top of page

Top Data Breaches of August 2026: Biggest Cybersecurity Incidents

19 minutes ago
9 min read

August 2026 underscored just how broad the modern cyber threat landscape has become.


From healthcare and financial services to airports, government systems, technology companies, retailers and consumer platforms, organizations across industries faced data breaches and cyberattacks exposing everything from contact details to highly sensitive medical and identity information.


Some incidents affected millions of people. Others demonstrated how attackers are increasingly exploiting third-party systems, social engineering, cloud environments and software vulnerabilities.


Here are the top data breaches and cybersecurity incidents of August 2026, based on the incidents and reporting compiled for this roundup.


Note: Some incidents described below involve claims or ongoing investigations. Where the affected organization has not independently confirmed the full scope, this article identifies the information as alleged or reported rather than presenting it as established fact.


1. McKesson Breach: ShinyHunters Claims 284 Million Patient Records

One of the most significant breach claims of August involved healthcare giant McKesson.

The ShinyHunters threat group claimed it had compromised McKesson and stolen 284 million records associated with tens of millions of patients.

The allegedly exposed information reportedly includes highly sensitive healthcare and identity data such as:

  • Social Security numbers

  • Medical records

  • Diagnoses

  • Prescription information

  • Insurance IDs

  • Other sensitive health information

McKesson has confirmed that it experienced a cybersecurity incident involving unauthorized access and data exfiltration. However, its investigation remains ongoing, and the number of individuals actually affected has not been established.

The incident highlights the particularly severe consequences of attacks against healthcare organizations, where a single compromised environment can potentially expose both personal and medical information.

Source: Cyber Insider


2. MyDr Cyberattack May Have Exposed Health Data of 18.8 Million People

Polish medical technology provider MyDr faced another major healthcare-related cybersecurity incident, with potentially 18.8 million people affected.

According to the supplied reporting, the potentially compromised information includes:

  • PESEL numbers

  • Names

  • Contact information

  • Diagnoses

  • Prescriptions

  • Doctors’ notes

Polish authorities are investigating the incident.

Importantly, MyDr has stated that there is currently no confirmation that the data has been publicly leaked.

That distinction matters. A security incident involving unauthorized access does not automatically mean that all potentially accessible information has been publicly released.

Nevertheless, the scale and sensitivity of the potentially exposed data make the incident particularly significant.

Source: CPOMagazine


3. Manchester Airports Group Breach Affects 8.7 Million Customers

Cyberattacks against critical infrastructure can have consequences far beyond stolen information.

Manchester Airports Group (MAG), which operates Manchester, East Midlands and London Stansted airports, confirmed a cyberattack affecting approximately 8.7 million customers.

According to the supplied reporting, attackers accessed:

  • Email addresses

  • Postcodes

  • Vehicle registration information

The attackers also demanded a ransom, which MAG refused to pay.

The company stated that passenger safety, aviation security and payment information were not compromised.

The incident demonstrates why organizations operating critical infrastructure have to protect not only operational systems but also the vast quantities of customer information connected to those systems.

Source: BBC


4. Apollo Global Management Reports Data Breach

Investment management company Apollo Global Management disclosed a data breach after attackers accessed certain cloud platforms between July 6 and July 10.

Potentially exposed information includes:

  • Names

  • Dates of birth

  • Contact details

  • Home addresses

  • Social Security numbers

Apollo said its investigation remains ongoing and that there was no evidence at the time of reporting that the information had been publicly disclosed or used for fraud.

The incident is another reminder that cloud environments can become high-value targets containing large amounts of sensitive personal information.

Source: Reuters


5. SplitVPN Breach Exposes 865,000+ Users

A particularly notable incident for privacy-focused services involved Russian VPN provider SplitVPN, formerly known as NotVPN.

The breach reportedly exposed information associated with more than 865,000 user accounts, along with millions of connection records.

The allegedly exposed data includes:

  • Email addresses

  • IP addresses

  • Device information

  • Partial payment information

  • Nearly 58 million VPN connection logs

The reported presence of connection logs is especially significant because it conflicts with the provider’s previous “no-logs” privacy claims.

For VPN providers, trust is a central part of the product. A breach involving connection records therefore creates consequences beyond the immediate exposure of account information—it can also raise questions about data retention and privacy practices.

Affected users were advised to change reused passwords, enable MFA and remain alert for phishing attempts.

Source: Cybersecurity News


6. IBM-Managed Singapore Land Authority Environment Exposes Data of 70,000 People

A breach involving a third-party environment affected approximately 70,000 individuals connected to Singapore’s Land Authority.

Unauthorized access to an IBM-managed development and testing environment exposed:

  • Names

  • NRIC numbers

  • Property addresses

The Singapore Land Authority stated that production systems and property records were not compromised.

