Strobesstrobes
Platform
Solutions
Resources
Customers
Company
Pricing
Book a Demo
Strobesstrobes

Strobes connects every exposure signal to autonomous action, so security teams fix what matters, prove what works, and stop chasing noise.

Book a DemoTalk to an expert
ISO 27001SOC 2CREST
  • Platform
  • Platform Overview
  • Agentic Exposure Management
  • AI Agents
  • Integrations
  • API & Developers
  • Workflows & Automation
  • Analytics & Reporting
  • Solutions
  • Exposure Assessment (EAP)
  • Attack Surface Management
  • Application Security Posture
  • Risk-Based Vulnerability Management
  • Adversarial Exposure Validation (AEV)
  • AI Pentesting
  • Pentesting as a Service
  • CTEM Framework
  • By Industry
  • Financial Institutions
  • Technology
  • Retail
  • Healthcare
  • Manufacturing
  • By Roles
  • CISOs
  • Security Directors
  • Cloud Security Leaders
  • App Sec Leaders
  • Resources
  • Quick Agentic Pentest
  • Blog
  • Customer Stories
  • eBooks
  • Whitepapers
  • Datasheets
  • Videos & Demos
  • Exposure Management Academy
  • Pentesting ROI Calculator
  • Pentest Health Check
  • Security Tool ROI Calculator
  • Company
  • About Strobes
  • Meet the Team
  • Trust & Security
  • Contact Us
  • Careers
  • Become a Partner
  • Technology Partner
  • Partner Deal Registration
  • Press Release

Weekly insight for security leaders

CTEM research, agentic AI trends, and what's actually moving the needle.

© 2026 Strobes Security Inc. All rights reserved.

Privacy PolicyTerms of ServiceCookie PolicyAccessibilitySitemap
Back to Blog
Biggest data breaches of August 2026, eight incidents and the exposure gaps attackers exploited
Data Breaches

Biggest data breaches of August 2026

Shubham JhaSeptember 3, 202616 min read

Table of Contents

  • August 2026 breaches at a glance
  • 1. McKesson: 284 million records claimed, but not 284 million patients
  • 2. Baxter International: 7.1 million records claimed, almost nothing confirmed
  • 3. Carhartt: an independent researcher cuts the hacker's own number in half
  • 4. Unlimited Technology Systems: a ten-month-old breach reaches 3.8 million people
  • 5. Fortune 500 Azure campaign: no CVE, just stolen logins
  • 6. Questel: the attacker claimed Salesforce, the company says SharePoint
  • 7. RingCentral: a phone call, then 1.6 million exposed accounts
  • 8. ReliaQuest: the company tracking the campaign got pulled into it
  • What does one stolen login actually reach?
  • Sources

Authors

S
Shubham Jha

Share

Table of Contents

  • August 2026 breaches at a glance
  • 1. McKesson: 284 million records claimed, but not 284 million patients
  • 2. Baxter International: 7.1 million records claimed, almost nothing confirmed
  • 3. Carhartt: an independent researcher cuts the hacker's own number in half
  • 4. Unlimited Technology Systems: a ten-month-old breach reaches 3.8 million people
  • 5. Fortune 500 Azure campaign: no CVE, just stolen logins
  • 6. Questel: the attacker claimed Salesforce, the company says SharePoint
  • 7. RingCentral: a phone call, then 1.6 million exposed accounts
  • 8. ReliaQuest: the company tracking the campaign got pulled into it
  • What does one stolen login actually reach?
  • Sources

Authors

S
Shubham Jha

Share

TL;DR
  • ✓McKesson is the month's largest exposure. ShinyHunters says it pulled 284 million records out of Snowflake after voice-phishing employee logins, then demanded $55 million. That number counts database rows, and the group told BleepingComputer it hasn't finished analyzing the data and doesn't know how many real people are in it.
  • ✓Six of the eight entries here trace to ShinyHunters: McKesson, Baxter, Carhartt, Questel, RingCentral, and ReliaQuest. Fewer targets than the 100-plus organizations it hit in a single Okta campaign in January, and much bigger names.
  • ✓Claimed numbers keep failing verification. Troy Hunt found Carhartt's real total was roughly half what ShinyHunters implied. TCS says the Azure data being sold under its name looks more than four years old.
  • ✓Only one company in this list, ReliaQuest, can point to a control that stopped the intrusion on its own.
  • ✓Every figure below is tied to a company statement, a regulatory filing, or a named security outlet. Attacker claims are labeled as claims.

