Abbott confirmed unauthorised access to a limited number of systems. ShinyHunters claims thirty million rows. Almost everything in between is unestablished.
6.9 million driver’s licence numbers, a field that is neither ceremonially protected nor practically replaceable.
Twenty-seven thousand employees queued in person to reset a password. That is what a broken identity system looks like.
An Oracle E-Business Suite flaw exploited in August 2025, found in June 2026. The records were employees’: identity documents, bank details, health data.
The team that named the cluster was also caught by it, and published. That removes the easiest excuse for ignoring the technique.
A claimed 2.2 million records. Long-lived brands hold data collected across decades, terms and regulatory regimes nobody has reconciled.
Valid credentials from somebody else’s breach, accepted. Nothing failed in the conventional sense, and customer data went anyway.
A phone call, a consent screen, and a refresh token that outlives every password change. No exploit is involved at any step.
A phishing-led compromise affecting close to six million guests, including passport numbers a passenger could never have declined to provide.
A vishing call against an employee’s Entra account, then customer records in a connected CRM. The reported total has moved from 4.9 million upward.
Two years between the intrusion and the notification, on identity documents. Small organisations produce long intervals, and mostly go unrecorded.
About 11.7 million accounts on France’s national identity portal, and a detained fifteen-year-old. The age is the least useful fact in the file.
The contract moves the work, the staffing and the cost. It does not move the consequence of resetting the wrong person’s credential.
229,200 driver’s licences at a lending platform, plus data for 797 broker firms. The licence is the KYC document other institutions trust.
967,000 accounts at a lending platform. Underwriting assembles identity, income and obligations — including for people who were declined.
Around three billion records in an unsecured database, including a billion KYC entries. No intrusion, no actor, and no way to say who read it.
A 139 TB claim against a national identity register, and issuance halted. A biometric register has no reissue path.
A number identifies a billing relationship. It now secures banking and government access, and the depending services cannot see a port request.
Most victims had no opportunity to behave differently. The failure was entirely at the carrier, and awareness training addresses none of it.
In many countries these are the most complete identity datasets in existence, and the state’s dataset is not one you can leave.
A credit application is the densest identity document an ordinary person produces. Most of the people in the database were declined.
Three hundred files describe organisations losing data. This is the other end — and there is no bridge between them.
The harms that get counted are the ones somebody already had a process for. Biometrics and medical history generate no report at all.
Self-service is not a convenience feature with a security cost. It is a decision about who holds authority.
An HR pretext works everywhere. Employees are conditioned not to question it, because the topics are personal and the consequences are employment-related.
A stolen code is worth one authentication. An enrolled device is worth all of them, and a password reset does not remove it.
Every anti-phishing control is looking for a fake site. There was no fake site — the employee consented on the real one.
The data followed the obligation and the supervision did not follow the data.
Credit monitoring is a product designed for the population that files the most reports — and useless against a persuasive phone call about savings.
The second move works because the first one is real. The employee has a genuine problem, and internal IT has arrived unprompted to solve it.
The identity boundary expressed as hardware. And a vendor exploited recently is more likely, not less, to be exploited again.
Once identity is compromised, a reset performed over the phone is exactly the mechanism it is trying to undo. The only remaining verifier is a face.
The case where the availability cost is documented and the confidentiality count is the footnote.
Whatever does not survive a migration is removed silently, and nobody is told.
The factor held. Being known to use it became the attack surface.
165 separate failures with one shape, and a platform that was never itself breached.
The platform behaved correctly at every step and 165 organisations lost data anyway. There was no CVE to index it under.
A rule to collect identity documents, and no matching rule to dispose of them.
A hundred and forty hospitals losing their record system is not a proportionate consequence of one download. What sits between is everything it was allowed to reach.
A written requirement that MFA be enabled everywhere is not a control. It is intent somebody then has to enforce against an estate nobody has fully inventoried.
No lookalike domain and no spoofed sender. The message came from a real colleague’s real account.
14,000 accounts to 6.9 million people. The multiplier was a feature, working as designed.
A HAR file does its job by capturing exactly the material an attacker needs.
Once the seeds live in an account protected by the same identity, there is one factor wearing two names.
Decommissioning is an intention. Switching something off is an action.
A reader comparing incidents by their first published figure is comparing almost nothing.
The corporate boundary turned out to run through a domestic living room.
There was no exploit. The endpoint answered anyone who asked, because nothing asked who was calling.
The second factor was not bypassed. It was delivered to the right person, who said yes.
Three Cloudflare employees typed their password into the attacker’s page. Nothing happened.
For a pseudonymous account, a phone number is not contact data. It is the link to the person.
Collected from a child, retained past the relationship, past the product, past recognition.
The browser did nothing wrong. It carried a work password into a personal account, exactly as designed.
The alert fired on day one. The customers heard on day sixty-one, from the attackers.
The harm is not identity theft. For a person on this list, the harm is being found.
Voice phishing into identity providers, then leak-site extortion. Active since 2020.