The incident highlights a recurring cybersecurity challenge: development and testing environments can contain sensitive information and therefore cannot be treated as inherently low-risk.

Third-party infrastructure also introduces another layer of responsibility. Organizations must understand not only their own security controls, but also how vendors and managed service providers protect connected environments.

Source: Computer Weekly


7. Unlimited Technology Systems Breach Affects 3.8 Million People

Healthcare software provider Unlimited Technology Systems disclosed a breach affecting approximately 3,803,750 people.

According to the supplied reporting, attackers accessed files over a five-day period in October 2025. Potentially exposed information included:

  • Names

  • Social Security numbers

  • Dates of birth

  • Government identification information

  • Insurance information

  • Medical records

Affected individuals were offered identity monitoring through Kroll.

The incident illustrates how healthcare technology providers can hold highly sensitive information even when they are not traditional hospitals or healthcare providers themselves.

The wider healthcare ecosystem—including software vendors, processors and technology providers—has become an increasingly important part of the attack surface.

Source: BleepingComputer


8. Suno Breach Reportedly Impacts 55.3 Million Users

AI-powered music platform Suno was reportedly affected by a November 2025 security incident involving the personal information of more than 55.3 million users.

According to the supplied reporting, the allegedly compromised information included:

  • Names

  • Email addresses

  • Physical addresses

  • Phone numbers

  • Purchase records

  • Partial payment-card details

The incident reportedly also involved source code that could provide insight into aspects of Suno’s AI training methods.

That makes the incident notable beyond traditional customer-data exposure. For AI companies, source code, training methodologies and technical infrastructure can represent valuable intellectual property in addition to personal data.

Source: TechCrunch


9. Paidwork Breach Exposes 23.3 Million Accounts

Online platform Paidwork suffered a major data breach involving 23.3 million accounts, following the public release of an approximately 11 GB database.

The exposed information reportedly includes:

  • Email addresses

  • Bank account information

  • Payout histories

  • Personal information

  • Device data

  • Cryptographically hashed passwords

The combination of financial information and identity data could increase the risk of phishing, identity theft, payment fraud and account takeover.

Security experts advised affected users to reset passwords and monitor financial accounts for suspicious activity.

The incident also demonstrates why password hashing alone should not be considered a complete defense when multiple categories of sensitive information are exposed together.

Source: Cybernews


10. Tata Electronics Investigation Raises Concerns Over Apple Supply-Chain Data

Indian authorities are investigating a cyberattack involving Tata Electronics after data reportedly linked to the unreleased Apple iPhone 18 Pro surfaced on the dark web.

The leaked material reportedly included:

  • Supplier lists

  • Component information

  • Prototype images

Documents associated with other major technology companies, including Tesla, Qualcomm and TSMC, were also reportedly exposed as part of the investigation.

Unlike a conventional consumer breach, this incident demonstrates the potential value of supply-chain information.

Attackers do not necessarily need access to a company’s customer database to cause significant damage. Proprietary designs, supplier relationships, component information and product-development documents can all have substantial commercial value.

Source: Reuters


11. AssuranceAmerica Breach Exposes Information of Nearly 7 Million Drivers

Insurance provider AssuranceAmerica disclosed a cyberattack affecting approximately 6.99 million individuals.

The compromised information reportedly included:

  • Names

  • Contact details

  • Insurance policy information

  • Vehicle information

  • Claims records

  • Driver’s license numbers

The company said it contained the incident, strengthened its security measures and notified law enforcement.

For insurers, breaches can be particularly damaging because customer profiles can combine identity, financial, vehicle and claims information in a single environment.

Source: BleepingComputer


12. Medtronic Breach Impacts 3.8 Million Individuals

Medical technology company Medtronic began notifying more than 3.8 million individuals following a cyberattack attributed to the ShinyHunters extortion group.

The incident reportedly exposed personal and health-related information.

Medtronic stated that the incident did not affect medical devices, patient safety, manufacturing or operations.

The company is offering affected individuals:

  • 24 months of credit monitoring

  • Dark web monitoring

  • Identity theft protection

The incident demonstrates the difference between compromising corporate data and compromising operational medical technology. Both can be serious, but the potential consequences and response requirements can differ significantly.

Source: Security Affairs


Other Notable August 2026 Breaches

Several additional incidents from the supplied material are worth watching.


Hasbro Employee Data Breach

Toy manufacturer Hasbro disclosed a breach involving employee personal and financial information.

While the total number of affected individuals remains unknown, 436 Massachusetts employees were confirmed to have potentially exposed information including Social Security numbers, financial account details, payment-card information or driver’s license data.

