Top Data Breaches of August 2026: Biggest Cybersecurity Incidents
August 2026 underscored just how broad the modern cyber threat landscape has become.
From healthcare and financial services to airports, government systems, technology companies, retailers and consumer platforms, organizations across industries faced data breaches and cyberattacks exposing everything from contact details to highly sensitive medical and identity information.
Some incidents affected millions of people. Others demonstrated how attackers are increasingly exploiting third-party systems, social engineering, cloud environments and software vulnerabilities.
Here are the top data breaches and cybersecurity incidents of August 2026, based on the incidents and reporting compiled for this roundup.
Note: Some incidents described below involve claims or ongoing investigations. Where the affected organization has not independently confirmed the full scope, this article identifies the information as alleged or reported rather than presenting it as established fact.
1. McKesson Breach: ShinyHunters Claims 284 Million Patient Records

One of the most significant breach claims of August involved healthcare giant McKesson.
The ShinyHunters threat group claimed it had compromised McKesson and stolen 284 million records associated with tens of millions of patients.
The allegedly exposed information reportedly includes highly sensitive healthcare and identity data such as:
Social Security numbers
Medical records
Diagnoses
Prescription information
Insurance IDs
Other sensitive health information
McKesson has confirmed that it experienced a cybersecurity incident involving unauthorized access and data exfiltration. However, its investigation remains ongoing, and the number of individuals actually affected has not been established.
The incident highlights the particularly severe consequences of attacks against healthcare organizations, where a single compromised environment can potentially expose both personal and medical information.
Source: Cyber Insider
2. MyDr Cyberattack May Have Exposed Health Data of 18.8 Million People

Polish medical technology provider MyDr faced another major healthcare-related cybersecurity incident, with potentially 18.8 million people affected.
According to the supplied reporting, the potentially compromised information includes:
PESEL numbers
Names
Contact information
Diagnoses
Prescriptions
Doctors’ notes
Polish authorities are investigating the incident.
Importantly, MyDr has stated that there is currently no confirmation that the data has been publicly leaked.
That distinction matters. A security incident involving unauthorized access does not automatically mean that all potentially accessible information has been publicly released.
Nevertheless, the scale and sensitivity of the potentially exposed data make the incident particularly significant.
Source: CPOMagazine
3. Manchester Airports Group Breach Affects 8.7 Million Customers

Cyberattacks against critical infrastructure can have consequences far beyond stolen information.
Manchester Airports Group (MAG), which operates Manchester, East Midlands and London Stansted airports, confirmed a cyberattack affecting approximately 8.7 million customers.
According to the supplied reporting, attackers accessed:
Email addresses
Postcodes
Vehicle registration information
The attackers also demanded a ransom, which MAG refused to pay.
The company stated that passenger safety, aviation security and payment information were not compromised.
The incident demonstrates why organizations operating critical infrastructure have to protect not only operational systems but also the vast quantities of customer information connected to those systems.
Source: BBC
4. Apollo Global Management Reports Data Breach

Investment management company Apollo Global Management disclosed a data breach after attackers accessed certain cloud platforms between July 6 and July 10.
Potentially exposed information includes:
Names
Dates of birth
Contact details
Home addresses
Social Security numbers
Apollo said its investigation remains ongoing and that there was no evidence at the time of reporting that the information had been publicly disclosed or used for fraud.
The incident is another reminder that cloud environments can become high-value targets containing large amounts of sensitive personal information.
Source: Reuters
5. SplitVPN Breach Exposes 865,000+ Users

A particularly notable incident for privacy-focused services involved Russian VPN provider SplitVPN, formerly known as NotVPN.
The breach reportedly exposed information associated with more than 865,000 user accounts, along with millions of connection records.
The allegedly exposed data includes:
Email addresses
IP addresses
Device information
Partial payment information
Nearly 58 million VPN connection logs
The reported presence of connection logs is especially significant because it conflicts with the provider’s previous “no-logs” privacy claims.
For VPN providers, trust is a central part of the product. A breach involving connection records therefore creates consequences beyond the immediate exposure of account information—it can also raise questions about data retention and privacy practices.
Affected users were advised to change reused passwords, enable MFA and remain alert for phishing attempts.
Source: Cybersecurity News
6. IBM-Managed Singapore Land Authority Environment Exposes Data of 70,000 People
A breach involving a third-party environment affected approximately 70,000 individuals connected to Singapore’s Land Authority.
Unauthorized access to an IBM-managed development and testing environment exposed:
Names
NRIC numbers
Property addresses
The Singapore Land Authority stated that production systems and property records were not compromised.
The incident highlights a recurring cybersecurity challenge: development and testing environments can contain sensitive information and therefore cannot be treated as inherently low-risk.
Third-party infrastructure also introduces another layer of responsibility. Organizations must understand not only their own security controls, but also how vendors and managed service providers protect connected environments.
Source: Computer Weekly
7. Unlimited Technology Systems Breach Affects 3.8 Million People

