Digital Privacy Watch

Massive US/EU PII breaches and ransomware surge; healthcare shift; insider betrayal; education sector analysis; stale credentials root cause; new enforcement actions; SonicWall zero-day; Spirals ransomware; VPN sanction; new breach settlements; Suno; T-Mobile ruling; ransom payment ban debate; AI boosting attacks; OpenLoop breach; Qilin MSP attack; The Gentlemen 144 attacks; ransomware 60% increase; IBM 2026 Cost of Data Breach Report; new healthcare vendor breaches; Health-ISAC ShinyHunters alert; Amgen, Redtail, Aflac Japan, AnMed, Kean University, Xfinity settlement; mortality study; Black Hat/HIMSS summit; SplitVPN breach; UK agency breach; sextortion campaign; Polish hospital ransomware; UK police staff leak; HealthStream breach; Flagstar settlement; Liechtenstein AML breach; Sakura Mobile breach; Qilin H1 2026 analysis; PNLD breach; Radia Inc. ransomware; Indico Data Solutions breach; Cameron Regional Medical Center ransomware; BlackFog Q2 2026 report; Doxim settlement; VillageMD breach; Brown Health Medical Group breach; Brinks Home breach; DentaQuest 15M; Origin Energy 900k; water utility PLC attacks; Analog Devices; Omnicell; Beacon CRM; Met Police; UK DfE 607k; hospital attack with withdrawn extortion; Snowflake hacker guilty plea; ADT Data Breach; Mansfield Family Dentistry; Orova ransomware group emerges; Framework breach; Suisun City attack; NPD breach resurfaced; new breaches: Freeway Insurance, Kovack Financial, SMC, Clover Health, Interim HealthCare, UCLA Health, BigLaw firms, Valve partner, Frontier lawsuit; Sunshine Health; Health Payment Systems; 3.8M medical billing vendor breach; Shenandoah Valley Medical System breach; MyDr Poland 19M; Trezor 14k; SunCloud Health; National Corporate Housing; LiteLLM breach; French tax breach; RingCentral breach; ITRC H1 2026 data; Akira Safe Mode technique; Arkansas Oral breach; Bits of Gold 200k; SafePal 40k; Sophos report: 79% ransomware from compromised identities; EU CRA standards published; Global Azure credential theft breach (McDonald's, Vodafone, TCS); Sharecare breach claim (3.4M, unverified); See's Candies breach; Colla Health breach; Clop campaign expands to Philips, GE, Shell; VMware vCenter flaw exploited by China-nexus group for Babuk ransomware; AI-assisted attacks (Claude Code with The Gentlemen, Zerofot, RAGE); Pokémon Center breach via CEVA Logistics; CareCloud breach 3.7M-3.8M; Medusa ransomware 500+ orgs; rogue ransomware affiliate double-dip (Ransom Busters); AI-assisted attacks detailed (Mexican govt 95M, GPT-4.1); DOJ targets Russian bulletproof hosting; NK IT worker alert; Baylor Genetics breach (genetic testing data); Healthcare attack surface report (93% attacked, 72% disrupted, 410 incidents H1 2026, AI used, Stryker attack, HIPAA delay); MOVEit zero-day breach (2,500 orgs, Clop); LockBit 5.0 targets U.S. Bank; Medusa ransomware hits 500 critical infrastructure orgs by buying access; Latam Pass breach (54M members, BIN data)

Massive US/EU PII breaches and ransomware surge; healthcare shift; insider betrayal; education sector analysis; stale credentials root cause; new enforcement actions; SonicWall zero-day; Spirals ransomware; VPN sanction; new breach settlements; Suno; T-Mobile ruling; ransom payment ban debate; AI boosting attacks; OpenLoop breach; Qilin MSP attack; The Gentlemen 144 attacks; ransomware 60% increase; IBM 2026 Cost of Data Breach Report; new healthcare vendor breaches; Health-ISAC ShinyHunters alert; Amgen, Redtail, Aflac Japan, AnMed, Kean University, Xfinity settlement; mortality study; Black Hat/HIMSS summit; SplitVPN breach; UK agency breach; sextortion campaign; Polish hospital ransomware; UK police staff leak; HealthStream breach; Flagstar settlement; Liechtenstein AML breach; Sakura Mobile breach; Qilin H1 2026 analysis; PNLD breach; Radia Inc. ransomware; Indico Data Solutions breach; Cameron Regional Medical Center ransomware; BlackFog Q2 2026 report; Doxim settlement; VillageMD breach; Brown Health Medical Group breach; Brinks Home breach; DentaQuest 15M; Origin Energy 900k; water utility PLC attacks; Analog Devices; Omnicell; Beacon CRM; Met Police; UK DfE 607k; hospital attack with withdrawn extortion; Snowflake hacker guilty plea; ADT Data Breach; Mansfield Family Dentistry; Orova ransomware group emerges; Framework breach; Suisun City attack; NPD breach resurfaced; new breaches: Freeway Insurance, Kovack Financial, SMC, Clover Health, Interim HealthCare, UCLA