🛡️ Cybersecurity / /via securityaffairs.com / updated 1d ago

Wave of Global Data Breaches Hits Wallet App, McDonald’s, French Tax Agency and Healthcare Firms

A string of major breaches has exposed data on millions of users, employees and patients across finance, retail, government and healthcare. Recent incidents span a SafePal order-tracking flaw, claimed McDonald’s employee data theft from Azure, a confirmed French tax agency cyberattack, and multi-million–record healthcare leaks. The cluster of cases underscores how third-party tools, cloud tenants and legacy datasets are becoming prime targets in a steadily escalating data-theft economy.

#SafePal#McDonald’s#France’staxadministration#CEVALogistics#UnlimitedTechnologySystems#SISVISA#PoliceNationalLegalDatabase#ŻabkaPolska#CareCloud#Azure
~/ Cybersecurity/ Wave of Global Data Breaches Hits Wallet App, M...

A fresh wave of data breaches is rippling across the tech, finance, retail, government and healthcare sectors, exposing the personal and professional details of millions of people worldwide. In the span of just a few months, a crypto wallet vendor, a global fast-food giant, France’s tax authority, logistics operators, and multiple healthcare technology firms have all disclosed or been linked to serious security incidents. The diversity of victims and attack paths highlights how attackers are probing every layer of digital infrastructure, from public cloud tenants to forgotten databases.

Crypto wallet company SafePal is among the latest to confirm a breach, revealing that personal data tied to 39,798 customers was exposed after hackers exploited a vulnerability in its order-tracking plugin. The incident affected orders placed between March 2, 2025, and April 11, 2026, but did not compromise wallet credentials, private keys, seed phrases, or payment information, according to the company’s disclosure. That distinction will offer some relief to customers, yet the exposure of order-linked personal details still creates risks ranging from targeted phishing to identity abuse.

In the retail sector, McDonald’s is facing questions after a seller on a data-trading forum claimed to be offering a trove of 1.7 million employee records allegedly taken from the company’s Azure tenant. The seller posted an 8,000-row sample to support the claim, and early checks suggest that the sample appears genuine, even if its age and the true size of the stolen directory remain unconfirmed. If validated, such a dataset could provide attackers with wide visibility into staff contact details and organizational structure, fueling social engineering and internal fraud attempts.

Government infrastructure is not being spared either. France’s tax administration confirmed that a sophisticated cyberattack exposed personal data, including income and tax details, for 678,000 taxpayers and businesses. The incident followed a threat actor’s boast in late June that they had breached the tax agency, prompting officials to launch a criminal investigation and bring in the national cybercrime unit. While operational details remain limited, the combination of tax identifiers and financial data makes this breach particularly sensitive for victims.

Other sectors are grappling with large-scale operational and privacy fallout of their own. CEVA Logistics, a major logistics operator, reported that a cyberattack on July 29 disrupted parts of its European operations, affecting eight warehouses and halting shipments at those locations while restoration efforts continue. In a separate incident, a vendor on a leak forum claimed to possess Israel’s 2026 population registry, offering 9.2 million records that checks suggest are authentic but date back to 2005, underscoring how decades-old data can resurface with new impact.

Healthcare-related platforms continue to be prime targets given the sensitivity and longevity of medical information. Unlimited Technology Systems disclosed that attackers accessed one of its commercial data centers over several days in October 2025, stealing personal, medical and insurance data for more than 3.8 million people. CareCloud, a New Jersey-based health tech company that stores records for tens of thousands of providers across the United States, is also notifying 345,000 individuals after hackers stole medical and financial data from its AWS-hosted systems, months after initially disclosing the breach.

Beyond headline-grabbing numbers, researchers are still uncovering quietly exposed systems that can be browsed without even basic authentication. Security researcher Jeremiah Fowler found a publicly accessible database belonging to SISVISA, Brazil’s Health Surveillance Information System, containing exactly 102,215 records with IDs, tax data and regulatory documents left open to the internet. In the UK, the Police National Legal Database confirmed that a breach exposed the names and work email addresses of police officers, staff and criminal justice contacts across England and Wales, raising concerns about targeted phishing and harassment of law enforcement personnel.

Not even internal tools and developer environments are immune from monetized leaks. In Poland, a brand-new account on a hacking forum appeared on August 2, offering what it claimed was a full data dump from Żabka Polska, the country’s largest convenience store chain, for €5,000. The offer included Jira data, GitLab repositories and embedded secrets such as API keys, and security researchers who reviewed the sample were able to verify a significant portion of the material, illustrating how compromised DevOps assets can translate into long-term security debt for retailers.

Why this matters

The current cluster of incidents illustrates how modern breach risk is no longer confined to core payment systems or obvious high-value databases. Attackers are just as willing to exploit a vulnerable order-tracking plugin, a misconfigured health surveillance database or a cloud-hosted employee directory if the result is a rich dataset that can be traded, ransomed or reused for further attacks. For organizations, the lesson is that every external integration, SaaS tenant and internal dev tool effectively broadens the attack surface, and any assumption that certain data is too old or too obscure to be worth protecting is increasingly dangerous.

Looking ahead, the real impact of these breaches will unfold over months and years as stolen datasets are combined, resold and weaponized in less visible ways. Victims may see more convincing phishing, tax fraud attempts, and abuse of medical and insurance information long after initial notifications fade from the news cycle. For companies and public agencies, the pressure will mount to harden third-party plugins, audit legacy systems and developer platforms, and improve transparency around cloud security practices, as regulators and users alike demand more than after-the-fact disclosure when their data becomes collateral in the expanding cybercrime economy.

share
𝕏 FB
← cd ../news