Most data breaches in August started with a phone call. Attackers talked employees into handing over single sign-on credentials or approving a push notification, then used that access to reach Salesforce, Snowflake, Databricks, and Entra ID. Eight incidents stood out, and in several of them the headline number still doesn't match anything a company or an independent researcher has confirmed. Here's what happened in each one, and the things worth doing about it.

August 2026 breaches at a glance

#OrganizationScaleAttack typeThreat actorConfidence
1McKesson284M records claimedVishing into Salesforce/SnowflakeShinyHunters (claimed)Access confirmed by company; scale attacker-claimed
2Baxter International7.1M records claimedThird-party application compromiseShinyHunters (claimed)Access confirmed by company; scale and actor unconfirmed
3Carhartt12.9M confirmed (independently verified)Databricks compromise, extortionShinyHuntersConfirmed via independent researcher analysis
4Unlimited Technology Systems3,803,750 confirmedData center intrusionUnknownConfirmed (HHS breach portal)
5Fortune 500 Azure campaign3.6M records, 9 companiesAccess vector unresolved; no CVE confirmed"TheHatman"Corroborated by cybercrime intelligence firm; TCS denies a breach, others silent
6Questel1.74M indexed by XposedOrNotVishing into Microsoft 365 (SharePoint)ShinyHuntersAccess confirmed by company; attacker's Salesforce/scale claims unconfirmed
7RingCentral1.6M claimed (HIBP-analyzed)Social engineeringShinyHuntersAccess confirmed by company; scale unconfirmed by company
8ReliaQuestView-only access confirmed, no data theftVishing/SSO phishingShinyHuntersFully confirmed and detailed by company

1. McKesson: 284 million records claimed, but not 284 million patients

Discovered August 25, disclosed August 28, scope confirmed August 29, 2026 · Healthcare / Pharmaceutical Distribution · United States · ShinyHunters (claimed)

McKesson, a major US healthcare and pharmaceutical distributor, says it discovered a cybersecurity incident on August 25, 2026, involving unauthorized access to third-party applications. The company disclosed it via a Form 8-K filing with the SEC, saying it has not determined the incident is material and has not confirmed any impact on its financial condition. The next day, CTO Francisco Fraga gave customers the one scope detail McKesson is willing to put on the record: attackers exfiltrated data tied to "a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units." The company says it expects intermittent service degradation and will provide credit monitoring to affected individuals. No record count, no data-type breakdown, no attribution.

ShinyHunters told BleepingComputer a far larger story: that vishing calls against multiple McKesson employees compromised their Okta single sign-on accounts, which the group then used to reach McKesson's Salesforce and Snowflake environments. The attackers claim to have fully compromised Salesforce, including support cases, and pulled 284 million patient-related records from Snowflake, exfiltrating roughly 1TB of data over four days between August 21 and August 25. That figure is a raw row count, not a count of unique patients, and ShinyHunters itself told BleepingComputer it hasn't fully analyzed the data and doesn't know how many actual people are represented in it. The group is demanding approximately $55 million and gave McKesson until September 1 to start negotiating. The domain used in the campaign, mckesson[.]claims, matches a pattern ReliaQuest's own threat research team had already been publicly tracking days earlier, registering domains that impersonate a target's name under the .claims top-level domain.

A distributor that moves medicine to pharmacies nationwide found its biggest exposure wasn't a server. It was an employee picking up the phone.

