Full names, addresses, dates of birth, phone numbers, and Security Social numbers were compromised in the breach, which is likely to have affected most – if not all – US citizens. A new court filing alleges that four months ago, background check company National Public Data (NPD) was breached by hacking group USDoD. The attack was quickly shut down, but not before personal information belonging to 115,837 people was accessed. Reportedly, stolen data varied from patient to patient, and there is not yet any evidence that it has been misused. The data in question could include names, dates of birth, social security numbers, and health insurance information.
Conduent stated it sincerely regrets any inconvenience and has set up a call center for questions.This evolving story highlights the risks third-party service providers pose to sensitive government and healthcare data. Recent state regulatory reports show at least 15.4 million people affected in Texas alone (up from an initial estimate of 4 million), with earlier filings indicating 10.5 million impacted in Oregon and hundreds of thousands more across other states. You should also manually remove old accounts, adjust social media privacy settings, and opt out of people-search sites.
In January, solution provider giant Conduent—whose systems are used to enable government services such https://master-your-business.com/how-can-cybersecurity-protect-your-business/ as child support payments and food assistance—confirmed that a major service outage was caused by a cyberattack. What follows are the key details on 10 major cyberattacks and data breaches in 2025 so far (in chronological order). As of this writing, one major attack is still ongoing, with threat actors exploiting vulnerabilities in on-premises Microsoft SharePoint servers in widespread cyberattacks.
Mining’s Digital Rush Hits a Cyber Minefield
U.S. health insurance giant Kaiser disclosed a data breach in April after inadvertently sharing the private health information of 13.4 million patients, specifically website search terms about diagnoses and medications, with tech companies and advertisers. Cencora has steadfastly refused to say how many people are affected, but a count by TechCrunch shows well over a million people https://myshoppingconnection.com/how-are-smart-homes-being-influenced-by-global-tech-innovations/ have been notified so far. Health service in the years that ran up to the June cyberattack on Synnovis. A Russia-based ransomware gang was blamed for the cyberattack, which saw the theft of data related to some 300 million patient interactions dating back a “significant number” of years. At least 100 million people are now known to be affected by the breach, but the final number is likely to rise. UnitedHealth says the stolen data — which it paid the hackers to obtain a copy — includes the personal, medical and billing information on a “substantial proportion” of people in the United States.
Customers faced temporary outages, and authorities have not advised any further action. An Israel-linked hacking group known as Predatory Sparrow (Gonjeshke Darande) claimed responsibility, stating it had “destroyed” bank data during the incident. Sepah Bank, one of Iran’s major state-owned financial institutions, suffered a cyberattack in June 2025 amid active military and cyber clashes between Iran and Israel following recent strikes and retaliations on both sides. Customers lost access to their accounts and stored messages after the applicable deadline.
- Sources familiar with the matter suggested that the attacks may be linked to Chinese threat actors, though the FBI has not yet confirmed attribution.
- Charter said no sensitive personal information or CPNI was exfiltrated, though later breach monitoring tied the exposed dataset to 4.9 million accounts.
- UnitedHealth says the stolen data — which it paid the hackers to obtain a copy — includes the personal, medical and billing information on a “substantial proportion” of people in the United States.
- Breach letters dated Feb 10, 2026 began reaching impacted PPWC users, and the Feb 22, 2026 update added user reports of unauthorized transactions, transaction refunds, and forced password resets as containment.
Over the past few months alone, there has been an uptick in major data exposures involving people’s sensitive government-issued identity documents, including passport and driver license scans left exposed to the web. It was an embarrassing and high-profile lapse in security — and trust — for one of the world’s largest tech companies. The incident affected tens of thousands of accounts before the improper access was discovered and cut off.
In fact, researchers who reviewed the leaked data found it could be used to identify military personnel and gay people in countries where homosexuality is illegal. And maybe, just maybe, this is further evidence that tech monopolies and centralization of data aren’t just bad for consumer rights, civil liberties, and the economy—but also for cybersecurity. Coming in through third-parties, companies that provide software or other services to businesses, is like using an unguarded side door, rather than checking in at the front desk.
August 5
Reporting cites 444,538 borrowers, 629,597 loan applications, 229,226 driver’s license numbers, and data tied to 797 broker organizations, with risk centered on fraud, phishing, and loan-application identity misuse. The youX update confirms a broader borrower and broker impact than a simple driver’s license incident. A controlled simulation of real-world attacks reveals flaws in systems, applications, and human processes, which allows organizations to fix those weaknesses in advance. Figure stated it is notifying impacted users and offering credit monitoring while investigators examine the full scope of the incident. Breach letters dated Feb 10, 2026 began reaching impacted PPWC users, and the Feb 22, 2026 update added user reports of unauthorized transactions, transaction refunds, and forced password resets as containment. PayPal said access continued until Dec 12, 2025, when the incident was detected, and the exposure window ran through Dec 12, 2025.
Turn on alerts for withdrawal, purchase, login attempts and password changes across all financial accounts. A credit freeze prevents criminals from opening new accounts in your name using stolen identity data. “These attacks are hard to catch early because the data being presented is accurate and often reused across multiple institutions,” Amper noted. This includes credit cards, loans, buy now pay later services and even new bank accounts. With enough personal details, attackers can bypass knowledge-based checks, reset passwords, change contact information and abuse accounts in ways that often look legitimate.
Conti members breached the government’s systems, stole highly valuable data, and demanded $20 million in payment to avoid it being leaked. According to Vice, the hacker was able to infiltrate the system after convincing an employee to give them remote access in a social engineering scam. The database contained account information for 69 million users, including names, email addresses, zip codes, genders, and dates of birth. A September update confirmed that LastPass’s security measures prevented customer data from being breached, and the company reminded customers that they do not have access to or store users’ master passwords. However, after inspecting the code, a number of security experts have dubbed the evidence “inconclusive,” including haveibeenpwned.com’s Troy Hunt.