SecureFact – August 31, 2026
Major cyber incidents impacted government, aviation, healthcare, retail, manufacturing, and enterprise organizations, exposing millions of records and sensitive personal, financial, medical, and corporate information worldwide.
Berlin confirms data theft after Rhysida ransomware attack claims
Berlin’s city administration confirmed that the Rhysida ransomware gang successfully exfiltrated 5.79 TB of data comprising approximately 1.44 million files from the city’s administrative network. The threat actor claims to have stolen government, legal, financial, contractual, HR, infrastructure, health, and mapping records. Compromised data includes thousands of names, email addresses, phone numbers, and 148 IBANs. The attackers obtained plaintext credentials, database accounts, payment-system data, password vaults, and credentials belonging to senior officials. Personnel files, payroll information, administrative-offense records, email archives, SQL database dumps, identity documents, and banking information were exfiltrated. Documents related to disciplinary proceedings and named cases were also stolen, along with allegedly classified government material including Bundesrat committee records. Critical-infrastructure security assessments concerning Berlin’s water supply were compromised. More than 3,200 documents marked as nondisclosure agreements were included in the theft. The attackers used GDPR violations as leverage, giving the victim four days to pay before publishing stolen files. Mayor Kai Wergner stated the city will not pay the extortion demand. The State Criminal Police Office, public prosecutor’s office, and federal security agencies are investigating the incident. Forensic investigators determined the threat actor exfiltrated data from the Senate Department for Mobility, Transport, Climate Protection and the Environment between August 7 and 12, with affected departments disconnected from the state network on August 14.
(Source: Read full report)
FulcrumSec claims Manchester Airports hack, theft of 86 GB of data
The extortion group FulcrumSec claimed responsibility for breaching Manchester Airports Group and stealing approximately 86 GB of data. The group obtained access using airport-specific Iterable API credentials exposed in client-side JavaScript. Stolen material includes a roughly 21.5 GB Manchester customer export containing consolidated profiles that combined customer identifiers with historical booking activity and marketing classifications. The breach exposed nearly 200,000 records related to upcoming travel during the remainder of 2026, containing dates, times, and booking information linked to personally identifiable information. BleepingComputer validated one traveler’s record by comparing it with known Manchester Airport purchase history, confirming the record accurately listed previous Fast Track purchases, booking and scheduled-arrival times, terminal used, amounts paid, purchase references, total spending, and apparent purpose of trips. Beyond email addresses, phone numbers, vehicle registrations, and postcodes initially disclosed by MAG, sampled records contained purchase and booking references, airport and product selections, prices, discounts, booking status, parking dates and times, historical spending, IP addresses, approximate locations, device information, and customer-engagement data. Payment-card or bank-account information was not observed in reviewed samples. FulcrumSec stated it is considering withholding or redacting records because of potential for real-world harm. MAG contacted affected customers and advised them to remain vigilant for suspicious emails, text messages, and telephone calls. The airport operator stressed it would never contact customers unexpectedly to request payment-card details, banking information, or passwords. Local media reported approximately 8.7 million customers were affected, making it the largest known customer data breach affecting a British airport operator.
(Source: Read full report)
McKesson discloses breach after ShinyHunters claims patient data theft
Healthcare and pharmaceutical distribution giant McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft. The ShinyHunters extortion group claimed it stole approximately 284 million patient-related data records from Snowflake. McKesson discovered the incident on August 25, 2026, and its investigation remains in early stages. ShinyHunters claimed it gained access through voice phishing (vishing) social engineering attacks against multiple McKesson employees, compromising multiple employees’ Okta single sign-on accounts. The threat actor used these credentials to access the company’s Salesforce and Snowflake environments. ShinyHunters fully compromised the Salesforce environment, including support cases, and allegedly stole approximately 1TB of data over four days between August 21 and August 25. The stolen Snowflake data allegedly contains approximately 284 million data records of patient-related information, though this represents a raw count of data records rather than unique individuals. Stolen information allegedly includes names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers, medical record numbers, medication and allergy information, illnesses, disabilities, appointment information, and physician information. The group also claims the data contains information related to deceased and terminally ill patients, prescriptions and medication shipments, invoices, employee information, Salesforce records, internal communications, and healthcare providers and clinics using McKesson’s services. ShinyHunters contacted McKesson after completing the data theft and demanded a $55,236,150 ransom with a 72-hour response deadline. According to ShinyHunters, McKesson did not respond to or negotiate over the ransom demand. McKesson warned that customers may experience intermittent service degradation believed to be related to the attack, though the company was not proactively disconnecting systems within its environment.