2. Baxter International: 7.1 million records claimed, almost nothing confirmed

Disclosed August 13, 2026 · Healthcare Equipment · United States · ShinyHunters (claimed)

Baxter's own statement, posted August 13, says the company identified unauthorized activity involving certain third-party applications. It says there has been no impact to manufacturing operations, customer operations, patient services, or business continuity, and no evidence that Baxter products or connected solutions used to deliver patient care were affected. The investigation is ongoing, and Baxter says it does not currently expect a material impact on its financials.

ShinyHunters added Baxter to its dark web leak site the next day, August 14, claiming to have stolen 7.1 million Salesforce records, and gave the company until August 17 to negotiate. HIPAA Journal notes that a claim of 7.1 million records does not necessarily mean 7.1 million patients were affected, the same row-count-versus-people distinction that applies to McKesson's much larger number this month. The data went up for download on August 19, which suggests, though neither side has confirmed it outright, that negotiations either never started or fell apart. Baxter, a Deerfield, Illinois-based manufacturer of renal care, IV, and infusion devices, has not confirmed the Salesforce attribution or the 7.1 million figure, saying only that the incident involved certain third-party applications.

Baxter's statement is confident about what wasn't touched. It says almost nothing about what was.

3. Carhartt: an independent researcher cuts the hacker's own number in half

Attack claimed August 13, verified count August 27, 2026 · Apparel / Retail · United States · ShinyHunters

ShinyHunters claimed the attack on Carhartt on August 13, saying it had stolen more than 50GB of customer, employee, and corporate data, and demanded a $3.3 million ransom. According to ShinyHunters, Carhartt's negotiator turned them down flat: "After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions." Carhartt has never commented publicly, so that account of the negotiation comes from the attacker alone. ShinyHunters was less diplomatic in its own telling, dismissing Carhartt's negotiator as "a very unskilled and incompetent negotiator" before publishing the data on its dark web site.

Rather than take the attacker's word for the damage, Have I Been Pwned founder Troy Hunt analyzed the leaked archive himself, linking it to a compromise of Carhartt's Databricks analytics platform, and used an AI tool called OpenClaw to help do it. His email extractor pulled nearly 25 million addresses out of the dump; running that through OpenClaw and his own manual review turned up obvious padding, email domains using randomized strings typical of synthetic test data, customers supposedly located in Benin and Montenegro in numbers that made no sense for a US retailer, and birth dates clustered in the early 1900s. Stripping out the fake and duplicate entries brought the real number down to 12,933,413 accounts, the figure that made it onto Have I Been Pwned, which notes 83 percent of those had already appeared in prior breaches. The confirmed data includes email addresses, names, phone numbers, and physical addresses, along with more than 15,000 internal @carhartt.com employee addresses found in the same database. Carhartt itself has still not issued a public statement about the incident.

Hunt wrote the whole thing up as a cautionary tale about breach claims and verification. The most reliable number in this story came from someone checking the hacker's math, not from the hacker and not from the company.

4. Unlimited Technology Systems: a ten-month-old breach reaches 3.8 million people

Intrusion October 2025, disclosed August 2026 · Healthcare Technology · United States · Unknown

Unlimited Technology Systems, an Ohio-based provider of financial and revenue-cycle technology working with more than 4,500 oncology offices and 6,500 specialty providers, discovered an incident involving one of its commercial data centers in October 2025. Its investigation determined hackers stole data from its systems between October 5 and October 10, 2025.

The stolen data includes names, addresses, phone numbers, email addresses, Social Security numbers, medical record numbers, diagnoses, dates of service, insurance policy numbers, claims and benefits information, and scanned identity documents. The company says the incident did not involve full medical records, imaging, or financial account information, and it is not aware of any attempted or actual misuse of the data. Unlimited notified HHS in late July that 3,803,750 people were affected; HHS added the company to its breach portal on August 6. Affected individuals are being offered two years of free credit monitoring, fraud consultation, and identity theft restoration. Unlimited has not named the threat actor responsible, and no extortion or ransomware group has surfaced publicly claiming the attack.

