Cybersecurity incidents continued to rise throughout August 2026, affecting healthcare providers, manufacturers, AI companies, software vendors, financial institutions, and millions of consumers worldwide. Attackers increasingly leveraged phishing, ransomware, credential theft, supply chain attacks, and AI-powered techniques to compromise organizations.
Below is a roundup of some of the most significant cybersecurity incidents reported during August 2026, along with practical security recommendations that organizations and individuals can implement to reduce risk.
McKesson discloses breach after ShinyHunters claims patient data theft
McKesson found unauthorized access to third-party applications on August 25 and disclosed it in an SEC 8-K. ShinyHunters says vishing calls compromised employees’ Okta SSO accounts, which gave access to Salesforce and Snowflake. The group claims it took about 1TB over four days and demanded roughly $55M. The 284M figure is a raw row count, not a count of unique patients.
Lessons learnt:
- Use phishing-resistant MFA (FIDO2/passkeys) instead of push approvals.
- Build a strict help-desk and caller verification process.
- Alert on bulk exports from SaaS data platforms.
Baxter International: 7.1M Salesforce records claimed
Baxter reported unauthorized activity involving certain third-party applications, with no impact on manufacturing or patient services. ShinyHunters claimed 7.1 million Salesforce records and published the data on August 19.
Lessons learnt:
Keep an inventory of the sensitive data held in SaaS apps.
Apply least-privilege access and monitor API export volumes in the CRM.
Carhartt data breach exposes information of 12.9 million accounts
The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned.
Founded in 1889, Carhartt is an American apparel company with workwear and streetwear manufacturing facilities in Kentucky and Tennessee and more than 3,000 employees in the United States and Europe.
While Carhartt has yet to confirm the extortion group’s claims or issue a statement about the breach, ShinyHunters claimed the attack on August 13 and said they allegedly stole more than 50GB of documents containing a wide range of customer, employee, and corporate data.
“Millions of records of customer data and vast amount of sensitive information and PII containing employee, customer, customer metadata (royalty info), and other internal corporate data was compromised,” the cybercrime gang said.
ShinyHunters also released an archive of the allegedly stolen records on its dark web after failing to pressure the apparel giant into paying a $3.3 million ransom demand.
“After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions,” a company negotiator told the extortion gang, according to ShinyHunters.
1.6 Million Likely Impacted by RingCentral Data Breach
The personal information of 1.6 million individuals appears to have been stolen from the widely used business communications platform RingCentral by a notorious extortion group.
The incident occurred in July and was the result of a “sophisticated social engineering campaign”, RingCentral said in a notice on its website.
Lessons learnt:
- Train staff on impersonation calls.
- Limit the customer data support staff can reach, and require step-up authentication for bulk access.
Apollo Global Management confirms breach
Apollo Global Management confirmed it was among several financial institutions impacted by a string of social engineering attacks.
Attackers gained unauthorized access to some of the private equity firm’s cloud platforms between July 6 and July 10, the company said in a data breach notification filed in California. Apollo did not say when or how it became aware of the intrusion and did not respond to a request for comment.
Apollo is the first victim to formally disclose that sensitive personal data under its care was compromised by a wave of attacks that have hit large private equity firms, law firms, financial rating agencies and medical technology companies.
Lessons learnt:
- Watch for anomalous cloud logins.
- Shorten session lifetimes for privileged cloud users.
Data breach at shipping giant Ceva Logistics affecting banks, retailers, and more.
Ceva Logistics, one of the world’s largest shipping and logistics giants, has been hacked. Several companies that rely on Ceva for shipping their products to their customers say that their personal information was also stolen in the breach.
The hack at Ceva also resulted in a data breach, affecting a large amount of personal information belonging to retail customers that Ceva relies on for delivering goods to people’s home addresses. Several companies reported that hackers took their customers’ names, home addresses, phone numbers, and email addresses used to place their orders from Ceva’s systems.
Lessons learnt:
- Map which vendors hold your customer PII.
- Contracts should require prompt breach notification, and business continuity plans should cover logistics partners.
Medical device maker Boston Scientific affected by cyberattack
A cyberattack on U.S. medical device maker Boston Scientific is causing an ongoing “global disruption” to its operations, according to a federal regulatory filing on Wednesday. This is the latest health tech giant to face a cyberattack in recent weeks.
The Massachusetts-based company, which makes medically implanted devices like pacemakers and defibrillators, confirmed in a filing with the U.S. Securities and Exchange Commission that on Tuesday it began experiencing “disruptions and limitations of access” to its IT systems and business applications critical for its operations.
Lessons learnt:
Test business continuity for operational outages, not just data loss.
Discover more from Information Security Blogs
Subscribe to get the latest posts sent to your email.