(Source: Read full report)
Manchester Airports Group says hackers stole travelers’ data
Manchester Airports Group disclosed that hackers breached its systems and stole customer data related to Manchester, London Stansted, and East Midlands airports. The intruder did not access customer payment details, and the attack had no impact on airport operations. Exfiltrated data relates to car park, lounge, and Fast Track bookings, including customers’ email addresses, phone numbers, vehicle registration numbers, and postcodes. MAG is the UK’s largest airport operator, owner of Manchester, London Stansted, and East Midlands airports, which together handle over 66 million passengers yearly. The company employs 40,000 people and generates annual revenue of £1.5 billion. After discovering the intrusion, MAG moved quickly to contain it by restricting access to affected systems, engaging with external experts, and notifying law enforcement. Out of an abundance of caution, MAG temporarily suspended its online “Manage My Booking” service and directed travelers to use its phone line instead. Potentially exposed customers were advised to remain alert for suspicious communications and avoid clicking on links arriving via email or SMS. MAG stressed that it will never ask customers for payment card information, banking details, or passwords. Customers were encouraged to follow NCSC’s post-breach recommendations to stay safe. The company contacted impacted customers directly but did not disclose the total number of affected individuals. Local media reported that data of up to 8.9 million travelers may have been exposed, citing private MAG statements; however, BleepingComputer could not confirm the figure. At the time of the initial disclosure, no ransomware or data extortion groups had claimed the attack publicly.
(Source: Read full report)
Carhartt data breach exposes information of 12.9 million accounts
The ShinyHunters extortion group published sensitive data from nearly 13 million accounts stolen from clothing retailer Carhartt earlier in August 2026, according to data breach notification service Have I Been Pwned. Founded in 1889, Carhartt is an American apparel company with workwear and streetwear manufacturing facilities in Kentucky and Tennessee and more than 3,000 employees in the United States and Europe. While Carhartt has yet to confirm the extortion group’s claims or issue a statement about the breach, ShinyHunters claimed the attack on August 13 and stated they allegedly stole more than 50GB of documents containing a wide range of customer, employee, and corporate data. ShinyHunters claimed that millions of records of customer data and vast amounts of sensitive information and personally identifiable information containing employee, customer, customer metadata (royalty info), and other internal corporate data were compromised. After analyzing the 50GB archive released by ShinyHunters on their dark web site, Have I Been Pwned founder Troy Hunt linked the resulting data breach to the compromise of Carhartt’s Databricks analytics platform, a cloud-based data platform combining standard business reporting and data storage into a unified architecture. The data breach affects more than 12.9 million Carhartt accounts, with exposed information including unique email addresses, names, phone numbers, and physical addresses. The analysis found over 15,000 employees with @carhartt.com email addresses in the leaked database. ShinyHunters also released an archive of the allegedly stolen records on its dark web after failing to pressure the apparel giant into paying a $3.3 million ransom demand. A company negotiator told the extortion gang: “After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions.” Carhartt has not publicly disclosed what information was stolen or confirmed the breach details.
(Source: Read full report)
Toy-making giant Hasbro disclose data breach affecting employees
Hasbro, one of the world’s largest toy and game companies, disclosed that attackers accessed the personal and financial information of an undisclosed number of employees. Founded in 1923, Hasbro is a publicly traded American multinational entertainment conglomerate on the NASDAQ and owns many brands including Monopoly, Clue, Nerf, Transformers, Play-Doh, Peppa Pig, Scrabble, Magic: The Gathering, and Dungeons & Dragons. The company filed data breach notification letters with the Massachusetts Attorney General’s Office but did not disclose the total number of affected individuals or when the incident was detected. According to Hasbro’s notification, the information involved varied by individual but may have included name and one or more additional personal information elements such as email, address, phone number, national ID number, or financial information. Hasbro implemented containment and remediation measures, including disabling the compromised employee account, terminating unauthorized access, and deploying additional safeguards designed to help prevent a similar incident from occurring in the future. According to the Massachusetts Attorney General’s Office 2026 Data Breach Notification Report, the breach affected the Social Security numbers, financial account information, credit/debit card numbers, and driver’s license information of 436 Hasbro employees in Massachusetts. A Hasbro spokesperson was not immediately available for comment when BleepingComputer reached out to ask whether any customers were also affected by this breach and whether the attackers sent a ransom demand. In early April 2026, Hasbro also disclosed a separate cyberattack that hit its systems on March 28, forcing the company to take some systems offline while working to restore them. According to financial reports filed by Hasbro since then, the company lost approximately $25 million in revenue because of that cyberattack. Hasbro did not link the March incident with the data breach disclosed in notification letters filed with the Massachusetts attorney general’s office this week.
(Source: Read full report)