Desk live·
ForensicPost
Section

Breaches

Unauthorised access, from first foothold to leak-site listing. Every file carries a confidence grade, an artefact count, and the questions we have not answered yet.

Files in section300
Median dwell time, 202638 days
Identity-first intrusions61%
Corrections issued4
Top of section26-0813 · Healthcare · Sev 5

19 Million Medical Records Stolen in Polish MyDr Hack

Prescriptions, appointments and medication histories for around 19 million people were taken from MyDr, a platform used by more than 12,000 Polish medical facilities. Poland’s digital affairs minister says there is no indication of an external attack.

11 min readConfidence: medium
Filter
Sort

Bank of Baroda Confirms Leak After Employee Email Compromise, With 700GB Claimed

A dispute about volume is a dispute about the wrong axis. Ask instead which fields can be reissued.

3 sources · 11 min read

Levi Strauss Says Social Engineering Compromised Three Employee Computers

Three compromised laptops, corporate data taken, and a filing that answers the shareholder question only.

2 sources · 8 min read

Amgen Says Patient Health Data Was Taken From Third-Party Cloud Systems

Materiality asks whether an investor would want to know. Whether patients are harmed is a different question.

3 sources · 11 min read

Corpus Audit: 251 of 587 Files Record No Established Entry Route

It does not mean SQL injection is rare. It means the disclosure regime records who was affected and not how.

3 sources · 13 min read

Thirty Million Rows, Claimed. A Limited Number of Systems, Confirmed

Abbott confirmed unauthorised access to a limited number of systems. ShinyHunters claims thirty million rows. Almost everything in between is unestablished.

6 sources · 14 min read

Conduent Breach Affected More Than 62 Million People, Final Count Shows

The final count on the Conduent intrusion landed above 62 million people — third-largest in US healthcare history, at a processor most of them have never heard of.

3 sources · 11 min read

An Energy Retailer, and the Customers Who Cannot Switch Quickly

Customer data leaked at a retailer serving 4.8 million. That figure is the customer base, not the affected count — and the distinction keeps getting lost.

1 source · 7 min read

AssuranceAmerica Breach Exposed 6.9 Million Driver's Licence Numbers

6.9 million driver’s licence numbers, a field that is neither ceremonially protected nor practically replaceable.

2 sources · 7 min read

Patients Learned About an October 2025 Intrusion in July 2026

The remedy is 24 months of monitoring. The scanned passport stays valid for ten years.

2 sources · 11 min read

Two Men Jailed for Five and a Half Years Over the Transport for London Attack

Twenty-seven thousand employees queued in person to reset a password. That is what a broken identity system looks like.

3 sources · 10 min read

They Shut the Network Down, and Forty-Two Million Relationships Went With It

A containment shutdown that locked members out of retirement accounts, and a credit union suing its own provider over the standards it contracted for.

3 sources · 13 min read

The Support Ticket Is the Breach

A compromise at a third-party ticketing platform used by EY’s IT staff. Ticket attachments hold whatever was needed to reproduce the problem.

2 sources · 8 min read

Qantas Customer Data Published a Year After Third-Party Platform Breach

Up to six million customers exposed in 2025; records published in 2026. Notification law assumes an incident that ends.

2 sources · 10 min read

Texas Parks and Wildlife Vendor Breach Exposed Three Million Licence Holders

Three million licence holders through a vendor the state chose. The data does not know it was collected for a fishing permit.

1 source · 7 min read

Third-party Flaw Exposed 14.2 Million Mailboxes at KDDI and Five Other ISPs

A third-party software flaw reached email accounts across six Japanese providers. Choosing a different ISP bought no independence.

1 source · 7 min read

Estee Lauder Reports Oracle E-Business Suite Breach Undetected for Ten Months

An Oracle E-Business Suite flaw exploited in August 2025, found in June 2026. The records were employees’: identity documents, bank details, health data.

1 source · 9 min read

The Company That Named the Technique Was Also Hit by It

The team that named the cluster was also caught by it, and published. That removes the easiest excuse for ignoring the technique.

2 sources · 8 min read

ShinyHunters Claim 2.2 Million Records From Kodak

A claimed 2.2 million records. Long-lived brands hold data collected across decades, terms and regulatory regimes nobody has reconciled.

1 source · 7 min read

ShinyHunters Claim 8.8TB From Amazon One Medical Legacy Archives

A claimed 8.8 TB from legacy patient archives. Every property that makes a legacy system low priority makes it high value.

1 source · 9 min read

DentaQuest Data Published After Extortion Demand Refused

Extortion refused, 234 GB published, 2.6 million addresses verified. The refusal produced a record that payment never does.

2 sources · 10 min read
© 2026 ForensicPost Media · the desk · newsletter · correctionsGlossary