This week witnessed significant identity broker exposures and healthcare ransomware disruptions across North America. Data broker vulnerabilities dominated the landscape, with massive credential databases exposed while healthcare infrastructure faced continued ransomware pressure.
Critical 677M records Mar 03
Infutor Data Broker Exposes 677M Americans' SSNs
Infutor/ActiveProspect
An Elasticsearch database containing full names, addresses, phone numbers, dates of birth, and Social Security numbers was exposed on the internet without authentication. SOCRadar discovered the misconfigured database linked to data broker Infutor.
What it means: This represents wholesale compromise of identity infrastructure, providing criminals everything needed for large-scale fraud across financial services and healthcare sectors.
High 2.7M records Mar 19
Navia Benefits Breach Compromises 2.7M Employee Records
Navia Benefit Solutions
Threat actors exploited Broken Object Level Authorization vulnerability between December 2025-January 2026, accessing Social Security numbers, names, addresses, and health plan information. Multiple major employers' benefits data was compromised.
What it means: Employee benefits systems represent a goldmine for identity thieves, affecting workers across multiple Fortune 500 companies through a single vendor compromise.
High 400K records Mar 03
LexisNexis Legal Suffers Government Data Breach
LexisNexis Legal & Professional
FulcrumSec exploited React2Shell vulnerability to access AWS infrastructure, stealing 2GB of data including federal judges, DOJ attorneys, and court clerk information. The attack leveraged over-privileged container access to Redshift databases.
What it means: Compromise of legal sector infrastructure threatens attorney-client privilege and exposes government legal operations to criminal-targeting sources.
Significant 6.8M records Mar 19
Crunchyroll Customer Support Tickets Stolen
Crunchyroll
Hackers compromised Okta SSO account of support agent and planted malware, stealing over 8 million support tickets containing email addresses, names, login information, and geographic data.
What it means: Customer service infrastructure provides extensive personal data for social engineering attacks and account takeover campaigns against younger demographics.
High 192K records Feb 21
Kaplan Education Provider Exposes Driver's Licenses
Kaplan North America
Unauthorized party accessed networks containing names, Social Security numbers, dates of birth, and driver's license numbers. The education and training provider began notifications in mid-March after discovering the breach in February.
What it means: Educational services hold complete identity packages needed for financial fraud, affecting students and professionals seeking career advancement.
Critical Unknown records Mar 10
Telus Digital Hit by ShinyHunters Mega-Breach
Telus Digital
ShinyHunters exploited stolen Google Cloud credentials to access nearly 1 petabyte of data including customer support logs, voice recordings, FBI background checks, source code, and financial information from 28+ clients. Attackers demanded $65M Bitcoin ransom.
What it means: Supply chain compromise of major BPO provider exposes sensitive data across multiple industries, demonstrating risks of third-party vendor concentration.