Health, BigLaw firms, Valve partner, Frontier lawsuit; Sunshine Health; Health Payment Systems; 3.8M medical billing vendor breach; Shenandoah Valley Medical System breach; MyDr Poland 19M; Trezor 14k; SunCloud Health; National Corporate Housing; LiteLLM breach; French tax breach; RingCentral breach; ITRC H1 2026 data; Akira Safe Mode technique; Arkansas Oral breach; Bits of Gold 200k; SafePal 40k; Sophos report: 79% ransomware from compromised identities; EU CRA standards published; Global Azure credential theft breach (McDonald's, Vodafone, TCS); Sharecare breach claim (3.4M, unverified); See's Candies breach; Colla Health breach; Clop campaign expands to Philips, GE, Shell; VMware vCenter flaw exploited by China-nexus group for Babuk ransomware; AI-assisted attacks (Claude Code with The Gentlemen, Zerofot, RAGE); Pokémon Center breach via CEVA Logistics; CareCloud breach 3.7M-3.8M; Medusa ransomware 500+ orgs; rogue ransomware affiliate double-dip (Ransom Busters); AI-assisted attacks detailed (Mexican govt 95M, GPT-4.1); DOJ targets Russian bulletproof hosting; NK IT worker alert; Baylor Genetics breach (genetic testing data); Healthcare attack surface report (93% attacked, 72% disrupted, 410 incidents H1 2026, AI used, Stryker attack, HIPAA delay); MOVEit zero-day breach (2,500 orgs, Clop); LockBit 5.0 targets U.S. Bank; Medusa ransomware hits 500 critical infrastructure orgs by buying access; Latam Pass breach (54M members, BIN data)

Continuing wave of breaches: PowerSchool 62M, Conduit 62M, 24B credentials, Canvas 275M, Columbia 868k, DentaQuest 2.6M, Panera 5.1M, Discord 10M, iRhythm, France Travail 1M+, Temu 310M claim, Medtronic 9M, Huntsville Hospital 10M+, AT&T $177M settlement, KDDI plaintext passwords, JADEPUFFER autonomous AI ransomware, Apple India supplier breach, TransUnion 4.4M, MSG 26M biometric, Kids Co. SSNs, AdaptHealth, Moody Bible Institute 2.3M, DHS HSIN, AssuranceAmerica 7M, 23andMe settlement (41 states, bankruptcy risk; NY AG $18M), Mount Royal University, Facebook Marketplace 200k, TD Bank insider breach, Nextcloud 367k, Labcorp $35M settlement, NJ law firm 12.8k, Frontier Airlines investigation, Odido 6.5M, Fiesta Insurance 12k+, Romania land registry breach, Ernst & Young (EY) breach (81-day disclosure gap), ZenPatient telehealth breach, GoBus breach (1M users, driver IDs, ride history), Paidwork breach 23M records, Washington Post breach, Fidelity breach settlement, Craneware breach, STIIIZY settlement, Unlimited Technology Systems breach, Abbott breach (22M records, ShinyHunters, July 21 deadline). Suno AI breach 55M users, misconfigured cloud storage, hashed passwords and payment metadata exposed. T-Mobile violated WA breach notification law — judge rules, sets precedent. Way Finders breach — nonprofit, SSNs and medical data exposed. Governments mull ban on ransom payments — policy debate could reshape ransomware economics. Chick-fil-A breach — credential stuffing on loyalty app, names/emails/payment data exposed, 10 states affected. Kootenai County ransomware — local government breach with SSNs, medical info, biometrics, 3-month disclosure gap. AI-Powered Ransomware analysis — synthesizes AI acceleration of attack chain. Proofpoint survey — 22% re-extortion rate, strengthens 'don't pay' advice; 65% say AI boosted attack effectiveness, 40% bypassed controls. Ransomware: +389% YoY, Q1 2026 revenue $529M; Qilin/Gentlemen/Akira top; SRG physical infiltration; AI-generated browser ransomware; FortiBleed pipeline; HHS 'blame the victim' strategy. June 2026: The Gentlemen tops Qilin with 94 victims, 9% MoM increase, 48% of breaches ransomware. GodDamn ransomware uses Microsoft-signed malicious driver to kill security tools. Healthcare ransomware shift: businesses up 35% while hospitals hold flat. Ransomware negotiator insider betrayal. Education sector analysis confirms schools as prime targets. Stale credentials and weak helpdesk verification root cause. Sophos report: identity compromise now primary ransomware vector (79% of attacks), MFA present in 97% of those incidents. US sanctions first VPN (1VPNS) for enabling ransomware. DOJ charges Russians for hosting infrastructure behind LockBit, Cl0p, Play. Ransomware gangs rebranding as norm. Coca-Cola Fairlife dairy ransomware forces production suspension (no data compromise confirmed). Anubis ransomware claims Fairlife attack, confirming food supply chain disruption and data exfiltration threat — uses CitrixBleed 2, disables