🏢 Big Tech / /via pkware.com / updated Aug 11, 2026

PKWARE: July 2026 breaches exposed data through valid access, not broken perimeters

PKWARE says July’s biggest breaches were driven mostly by access that already worked, including phished employees, vendor systems, and inherited environments. The company argues the common failure was not the perimeter but where sensitive data was stored and whether it was protected at the data layer. That matters because several incidents exposed information that cannot be reissued, turning a one-time intrusion into lasting liability.

#PKWARE#IBM#AssuranceAmerica#Ernst&Young#Craneware#Abbott#ExactSciences#NYCHealth&Hospitals#Microsoft
~/ Big Tech/ PKWARE: July 2026 breaches exposed data through...

PKWARE’s July breach roundup says the month’s largest incidents shared a stark pattern: attackers often did not need to break in, because they were able to use access that already worked. In four of the five cases, the entry point was a phished employee, a vishing-triggered single sign-on session, a third-party ticketing platform, or vendor-connected access. The company says the harder problem was not getting past the front door, but reaching data that was already readable once inside.

One of the biggest disclosed incidents involved AssuranceAmerica, which confirmed the largest known exposure of U.S. driver’s license numbers this year after malicious activity targeting one employee. PKWARE says that single event affected nearly 7 million people. In the company’s view, that makes the breach a case study in how one compromised login can scale into a major disclosure when sensitive records are not protected at the data layer.

Ernst & Young was another example of access through an existing business workflow, according to PKWARE. The firm said an unauthorized party spent two weeks inside a third-party IT service management platform and downloaded tax documents belonging to customers of financial institutions that use EY. The source article frames the issue as broader than one company: support systems that were never meant to store regulated data can become high-value targets when they end up holding it anyway.

Craneware’s disclosure showed the same theme in a different setting. The software company, which supports hospitals, clinics, and pharmacies, told the London Stock Exchange that attackers exfiltrated file names, a percentage of employee data, and a subset of customer and partner records. PKWARE says the company contained the incident and external specialists found no residual indicators of compromise, but that did not change the fact that the exposed data had already been accessible to the attacker.

Abbott also reported unauthorized access to legacy Exact Sciences systems in its Cancer Diagnostics business, with the compromise arriving roughly twelve weeks after the acquisition that brought those systems inside. PKWARE says the attacker’s access came through a vishing campaign that compromised a corporate Microsoft Entra single sign-on account, though Abbott had not fully confirmed the vector in the source text. The larger point, according to PKWARE, is that acquired environments can remain exposed long after a deal closes if they are not quickly brought under the same security model.

NYC Health & Hospitals rounded out the month’s examples after an extortion group claimed an 11-terabyte archive months after a breach that exposed fingerprints and palm prints. PKWARE says the initial access may have come through a third-party vendor compromise. That matters because biometric data, unlike passwords or cards, cannot simply be replaced after theft, which makes the downstream consequences especially difficult to unwind.

Why this matters

PKWARE’s broader argument is that July’s incidents were not primarily failures of detection or containment. The victims in several cases noticed suspicious activity quickly, and in some cases the incidents were contained or isolated without obvious operational fallout. Even so, the attackers had already authenticated, and the data was already in a readable state when they arrived.

The company says that shifts the security question from “Did the perimeter hold?” to “Was the data protected where it lived?” Support tickets, inherited legacy systems, and vendor-reachable platforms are exactly the kinds of places teams often overlook, yet those are now routine repositories for regulated information. PKWARE points to automated discovery, minimizing retained data, and field-level encryption or tokenization as the controls that can reduce the impact when valid access is abused.

PKWARE also notes that two of July’s five incidents drew proposed class actions within 11 days of notification, underscoring how fast legal exposure can follow a breach. The month’s pattern suggests that third-party risk is no longer limited to direct supplier compromise; it also includes whatever sensitive data organizations choose to place into vendor workflows. In practice, that means contractual assurances are not enough if the underlying data remains readable.

The company’s closing warning is straightforward: attackers keep finding the easiest path through people, vendors, and inherited systems, and those paths often lead straight to data that was never meant to sit there. July’s incidents suggest that incident response alone cannot erase exposure after the fact. What remains most decisive is whether the sensitive information was already protected before anyone logged in.

share
𝕏 FB
← cd ../news