Over 7,419 large healthcare data breaches involving 500 or more records have been reported to the Office for Civil Rights since 2009, cumulatively affecting 935.5 million individuals, approximately 2.6 times the US population. SimonMed Imaging, an Arizona-based radiology practice, reported a January 2025 healthcare data breach stemming from a cyberattack that impacted 1.27 million individuals. Cloudflare’s support systems contain case records from thousands of enterprise clients, meaning stolen support case data could include API credentials, internal architecture details, network configuration information, and vulnerability disclosures submitted by Cloudflare customers in the course of resolving technical issues.
The campaign targeted packages with combined weekly downloads exceeding 50 million, meaning the malicious code ran inside thousands of development and production environments before detection. The second involved a threat actor using stolen OAuth credentials to access customer service case records across a subset of Zendesk’s enterprise accounts. Zendesk confirmed two separate unauthorized access events in October 2025, both originating through compromised vendor integrations rather than direct platform exploitation.
What is confirmed is that named downstream victims include Qantas (5.7 million customers), Stellantis, Farmers Insurance, and several financial institutions whose data appeared in ShinyHunters’ extortion materials. The claimed scope, 1.5 billion CRM records spanning hundreds of global enterprises, has not been independently verified at that figure, and Salesforce has disputed the top-line number. The campaign began as https://mobaon.net/soundcloud-app-songs-downloaden/ early as June, remained undetected across multiple affected organizations through August, and became public knowledge in September when ShinyHunters began contacting victims directly with extortion demands. The Salesforce breach of 2025 was less a single incident than a months-long campaign by ShinyHunters that used compromised OAuth tokens and third-party integration weaknesses to move laterally across Salesforce-connected enterprise environments.
Marks & Spencer Ransomware Attack
The first is surface-level security posture monitoring, continuous scanning of vendor-exposed infrastructure for known vulnerabilities, misconfigured cloud storage, expired TLS certificates, and open RDP or SMB ports. A vendor that passes a security assessment in January can be breached in February, remain undisclosed until October, and have your data https://givewebhosting.com/firebase-alternatives.html circulating on dark web markets for nine months while your vendor risk program shows them as green. Supply chain attacks reached 1,251 downstream victim organizations in 2025, nearly double the prior year, from a marginal increase in discrete attacks, meaning each supply chain attack is reaching more downstream targets than before. The Salesforce campaign’s success in 2025 was partly attributable to the fact that the exfiltration activity generated signals in Salesforce audit logs, OAuth management consoles, and network monitoring systems simultaneously.
How do I prevent data breaches?
- Once the exact way that the data was compromised is identified, there is typically only one or two technical vulnerabilities that need to be addressed in order to contain the breach and prevent it from reoccurring.
- The customer service agent’s account has been locked and the company is in the process of ensuring that no persistent threat remains on their devices or network.
- According to the Cost of a Data Breach 2025 report, stolen or compromised credentials is one of the top five most common initial attack vectors, accounting for 10% of data breaches and taking up to 186 days to identify.
- Five Below disclosed that a threat actor used social engineering to access an employee computer and exfiltrate files before the intrusion was contained.
- The hack was disclosed by Progress Software, makers of MOVEit, and since then, many companies have reported being affected.
The Finastra data breach, disclosed in January 2025 following a November 2024 intrusion, saw a threat actor who had been selling 400GB of stolen data on dark web forums, with Finastra confirming the theft originated from its SWIFT messaging and managed file transfer platform, used by banks globally to move funds and process interbank settlements. Beyond the major four, the regional banking and credit union sector absorbed a sustained wave of incidents throughout the year. Regulatory filings in multiple states confirmed the breach affected tens of thousands of customers.
The threat actors claimed 13 million records were exposed in total, with https://hokuen.info/british-gp-fan-safety-security-tips about 4.4 million US consumers affected according to the official data breach notification. In addition to the Texas AG disclosure, the breach was also reported to the Attorneys General of California, Iowa, Washington, Massachusetts, New Hampshire, Montana, and Maine. The incident is linked to the ShinyHunters extortion group and forms part of the broader Salesforce-connected campaign that struck dozens of major organizations across 2025. The 2025 TransUnion data breach exposed the personal information of 4,461,511 Americans, including names, Social Security numbers, and dates of birth, after attackers exploited a third-party application connected to TransUnion’s US consumer support operations. Qantas Airways confirmed in October that attackers had stolen data through a third-party contact center platform connected to its Salesforce environment, exposing the personal information of 5.7 million customers, including names, email addresses, dates of birth, phone numbers, and Frequent Flyer numbers.
- The systems were compromised in June and the unauthorized party, who remained on the network until late July.
- When your business experiences a data breach, notify law enforcement, other affected businesses, and affected individuals.
- The first is surface-level security posture monitoring, continuous scanning of vendor-exposed infrastructure for known vulnerabilities, misconfigured cloud storage, expired TLS certificates, and open RDP or SMB ports.
- We previously reported that security researchers had discovered billions of exposed records online, calling it the “mother of all breaches.” It has been uncovered that the dataset comes from a compilation of multiple breaches.
- But the financial costs of the breach and the knock-on effect to its business are likely to be realized in the coming months, and are expected to be substantial.