backups, 1TB claim. Qantas breach (5.7M) via voice phishing, regulator cleared; AI-powered social engineering trend noted. Partnered Health (Australia) breach reinforces global healthcare ransomware crisis. INC ransomware exploits SonicWall SMA zero-days (SSRF + code injection) — patching alone insufficient, attackers roll back patches; assume-breach mindset required. Bath Fitter breach exposes SSNs for 44 Vermont residents. Spirals ransomware uses IIS web shell and PsExec to encrypt IT firm in under 24 hours. Motility Software breach settlement ($75 no-proof, deadline Aug 7). Oak View Group breach (59k victims, deadline Aug 15). Texas hunting/fishing license breach (3M customers, driver license/passport numbers exposed, free credit monitoring). NordStellar Q2 2026 data: Qilin vs Gentlemen rivalry driving surge, SMBs hit hardest (769 US incidents), enterprise attacks up 74%. MFA failure in 97% of ransomware breaches — identity compromise primary vector, inventory gaps persist. ENCFORGE ransomware targets AI model files via Langflow RCE; recovery costs up to $500K per model. ITRC H1 2026 report: insider incidents up 7x, supply chain breaches driving massive notice counts, 76% opacity on attack vectors. Eyemart Express breach — retail optical chain, SSNs and health data exposed. Ransomware groups exploiting VPN vulnerabilities (Qilin targeting Palo Alto, Fortinet, Citrix) within days of disclosure — stolen credentials and weak MFA key vectors. University ransomware attacks up 8% in H1 2026, driven by The Gentlemen — adds to education sector risk. ITRC H1 2026: 471M victims in first half of 2026, already exceeding all of 2025; only 24% of breaches disclose attack method; 7x insider incidents. Re-extortion rate 37% among those who paid — reinforces 'don't pay' advice. Hanscom Federal Credit Union breach — 476 MA residents confirmed, SSNs and medical records exposed. Krispy Kreme data breach settlement — deadline approaching, practical for affected consumers. OnTrac Network Breach — regional parcel carrier, western US, unconfirmed 40k records, network access confirmed, customer PII exposed. OpenLoop breach — 716k patients across 120 healthcare organizations, third-party multi-tenant risk, highlights concentration of patient data in invisible infrastructure. Four more healthcare breaches (Wildwood, Penobscot Valley, Whitfield, Michigan Surgical Center) with SSNs/medical data, The Gentlemen tied to Michigan Surgical Center. EXFILSQUAD claims Microsoft breach (8M records, unverified). Qilin supply chain attack on MSP hit 32 banks. The Gentlemen recorded 144 attacks in H1 2026 across Europe/UK. Ransomware accelerated 60% in six months (Black Kite). BlueNoroff deepfake Zoom phishing for crypto theft. Marlboro-Chesterfield Pathology settles ransomware breach affecting 236k patients, SafePay removal suggests ransom paid. Loma Linda University Health researcher accidentally uploaded patient data to external AI tool, no SSNs but highlights AI integration risks. IBM 2026 Cost of Data Breach Report: $5M average cost, 12% YoY increase, shadow AI incidents doubled to 43%, 92% of AI-attacked orgs lacked access controls. Unlimited Systems ransomware breach exposes 442k patients' SSNs/medical data (9-month disclosure gap). RCM vendor breach (PEAR ransomware) affects 1.26M patients, SSNs/medical history, 9-month gap. Nephrology Associates breach (Insomnia ransomware, PHI/PII, 3-month gap). Werth Wealth Management breach (SSNs/account numbers). Amgen breach — patient data stolen from third-party cloud storage, materiality determination pending. Redtail Technology breach — SSNs and account numbers exposed via social engineering, May-to-July disclosure gap. Aflac Japan breach — 4.38M records, bank details, policy data, second attack in a year, fast disclosure. AnMed (SC) ransomware attack — hospital still in shutdown, patient data at risk; The Gentlemen hijacked hospital's Facebook page to post ransom demands and claim 6TB of sensitive data (HIV, mental health, abortion, genetic records) — new public-shaming escalation. Kean University class action over Qilin ransomware — basic cybersecurity failures alleged. Xfinity $117.5M settlement for 2023 breach — Sept 14 deadline, up to $10k for documented losses, $50 flat claim option. Health-ISAC warns of increasing ShinyHunters healthcare data theft attacks — vishing-to-SSO attack chain, recommendations for phishing-resistant MFA. Everest ransomware group targets Rx Networks with