Major incidents continue across North America with six significant breaches affecting millions of individuals across financial services, healthcare, and third-party vendors. Organizations face escalating risks from contractor access, vendor vulnerabilities, and credential theft.
Critical 1.4M records Jul 2025
Allianz Life Insurance Compromised via Third-Party CRM
Allianz Life Insurance Company of North America
Attackers gained access through a third-party cloud-based customer relationship management platform using social engineering tactics against the vendor.
What it means: Customers face exposure of sensitive financial and identity data including Social Security numbers, making them vulnerable to identity theft and fraud.
Critical Undisclosed records Dec 2025
PayPal Working Capital Loan System Breached
PayPal
Threat actor accessed PayPal systems starting July 1, 2025 and maintained access through December 12, 2025 via the PayPal Working Capital loan application.
What it means: Customers who applied for working capital loans face potential account takeover and financial fraud due to prolonged system compromise.
Critical 5.8M records Oct 2025
700Credit Credential Database Compromised
700Credit
Hackers accessed customer information via a compromised third-party API, affecting the largest automotive credit check and identity verification provider in North America.
What it means: Automotive industry vendors and their customers face identity theft and fraud risks as payment and verification credentials were exposed.
Critical 1.2M records Aug 2025
University of Hawaii Cancer Center Patient Data Stolen
University of Hawaii Cancer Center
A criminal organization breached the Cancer Center's Epidemiology Division network, stealing sensitive patient records from the healthcare provider.
What it means: Cancer patients face exposure of medical history, diagnoses, and personal information that could be used for targeted fraud or blackmail.
High 30 records Feb 2026
Coinbase Insider Theft Exposes Customer Accounts
Coinbase
A contractor improperly accessed and leaked screenshots of an internal support tool revealing customer identity verification details, wallet balances, and transaction history.
What it means: Customers face account takeover risk and targeted attacks as criminals can now profile valuable accounts and validate credentials.
Significant 17K records Feb 2026
Volvo North America Exposed via Vendor Breach
Volvo Group North America
Customer and staff data was exposed through Conduent, a third-party business services provider used for operations and administration.
What it means: Employees and customers face identity theft risk from exposure of personal and contact information through cascading vendor vulnerabilities.