Healthcare software provider Unlimited Technology Systems disclosed a breach affecting approximately 3,803,750 people.
According to the supplied reporting, attackers accessed files over a five-day period in October 2025. Potentially exposed information included:
Names
Social Security numbers
Dates of birth
Government identification information
Insurance information
Medical records
Affected individuals were offered identity monitoring through Kroll.
The incident illustrates how healthcare technology providers can hold highly sensitive information even when they are not traditional hospitals or healthcare providers themselves.
The wider healthcare ecosystem—including software vendors, processors and technology providers—has become an increasingly important part of the attack surface.
Source: BleepingComputer
8. Suno Breach Reportedly Impacts 55.3 Million Users
AI-powered music platform Suno was reportedly affected by a November 2025 security incident involving the personal information of more than 55.3 million users.
According to the supplied reporting, the allegedly compromised information included:
Names
Email addresses
Physical addresses
Phone numbers
Purchase records
Partial payment-card details
The incident reportedly also involved source code that could provide insight into aspects of Suno’s AI training methods.
That makes the incident notable beyond traditional customer-data exposure. For AI companies, source code, training methodologies and technical infrastructure can represent valuable intellectual property in addition to personal data.
Source: TechCrunch
9. Paidwork Breach Exposes 23.3 Million Accounts
Online platform Paidwork suffered a major data breach involving 23.3 million accounts, following the public release of an approximately 11 GB database.
The exposed information reportedly includes:
Email addresses
Bank account information
Payout histories
Personal information
Device data
Cryptographically hashed passwords
The combination of financial information and identity data could increase the risk of phishing, identity theft, payment fraud and account takeover.
Security experts advised affected users to reset passwords and monitor financial accounts for suspicious activity.
The incident also demonstrates why password hashing alone should not be considered a complete defense when multiple categories of sensitive information are exposed together.
Source: Cybernews
10. Tata Electronics Investigation Raises Concerns Over Apple Supply-Chain Data
Indian authorities are investigating a cyberattack involving Tata Electronics after data reportedly linked to the unreleased Apple iPhone 18 Pro surfaced on the dark web.
The leaked material reportedly included:
Supplier lists
Component information
Prototype images
Documents associated with other major technology companies, including Tesla, Qualcomm and TSMC, were also reportedly exposed as part of the investigation.
Unlike a conventional consumer breach, this incident demonstrates the potential value of supply-chain information.
Attackers do not necessarily need access to a company’s customer database to cause significant damage. Proprietary designs, supplier relationships, component information and product-development documents can all have substantial commercial value.
Source: Reuters
11. AssuranceAmerica Breach Exposes Information of Nearly 7 Million Drivers
Insurance provider AssuranceAmerica disclosed a cyberattack affecting approximately 6.99 million individuals.
The compromised information reportedly included:
Names
Contact details
Insurance policy information
Vehicle information
Claims records
Driver’s license numbers
The company said it contained the incident, strengthened its security measures and notified law enforcement.
For insurers, breaches can be particularly damaging because customer profiles can combine identity, financial, vehicle and claims information in a single environment.
Source: BleepingComputer
12. Medtronic Breach Impacts 3.8 Million Individuals
Medical technology company Medtronic began notifying more than 3.8 million individuals following a cyberattack attributed to the ShinyHunters extortion group.
The incident reportedly exposed personal and health-related information.
Medtronic stated that the incident did not affect medical devices, patient safety, manufacturing or operations.
The company is offering affected individuals:
24 months of credit monitoring
Dark web monitoring
Identity theft protection
The incident demonstrates the difference between compromising corporate data and compromising operational medical technology. Both can be serious, but the potential consequences and response requirements can differ significantly.
Source: Security Affairs
Other Notable August 2026 Breaches
Several additional incidents from the supplied material are worth watching.
Hasbro Employee Data Breach

Toy manufacturer Hasbro disclosed a breach involving employee personal and financial information.
While the total number of affected individuals remains unknown, 436 Massachusetts employees were confirmed to have potentially exposed information including Social Security numbers, financial account details, payment-card information or driver’s license data.
Source: BleepingComputer
Pokémon Center Customer Data Breach