Ten months passed between the intrusion and the moment this became a number on a federal breach portal.

5. Fortune 500 Azure campaign: no CVE, just stolen logins

Listings began August 1, reported mid-August 2026 · Cloud / Identity · Global · "TheHatman"

A threat actor using the alias "TheHatman" is selling roughly 3.6 million employee-directory records allegedly pulled from the Microsoft Azure and Entra ID tenants of nine large companies, according to cybercrime intelligence firm Hudson Rock: McDonald's, Vodafone, Tata Consultancy Services, Kyndryl, HCL Technologies, InterContinental Hotels Group, Gap, Hexaware Technologies, and Wyndham Hotels. McDonald's accounts for the largest single dump, 1.7 million records, followed by TCS at 800,000, Vodafone at 425,000, and HCL at 250,000. Hudson Rock assessed the data as "highly likely authentic," based on corporate email structures consistent with real Azure directory exports, and the sample it reviewed includes phone numbers, employee IDs, job titles, reporting structures, and service account details, some flagged with Global Administrator privileges.

How TheHatman actually got in is genuinely unresolved. The attacker claims compromised credentials did it, but Hudson Rock says it could not independently establish the access vector, and while its own infostealer database contains stolen Microsoft cloud credentials tied to most of the named companies, it could not link those specific credentials to TheHatman's alleged access. Infostealer malware, phishing, weak or missing multi-factor authentication, and overly permissive third-party app access are all still on the table. What Hudson Rock is confident about is the negative case: no CVE, no confirmed platform vulnerability. Its reasoning is worth repeating directly: "Judging by the massive size of the organizations impacted, it appears highly likely that this campaign originates from targeted exploitation of Infostealer infections rather than a systemic zero-day vulnerability in Azure. If this were a widespread vulnerability, we would likely see a much broader spectrum of organizations impacted, including smaller businesses, rather than just these massive Fortune 500-level enterprises."

Tata Consultancy Services is the only named company to respond, and its response cuts against the claim. In an August 10 filing with the Bombay Stock Exchange, TCS said it had found no credible evidence of a breach of its own systems or its customer environments, that the data referenced in the alerts appears to be more than four years old and limited to basic employee details like names, IDs, job titles, and contact information, and that nothing indicates customer data, customer systems, or its operational systems were affected. Eight of the nine companies have said nothing at all.

A security firm that's confident there's no software flaw here still can't say exactly how the attacker got in, and it says so plainly instead of guessing.

6. Questel: the attacker claimed Salesforce, the company says SharePoint

Attack claimed August 2, company statement August 13, 2026 · Intellectual Property Services · France · ShinyHunters

ShinyHunters attacked Questel, a French intellectual property and innovation management firm, on August 2, threatening to leak more than 21 million Salesforce records and 147GB of internal data unless the company responded by August 4. The threat message ran through the group's standard template, the same "several annoying (digital) problems" and "don't be the next headline" wording it has been pasting into leak-site listings since at least February, including the Baxter listing earlier this month.

Questel's own statement to CyberInsider tells a narrower story than the threat. The company confirmed a voice-phishing (vishing) attack led to unauthorized access to part of its Microsoft 365 environment, specifically a Sales SharePoint environment, not Salesforce, the platform ShinyHunters actually named. Questel says the access has been contained, its production tools and IP platforms were never touched, and operations continued normally throughout. On the attacker's broader claims, the company was direct: "We are therefore not in a position to confirm all of the claims made by the threat actor at this stage." What Questel hasn't said is just as notable: how the vishing call actually turned into Microsoft 365 access, how long the access lasted, or which categories of data were exposed. The company is notifying affected customers, working with outside cybersecurity experts, and has reported the incident to France's data protection authority (CNIL) and filed criminal complaints. Independent breach-tracking service XposedOrNot separately indexed 1,744,241 exposed records, including email addresses, physical addresses, dates of birth, and phone numbers, though that figure comes from XposedOrNot's own analysis, not from Questel.

