North St. Paul Police Department
July 23, 2025
•[ phishing, government, hack ]
A phishing email compromised a single business email account in the North St. Paul Police Department around July 23 2025. The incident was swiftly contained with no service disruption and no confirmed data exfiltration, though data compromise is being investigated. Disclosed August 5 2025.
Joint Court of Justice (Dutch Caribbean)
July 23, 2025
•[ hack, malware, government ]
A malware infection on July 23, 2025 forced the shutdown of the Joint Court of Justices entire IT network across six islands. Judicial case management, filings, and email were fully disrupted until restoration began around July 28. No group has claimed responsibility; no data exfiltration confirmed.
CoinDCX
July 19, 2025
•[ financial, hack, finance ]
CoinDCX, Indias largest crypto exchange, suffered a $44M breach in July 2025 after attackers compromised a backend server connected to a hot wallet. Withdrawals were suspended but later resumed with assurances user funds were safe. Attribution remains undetermined; some analysts suggest Lazarus Group, while Indian police arrested a local engineer tied to suspicious freelance work.
Dutch Public Prosecution Service (Openbaar Ministerie)
July 17, 2025
•[ hack, government ]
Systems shut down after discovery of unauthorized access via Citrix.
Automated Business Solutions (ABS)
July 16, 2025
•[ hack, technology ]
ABS reported unauthorized network access (July 1617, 2025); investigation confirmed on Aug. 22 that names, SSNs, and bank account data were copied; notifications and Equifax monitoring offered.
IMDataCenter
July 15, 2025
•[ leak, hack, misconfiguration ]
Unsecured AWS S3 bucket exposed ~38GB of records; hacker downloaded ~75GB, including ~20M emails, ~37M phone numbers, 50k SSNs/DOBs; affects multiple industries (healthcare, airlines, universities, dealerships). Bucket later secured; lawsuits pending.
Workday Inc. (via undisclosed third-party CRM)
July 10, 2025
•[ hack, technology ]
Workday disclosed in Aug 2025 that hackers accessed a third-party CRM system, stealing personal data of ~1.6M people linked to enterprise customers; core HR/payroll systems were unaffected.
Venice Film Festival
July 7, 2025
•[ hack, leak ]
On July 7, 2025, unauthorized actors accessed and copied documents from the Venice Film Festivals servers, extracting personal data of attendees, including journalists and industry professionals. Systems were proactively isolated by the festivals IT team, and authorities were notified. There is no indication of data encryption, nor disruption of payment, booking, or ticketing systems. Notifications to affected individuals began around early August 2025.
U.S. federal judiciary CM/ECF & PACER systems
July 4, 2025
•[ hack, leak, government ]
The U.S. federal judiciarys electronic case filing systems (CM/ECF and PACER) were breached around July 4, 2025. Sensitive sealed dataincluding indictments, arrest warrants, and identities of confidential informantswas accessed across multiple district courts. Reports suggest possible theft of system source code and tampering with ~12 dockets. The precise volume of data stolen is unknown, but officials confirmed that a significant number of sealed case files were exposed.
Clinical Diagnostics NMDL (Eurofins) lab systems
July 3, 2025
•[ hack, healthcare ]
A breach at the Clinical Diagnostics NMDL lab in Rijswijk compromised personal and medical data of women who participated in cervical cancer screenings; hackers accessed the data starting July 3, 2025, with notification to affected individuals beginning around August 11
University of Iowa Community HomeCare
July 3, 2025
•[ hack, healthcare ]
Cybercriminal gained unauthorized access to UI Community HomeCare computer system on July 3, 2025; systems restored within one business day but files containing patient information were viewed and copied.
Royal Health
July 3, 2025
•[ hack, healthcare ]
Data breach at Royal Health Inc. detected on or about July 3, 2025, where an unauthorized party accessed documents potentially containing full names and Social Security numbers. The breach was disclosed to the Massachusetts Attorney General and notifications began August 21. Compensation inquiries are underway under Levi & Korsinsky LLPs investigation.
Luzerne County Government
July 1, 2025
•[ hack, government ]
Luzerne County, Pennsylvania reported a data breach in July 2025 after discovering unauthorized access to county servers. Investigation suggests personal and possibly financial data were exposed, though no service disruption or encryption was reported.
Federal Emergency Management Agency (FEMA) and U.S. Customs and Border Protection (CBP)
July 1, 2025
•[ hack, government ]
Attackers gained unauthorized access to FEMA Region 6s Citrix-based virtual desktop infrastructure beginning July 2025, exfiltrating sensitive employee data from both FEMA and CBP systems. The compromise originated from stolen credentials and enabled lateral movement between federal systems before detection.
MPOWERHealth
June 29, 2025
•[ ransomware, leak, hack ]
WorldLeaks, a criminal ransomware group, claimed responsibility for a June 29, 2025 cyberattack on MPOWERHealth in Addison, Texas. The attackers exfiltrated roughly 1.5 TB of data (over 1.6 million files), including PHI, insurance claims, internal documents, login credentials, and cyber-insurance records. While negotiations began, the company ceased responding, after which WorldLeaks leaked the stolen files. Reports indicate data theft and exposure but no confirmed operational outage.
Somerset County Children & Youth Services
June 26, 2025
•[ hack, healthcare ]
Email accounts of Somerset County CYS were breached during a fourday period; exposed data includes Social Security and insurance IDs, medical dates, condition/treatment info, sometimes paternity testing info; no confirmed misuse yet; County working with forensics, notifying affected, improving email security and staff training.
Carter Credit Union
June 25, 2025
•[ hack, finance ]
A cybercriminal infiltrated Carter Credit Unions network between June 25 and July 2, 2025, accessing files containing personal and medical information of approximately 68,934 individuals. Investigations are ongoing, notifications have been sent, and affected members were offered credit monitoring services. Law firms are reviewing legal claims.
Union Home Mortgage Corp.
June 25, 2025
•[ hack, finance ]
Union Home Mortgage Corp. experienced unauthorized access to internal servers, exposing personal and identification data of roughly 24,000 customers. No encryption or ransomware activity was reported.
Vietnam Airlines
June 20, 2025
•[ hack, leak, technology ]
In October 2025, data stolen from the Salesforce instances of multiple companies by a hacking group calling itself "Scattered LAPSUS$ Hunters" was publicly released. Among the affected organisations was Vietnam Airlines, which had 7.5M unique customer email addresses exposed following a breach of its Salesforce environment in June of that year. The compromised data also included names, phone numbers, dates of birth, and loyalty program membership numbers.
Sree Padmanabhaswamy Temple
June 13, 2025
•[ hack, insider, financial ]
On June 13, 2025, the Sree Padmanabhaswamy Temples computer system in Kerala, India, was hacked, suspected to involve a former IT staff member retaining access after transfer. Critical operational and financial records were accessed and tampered with, though no encryption or ransomware-style disruption was reported. The breach was discovered by temple officials and reported to police, with a forensic probe launched.