Wake-on-LAN, mutex checks, backup erasure. Study shows in-hospital mortality jumps 34–38% during ransomware attacks (Medicare claims data). Black Hat and HIMSS launch first Healthcare Summit to address crisis. SplitVPN breach — 865k users' emails, IPs, payment tokens, and 58M connection logs exposed, no-logs claim shattered, especially dangerous for dissidents in Russia/Iran/India. UK state investments agency breach — 51 officials' data exposed for 40 hours, tied to AI agent exploitation (OpenAI/Hugging Face). Fake ShinyHunters sextortion campaign using Carnival breach data — leaked names/emails used to fabricate device compromise, follow-on scam alert. Polish hospital ransomware attack forces paper-based operations — adds to healthcare disruption trend. UK police staff data leak — 100k records of police staff exposed on dark web, third UK government breach in a week (MoD, Home Office also hit). HealthStream breach (details emerging) — healthcare training platform, potential PII exposure. Flagstar Bank $31.5M settlement — Aug 11 deadline, up to $25k for documented losses. Liechtenstein AML registry breach — 31k entity records stolen, exposing EU beneficial ownership registry security flaws. Sakura Mobile breach — passport data of international travelers exposed, cross-border notification gaps. Qilin ransomware analysis — 370 attacks in North America H1 2026, RaaS model resilient, manufacturing/healthcare top targets. PNLD breach — UK Police National Legal Database exposes names and work emails of officers/justice staff on dark web, likely via misconfigured Power Pages. Radia Inc. ransomware — CHAOS group claims 655GB data including SSNs, medical records, employee HR files; no official disclosure yet. Indico Data Solutions breach — SSNs, names, addresses exposed; 2-month disclosure gap. Cameron Regional Medical Center ransomware — Anubis claim, patient/employee data at risk. BlackFog Q2 2026 report — ransomware attacks surge 40%, 97% data exfiltration rate, healthcare top target, services sector up 221%. Doxim (credit union software) $5.5M settlement for Dec 2023 breach exposing SSNs/account numbers — Oct 13 deadline for claims. VillageMD breach — 25k+ Texas residents, SSNs/medical data via Aesto Health vendor, class action investigation. Brown Health Medical Group breach — 312k individuals, SSNs/financials/HR files, 6-month disclosure gap. Brinks Home breach — ShinyHunters, 4.9M records from Salesforce, PII exposed, ransom refused. DentaQuest breach — 15M records, largest healthcare breach of 2026. Origin Energy breach — 900k customers, partial card data. Water utility PLC attacks — FBI/EPA warning, likely Iranian. Analog Devices and Omnicell breaches — semiconductor and healthcare tech. Beacon CRM breach — charity CRM, 1,000+ orgs affected, donor data (English National Ballet among victims); root cause: exposed AWS access key in JS build artifacts; ICO says charities not responsible. Met Police ordered to fix data protection after breaches. UK DfE breach — 607k records via social engineering, ExfilSquad. Hospital attack (150k records) — attackers withdrew extortion after learning it was a hospital. Snowflake hacker Moucka pleads guilty, faces 32 years — major law enforcement win. ADT Data Breach — 37k customers, home security data (addresses, patterns), 70-day disclosure gap, class action filed. Mansfield Family Dentistry — listed by Everest ransomware, unconfirmed but consistent with healthcare targeting. Orova ransomware group emerges — hits healthcare, SMBs, churches, vet clinics; MSP supply chain via Syncro; also breaches five Hong Kong firms including SFC-regulated asset manager; SFC issues first ransomware fine same week. Zscaler research shows 62% of ransomware victims hold manager-level roles. Framework breach — Metabase zero-day (CVSS 10) exposes customer PII (addresses, phone numbers), quick notification but downplaying scope. Suisun City (CA) network shutdown due to cyberattack, data breach under investigation — adds to municipal ransomware/breach wave. 2024 National Public Data breach (3B records) resurfaces in news — SSA guide for affected individuals. New breaches: Freeway Insurance (SSNs/financial, 4-month gap), Kovack Financial (11-month gap), SMC (Smith-Midland Corp, SSNs/medical, 19-month gap), Clover Health (social engineering, Medicare Advantage, class actions), Interim HealthCare (genesis ransomware, elderly care), UCLA Health (partial SSNs, small), BigLaw firms (Herbert Smith, Goodwin, Taft — SSNs/health info), Valve partner CEVA Logistics (Steam customer details, phishing risk) — CEVA Logistics breach hits eight European warehouses, exposing customer PII from Bol, De Bijenkorf, Ajax, ING, Ace & Tate, and Valve; supply-chain data spill. Frontier Airlines lawsuit (delayed notification, Scattered Lapsus$ Hunters). Sunshine Health breach — 41k PHI via vishing. Health Payment Systems breach — 9k+ via email compromise, 13-month disclosure gap. Medical billing vendor breach affects 3.8M patients across 4,500 medical offices — 9-month disclosure gap (Oct 2025 to July 2026), SSNs and medical data exposed. Shenandoah Valley Medical System data breach lawsuit — Aesto vendor, 6-month gap, PHI+SSN. New: MyDr (Poland, 19M patients, EMR vendor, major EU breach); Trezor (14k users, shipping provider ShipMonk, names/addresses/phones/emails, high phishing risk for crypto users); SunCloud Health (behavioral health, lawsuit filed, details sparse); National Corporate Housing (physical theft of paper HR files, SSNs/DL/DOB, 80-day delay). LiteLLM breach (2500+ orgs via Trivy scanner compromise, credential theft from CI/CD, Mercor sub-breach 4TB) — some credentials still working 5 months later, highlighting persistent risk from poisoned open-source tools. French tax breach (678k, Cl0p zero-day campaign hitting 50+ companies including Philips, Shell) — income breakdown exposes 27k high earners, physical safety risk; RingCentral breach (1.6M accounts, ShinyHunters); ITRC H1 2026 report confirms 471M victims, AI involvement up 56%, malicious insiders spiking; Akira ransomware now uses Safe Mode to bypass EDR (but broke own encryption). Arkansas Oral & Maxillofacial Surgeons breach by PEAR ransomware, 2.1TB data including SSNs/PHI, disclosure gap April-August. New: Bits of Gold (200k, KYC data, Israeli crypto broker), SafePal (40k, crypto wallet, names/addresses/purchase history). Sophos report: 79% of ransomware attacks start with compromised identities, MFA present in 97% of those incidents. EU CRA standards published — 17 categories, enforcement Dec 2027. New: Global Azure credential theft breach hits McDonald's, Vodafone, TCS, others — infostealer vector, identity as new perimeter. Sharecare breach claimed by ShinyHunters (3.4M records, unverified). See's Candies breach (delayed notification, names only). Colla Health breach (Direwolf ransomware, details sparse). Clop campaign expands to Philips, GE, Shell via PTC Windchill/FlexPLM (43 orgs) — zero-day CVE-2026-12569. New: VMware vCenter flaw (CVE-2026-59310, CVSS 9.8) actively exploited by China-nexus group to deliver Babuk ransomware — enterprise infrastructure at risk. New: AI-assisted attacks: Claude Code used by The Gentlemen to identify and exfiltrate high-value files; Zerofot and RAGE campaigns show AI lowering skill barriers. New: Pokémon Center customer data breach via CEVA Logistics (third-party logistics, PII exposed, scale unclear). New: CareCloud breach affects 3.7M–3.8M patients (EHR vendor, AWS compromise, SSNs/medical data) — delayed notification March to August. New: Medusa ransomware hits 500+ orgs, CISA/FBI/HHS advisory — 67% victim increase, 24-hour exploitation cycle, UMMC attack (9-day outage, $800k ransom). New: Rogue ransomware affiliate poses as recovery firm to steal payments — double-dip scheme (Ransom Busters, tied to DragonForce/Settra/Anubis). New: AI-assisted attacks detailed: Claude Code used in Mexican government breach (95M taxpayer records), GPT-4.1 in real intrusions. New: DOJ targets Russian bulletproof hosting; AI agentic attacker reaches domain admin in 40 min; Apple sues OpenAI for trade secret theft; NK IT worker alert. New: Baylor Genetics breach exposes genetic testing data (SSNs, medical records, genetic results) — 248k+ Texans confirmed, total unknown. New: Healthcare attack surface report: 93% of orgs attacked in 2025, 72% disrupted patient care, 410 incidents H1 2026 (+14%), AI used in attacks, human error second cause, 9-month breach containment, Stryker attack disrupted surgeries, HIPAA update delayed to 2027. New: MOVEit zero-day breach (2,500 orgs, Clop, supply chain) — detailed breakdown of tactics and impact. New: LockBit 5.0 targets U.S. Bank — resurgence after 2024 takedown, financial sector risk. New: Medusa ransomware hits 500 critical infrastructure orgs by buying access — access-broker market thriving. New: Latam Pass breach (54M members, BIN data exposed) — fraud risk from partial card data.

