‘Sorry for any disruption’

DocuSign Phishing Kit Delivers RMM Tools to Windows and macOS

Don’t run into these ‘Gentlemen’. More on this Ransomware gang

Ecopetrol confirms ransomware attempt, data stolen from 3,300 accounts

Edinburgh-based healthcare firm 'hit with cyber attack' as hackers steal data

Ernst & Young Data Breach Affects Personal, Financial Information

Ernst & Young data breach exposes personal and financial information of tax clients

Ernst & Young reveals data breach following hack on support system

Estée Lauder discloses data breach via Oracle E-Business flaw

Experts Advise iPhone Users to Turn Off AirPlay to Prevent Hacker Threats via Public Wi-Fi

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

Fairlife Ransomware Attack Hits Production Systems, U.S. Operations Suspended

Fairlife shortage looms after ransomware hits Coca-Cola plants

Fairlife stops US milk production after ransomware attack

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

Family Partnerships Data Breach Exposes SSNs and Financial Account Information

FBI Arrests Florida Man in $220,000 Steam Crypto Theft Case

Free Archive Program 7-Zip Can Be Hacked With a Malicious File

‘Frustrated and stressed’: Thousands impacted by cyber attack at Calgary university

Governments Weigh Ransomware Payment Bans as Hackers Grow Bolder

Hacker stole from Steam users for years, got caught because he ordered food online

Hacker wipes European country’s entire land registry database, paralyzing real-estate market

Hacker wipes Romania's entire land registry database

Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk

Hackers Are Hiding Invisible Text in Phishing Emails to Fool AI Security Tools

Hackers steal $23.7 million in crypto from Ostium in off-chain attack

Hackers stole ‘significant’ amount of data from tech firm relied on by thousands of US hospitals and pharmacies

Hackers were inside South Korea's diplomat training system for 9 months

Health tech firm Craneware admits “significant volume” of customer and employee data exposed in cyber attack

Health tech firm Craneware says customer and staff data stolen in cyber attack

Healthcare phishing breach exposes SSNs, medical records for 15 months

Healthcare ransomware attacks up 14% in first half of 2026

Heart Care Centers of Illinois Data Breach Compromises PHI and PII

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel

How receding Ransomware payments are reshaping the Economics of Cyber Extortion

Hugging Face: We Used AI to Catch the First Confirmed AI Agent Breach of a Major AI Platform

Hugging Face breach reveals why defenders need their own AI models on standby

Hugging Face breached by autonomous AI agent

Hugging Face confirms breach affected internal datasets and credentials, urges users to take action

Hugging Face Confirms Data Breach Caused by Autonomous AI Agent

Hugging Face Hacked in Autonomous AI Attack

Hugging Face Says Autonomous AI Agent System Breached Production Infrastructure

Hugging Face says it resorted to a Chinese AI model to battle a fully autonomous cyberattack because U.S. model guardrails stymied its defense

Hugging Face warns an autonomous AI agent hacked its network

Identity-based attacks overtake software flaws as leading ransomware entry point

India: Data breach exposes documents tied to Kudankulam nuclear plant expansion

India says allegedly leaked nuclear plant files pose no safety risk

Information Commissioner Notified After Data Breach Concerns At Former West Sussex County Council Buildings

Italy fines WINDTRE €1.7 million over security flaws behind two data breaches

Jadepuffer: Agentic attack evolves to destroy AI models

JadePuffer agentic attacks now target AI model data with ransomware

JadePuffer Returns With Ransomware Designed to Wipe AI Models

Kenya restores presidential website after cyber attack

Kenya’s Presidential Website Hit by Cyber Incident, Government Says No Data Was Stolen

Kentucky included in settlement with 23andMe following 2023 data breach

LG Monitors Spotted Installing Adware-Like App on Windows PCs

Little Flower Data Breach Exposes Health Information and SSNs

Minnesota Health Insurance Network Data Breach Exposes PHI and PII

Mythos Didn't Break Your Security Program. Your Exposure Window Could

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications

New HollowGraph malware uses Microsoft Graph for stealthy C2 comms

New X phishing scam uses fake login alerts to steal your account

Oak Hill Data Breach Exposes SSNs and Medical Information

One threat that infiltrated the ANC, Anglo American, Mediclinic, South African Airways, and Pick n Pay

Paidwork breach exposes sensitive data of 23 million user

Paidwork Data Breach Exposes 23 Million User Records, Have I Been Pwned (HIBP) Says

Plugging an LG monitor into a Windows computer installs a potentially unwanted program

Police Chiefs Cite Transport for London (TfL) Hack in Push for Cybercrime Risk Orders

Qantas goes unpunished for staggering data breach

Ransomware attack disrupts fairlife’s US production

Ransomware attack forces Coca-Cola to suspend US production at dairy unit

Ransomware attacks hit SMBs harder than ever as cybercrime gang rivalry heats up

Ransomware detections on Indian SMBs is on the rise

Researchers Build WordPress Exploit Using OpenAI's GPT

Resource Center of Dallas Data Breach Affects At Least 9k Individuals: SSNs Exposed

Romania races to restore land registry after cyberattack disrupts property market

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine

Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs

Sefas Innovation Data Breach Impacts Banks: Personal and Financial Info Exposed

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

Software provider to more than 2,000 US hospitals says hackers stole employee and customer data

SonicWall SMA1000 flaws exploited as zero-days to push custom malware

South African industrial giant that makes chemicals targeted by one of the world’s most notorious ransomware groups

South Carolina will receive $280,000 in 23andMe settlement after data breach

Thailand: Base-education hacker arrested in Phuket

The Gentlemen deploys new malware to take control of systems before encryption

The New Cyber Frontier: Ransomware Surges as AI Deepfakes Expose Corporate Vulnerabilities

The Odyssey piracy scams surface hours after its theatrical debut

The Rise of Calendar Phishing

The Windows 10 hangover is becoming a security problem

Threat Actors Allegedly Listed Starbucks Data on Hacker Forums

U.S. court seizes $8.37 million in crypto from ransomware negotiator accused of aiding hackers

U.S. Prosecutors Charge Russian Trio in Cybercrimes Causing More Than $62 Million in Losses

United Arab Emirates: Dubai Police Warns Against Online Scams Promising Work and Visit Visas

Unpatched SharkNinja flaw turns vacuum cleaner into a spy, reveals house maps, WiFi passwords

Why Security companies can’t create an invincible Vaccine against Ransomware

WordPress Critical RCE Security Flaw a Threat to Millions of Websites

WordPress urges immediate update: hackers are gaining full control with a critical exploit

World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

wp2shell: The Unauthenticated WordPress Exploit That Needs No Login, No Plugins, Just a Vulnerable Core

X users are being hit by fake login alerts: the phishing emails look real

Zero-Day Hack Exposes South Korean Diplomatic Academy to Massive Data Breach