Pokémon Center confirmed a breach linked to logistics partner CEVA Logistics, exposing customer names, addresses, phone numbers, email addresses and order details in the UK and Germany.
Payment-card information was reportedly not affected.
Source: Cybersecurity News
SafePal Breach

Cryptocurrency wallet provider SafePal disclosed a security flaw that exposed information belonging to 39,798 customers who placed orders between March 2025 and April 2026.
The exposed information reportedly included names, addresses and contact details.
SafePal stated that private keys, seed phrases, passwords, payment data and crypto assets were not compromised.
Source: CoinDesk
Framework Data Breach

PC manufacturer Framework confirmed a breach exposing customer names, email addresses, phone numbers, physical addresses and login IP addresses.
The incident was reportedly linked to a Metabase Cloud zero-day vulnerability.
Framework stated that order and payment information was not accessed.
Source: CNET
Levi’s Corporate Data Breach

Levi Strauss & Co. reported that attackers used social engineering to compromise the computers of three employees and exfiltrate corporate data.
The company said its rapid response prevented an impact on consumer data or business operations, while the investigation continued.
Source: BleepingComputer
Seoul Ttareungi Breach

A breach involving Seoul’s public bicycle service Ttareungi has led to a lawsuit filed by 23 users seeking compensation.
The breach reportedly exposed information associated with approximately 4.62 million users, including phone numbers, birth dates, email addresses, home addresses and other personal information.
The lawsuit alleges inadequate security controls and a lengthy delay in disclosing the breach.
Source: Korea JoongAng Daily
What August 2026’s Breaches Tell Us About Cybersecurity
The incidents above aren’t isolated stories. Together, they reveal several clear patterns.
1. Healthcare Remains a High-Value Target
McKesson, MyDr and Medtronic demonstrate the enormous value of healthcare data to attackers.
Medical information is difficult to change once exposed. Unlike a password, a diagnosis, prescription history or Social Security number cannot simply be replaced.
That makes healthcare organizations—and the technology companies supporting them—particularly attractive targets.
2. Third Parties Continue to Expand the Attack Surface
Several incidents involve vendors, partners or connected environments.
The Singapore Land Authority incident involved an IBM-managed environment, while the Pokémon Center breach was linked to a logistics partner.
This reinforces a critical cybersecurity reality:
Your security perimeter doesn’t end at your own infrastructure.
Vendors, cloud providers, logistics companies, software platforms and other partners can all become pathways to sensitive information.
3. Social Engineering Still Works
The Levi’s incident demonstrates that sophisticated technical defenses can still be undermined by attacks targeting people.
Social engineering remains attractive because attackers can sometimes obtain access without exploiting a complicated software vulnerability.
Organizations therefore need a combination of:
Employee awareness
Strong authentication
Least-privilege access
Endpoint monitoring
Identity security
Rapid incident response
4. Cloud and Development Environments Need Serious Protection
The Singapore Land Authority incident shows why development and testing environments cannot automatically be considered safe from attackers.
Sensitive information can exist outside production systems, and those environments still require appropriate access controls, monitoring and data protection.
5. Data Minimization Matters
A recurring theme across these incidents is the sheer volume of information organizations hold.
Names, addresses, identity numbers, medical records, financial information, device data and behavioral records can become extremely valuable when combined.
Reducing unnecessary data collection and retention can therefore reduce the potential impact of a successful breach.
The Biggest Lesson From August 2026
The most important cybersecurity lesson from August isn’t simply that breaches are becoming larger.
It’s that the attack surface is becoming more interconnected.
A healthcare provider can be compromised through a technology partner.A retailer can be exposed through a logistics provider.A government organization can be affected through a managed environment.An employee can become the entry point through social engineering.A cloud vulnerability can expose customer information far beyond the application that originally contained it.
Cybersecurity therefore has to move beyond protecting individual systems.
Organizations need visibility across people, applications, vendors, cloud infrastructure, data and third-party relationships.
Final Takeaway
The top data breaches of August 2026 show that no industry is operating in isolation.
From potentially 284 million healthcare records claimed in the McKesson incident to 18.8 million people potentially affected by the MyDr breach and 8.7 million customers impacted by the Manchester Airports Group attack, the scale of modern cyber incidents remains significant.
But the numbers tell only part of the story.
The deeper challenge is understanding where sensitive data lives, who can access it, which third parties connect to it and how quickly an organization can detect and respond when something goes wrong.
As organizations continue adopting cloud services, AI, connected platforms and complex technology ecosystems, cybersecurity needs to become increasingly proactive, continuous and interconnected.
Because in 2026, protecting the perimeter isn’t enough. You have to protect the entire ecosystem.





Comments