Sources (57)
Updated Aug 22, 2026
Massive US/EU PII breaches and ransomware surge; healthcare shift; insider betrayal; education sector analysis; stale credentials root cause; new enforcement actions; SonicWall zero-day; Spirals ransomware; VPN sanction; new breach settlements; Suno; T-Mobile ruling; ransom payment ban debate; AI boosting attacks; OpenLoop breach; Qilin MSP attack; The Gentlemen 144 attacks; ransomware 60% increase; IBM 2026 Cost of Data Breach Report; new healthcare vendor breaches; Health-ISAC ShinyHunters alert; Amgen, Redtail, Aflac Japan, AnMed, Kean University, Xfinity settlement; mortality study; Black Hat/HIMSS summit; SplitVPN breach; UK agency breach; sextortion campaign; Polish hospital ransomware; UK police staff leak; HealthStream breach; Flagstar settlement; Liechtenstein AML breach; Sakura Mobile breach; Qilin H1 2026 analysis; PNLD breach; Radia Inc. ransomware; Indico Data Solutions breach; Cameron Regional Medical Center ransomware; BlackFog Q2 2026 report; Doxim settlement; VillageMD breach; Brown Health Medical Group breach; Brinks Home breach; DentaQuest 15M; Origin Energy 900k; water utility PLC attacks; Analog Devices; Omnicell; Beacon CRM; Met Police; UK DfE 607k; hospital attack with withdrawn extortion; Snowflake hacker guilty plea; ADT Data Breach; Mansfield Family Dentistry; Orova ransomware group emerges; Framework breach; Suisun City attack; NPD breach resurfaced; new breaches: Freeway Insurance, Kovack Financial, SMC, Clover Health, Interim HealthCare, UCLA Health, BigLaw firms, Valve partner, Frontier lawsuit; Sunshine Health; Health Payment Systems; 3.8M medical billing vendor breach; Shenandoah Valley Medical System breach; MyDr Poland 19M; Trezor 14k; SunCloud Health; National Corporate Housing; LiteLLM breach; French tax breach; RingCentral breach; ITRC H1 2026 data; Akira Safe Mode technique; Arkansas Oral breach; Bits of Gold 200k; SafePal 40k; Sophos report: 79% ransomware from compromised identities; EU CRA standards published; Global Azure credential theft breach (McDonald's, Vodafone, TCS); Sharecare breach claim (3.4M, unverified); See's Candies breach; Colla Health breach; Clop campaign expands to Philips, GE, Shell; VMware vCenter flaw exploited by China-nexus group for Babuk ransomware; AI-assisted attacks (Claude Code with The Gentlemen, Zerofot, RAGE); Pokémon Center breach via CEVA Logistics; CareCloud breach 3.7M-3.8M; Medusa ransomware 500+ orgs; rogue ransomware affiliate double-dip (Ransom Busters); AI-assisted attacks detailed (Mexican govt 95M, GPT-4.1); DOJ targets Russian bulletproof hosting; NK IT worker alert; Baylor Genetics breach (genetic testing data); Healthcare attack surface report (93% attacked, 72% disrupted, 410 incidents H1 2026, AI used, Stryker attack, HIPAA delay); MOVEit zero-day breach (2,500 orgs, Clop); LockBit 5.0 targets U.S. Bank; Medusa ransomware hits 500 critical infrastructure orgs by buying access; Latam Pass breach (54M members, BIN data) - Digital Privacy Watch | NBot | nbot.ai