Source: BleepingComputer


Pokémon Center Customer Data Breach

Pokémon Center confirmed a breach linked to logistics partner CEVA Logistics, exposing customer names, addresses, phone numbers, email addresses and order details in the UK and Germany.

Payment-card information was reportedly not affected.

Source: Cybersecurity News


SafePal Breach

Cryptocurrency wallet provider SafePal disclosed a security flaw that exposed information belonging to 39,798 customers who placed orders between March 2025 and April 2026.

The exposed information reportedly included names, addresses and contact details.

SafePal stated that private keys, seed phrases, passwords, payment data and crypto assets were not compromised.

Source: CoinDesk


Framework Data Breach

PC manufacturer Framework confirmed a breach exposing customer names, email addresses, phone numbers, physical addresses and login IP addresses.

The incident was reportedly linked to a Metabase Cloud zero-day vulnerability.

Framework stated that order and payment information was not accessed.

Source: CNET


Levi’s Corporate Data Breach

Levi Strauss & Co. reported that attackers used social engineering to compromise the computers of three employees and exfiltrate corporate data.

The company said its rapid response prevented an impact on consumer data or business operations, while the investigation continued.

Source: BleepingComputer


Seoul Ttareungi Breach

A breach involving Seoul’s public bicycle service Ttareungi has led to a lawsuit filed by 23 users seeking compensation.

The breach reportedly exposed information associated with approximately 4.62 million users, including phone numbers, birth dates, email addresses, home addresses and other personal information.

The lawsuit alleges inadequate security controls and a lengthy delay in disclosing the breach.

Source: Korea JoongAng Daily


What August 2026’s Breaches Tell Us About Cybersecurity


The incidents above aren’t isolated stories. Together, they reveal several clear patterns.


1. Healthcare Remains a High-Value Target

McKesson, MyDr and Medtronic demonstrate the enormous value of healthcare data to attackers.

Medical information is difficult to change once exposed. Unlike a password, a diagnosis, prescription history or Social Security number cannot simply be replaced.

That makes healthcare organizations—and the technology companies supporting them—particularly attractive targets.


2. Third Parties Continue to Expand the Attack Surface

Several incidents involve vendors, partners or connected environments.

The Singapore Land Authority incident involved an IBM-managed environment, while the Pokémon Center breach was linked to a logistics partner.

This reinforces a critical cybersecurity reality:

Your security perimeter doesn’t end at your own infrastructure.

Vendors, cloud providers, logistics companies, software platforms and other partners can all become pathways to sensitive information.


3. Social Engineering Still Works

The Levi’s incident demonstrates that sophisticated technical defenses can still be undermined by attacks targeting people.

Social engineering remains attractive because attackers can sometimes obtain access without exploiting a complicated software vulnerability.

Organizations therefore need a combination of:

  • Employee awareness

  • Strong authentication

  • Least-privilege access

  • Endpoint monitoring

  • Identity security

  • Rapid incident response


4. Cloud and Development Environments Need Serious Protection

The Singapore Land Authority incident shows why development and testing environments cannot automatically be considered safe from attackers.

Sensitive information can exist outside production systems, and those environments still require appropriate access controls, monitoring and data protection.


5. Data Minimization Matters

A recurring theme across these incidents is the sheer volume of information organizations hold.

Names, addresses, identity numbers, medical records, financial information, device data and behavioral records can become extremely valuable when combined.

Reducing unnecessary data collection and retention can therefore reduce the potential impact of a successful breach.


The Biggest Lesson From August 2026


The most important cybersecurity lesson from August isn’t simply that breaches are becoming larger.


It’s that the attack surface is becoming more interconnected.

A healthcare provider can be compromised through a technology partner.A retailer can be exposed through a logistics provider.A government organization can be affected through a managed environment.An employee can become the entry point through social engineering.A cloud vulnerability can expose customer information far beyond the application that originally contained it.


Cybersecurity therefore has to move beyond protecting individual systems.

Organizations need visibility across people, applications, vendors, cloud infrastructure, data and third-party relationships.


Final Takeaway


The top data breaches of August 2026 show that no industry is operating in isolation.

From potentially 284 million healthcare records claimed in the McKesson incident to 18.8 million people potentially affected by the MyDr breach and 8.7 million customers impacted by the Manchester Airports Group attack, the scale of modern cyber incidents remains significant.


But the numbers tell only part of the story.


The deeper challenge is understanding where sensitive data lives, who can access it, which third parties connect to it and how quickly an organization can detect and respond when something goes wrong.


As organizations continue adopting cloud services, AI, connected platforms and complex technology ecosystems, cybersecurity needs to become increasingly proactive, continuous and interconnected.


Because in 2026, protecting the perimeter isn’t enough. You have to protect the entire ecosystem.

Comments


bottom of page