The attacker named one Microsoft product. The company that got breached says it was a different one.

7. RingCentral: a phone call, then 1.6 million exposed accounts

Incident July 2026, disclosed July 28, leak analyzed August 13, 2026 · Business Communications · United States · ShinyHunters

RingCentral, a widely used business communications platform, said a "sophisticated social engineering campaign" in July led to unauthorized access to customer data. The company says it stopped the activity, brought in a third-party forensic firm, and has seen no new unauthorized activity since. RingCentral says only a limited portion of customers was affected, those individuals were notified directly, and the core platform was never disrupted.

RingCentral did not name the attackers, but ShinyHunters added the company to its leak site on July 27, a day before the disclosure, claiming to have stolen more than 623GB of data. When RingCentral did not pay, the group published a 280GB archive roughly a week later. Have I Been Pwned added the leak to its database on August 13, finding approximately 1.6 million unique email addresses along with names, addresses, and phone numbers. RingCentral has not confirmed the attackers' claims or that specific figure. The incident first surfaced in our July 2026 breach roundup, before the leaked archive had been analyzed.

The company that makes its living on secure business communication got in through a phone call.

8. ReliaQuest: the company tracking the campaign got pulled into it

Attack August 22, confirmed August 23, 2026 · Cybersecurity · United States · ShinyHunters

On August 17, ReliaQuest posted publicly that it was tracking a widespread ShinyHunters phishing campaign built around domains following a company[.]claims pattern, the same pattern later used against McKesson, and warned that the group had started expanding its social engineering beyond IT and help desk impersonation to include posing as legal teams. Within days, someone posted screenshots that appeared to show access to a ReliaQuest Okta dashboard. ShinyHunters posted the same screenshots on its own leak site, along with a taunting message aimed at the security firm.

ReliaQuest published its account the same day the listing went up. Attackers registered a fake domain hosting a ReliaQuest single sign-on phishing page, then called multiple employees, each time posing as a specific, named security employee. One employee entered their password and approved a push notification, handing the attacker a brief session on the identity dashboard. ReliaQuest says the access obtained was view-only, that every further attempt to reach other applications from that dashboard was blocked by existing security controls, that no additional identities or business applications were reached, that no customer or company data was accessed beyond the one employee's login credentials, and that no persistence was established. The company explicitly denies claims that it was compromised or hit by ransomware.

The company publicly tracking this exact campaign got pulled into it days later, and its own security controls were the only reason it stopped there.

What does one stolen login actually reach?

Look at where the data actually came from. Snowflake at McKesson. A Databricks platform at Carhartt. A Sales SharePoint site at Questel. Entra ID directories in the Azure listings. Where anyone has confirmed the entry point, it was a phone call and one valid session, and the session is what reached the data.

That second hop is where teams have the least visibility. You can guess which of your employees would fall for the call. Ask which systems one compromised SSO session reaches today, and the honest answer is usually a diagram from a pentest a few quarters back, drawn before the last handful of integrations went live.

Attackers work it out from the inside, and McKesson shows how fast. Four days between the first call and a terabyte leaving Snowflake. You can keep the same answer current on your side, through continuous validation, so what you assume is reachable and what actually is don't drift apart. That is the same gap that turns a scanner backlog into noise, which we covered in why most of your scanner backlog is noise.

If you want a sense of where your own gaps sit, the CTEM maturity assessment walks through discovery, validation, and mobilization in a few minutes.

For the wider pattern across the year, see our month-by-month breach archive and the latest top CVEs roundup.

Sources

  • McKesson · BleepingComputer · SecurityWeek
  • Baxter International · Company statement · HIPAA Journal
  • Carhartt · Troy Hunt · The Register · BleepingComputer · Have I Been Pwned
  • Unlimited Technology Systems · SecurityWeek
  • Fortune 500 Azure campaign · The Register · SecurityWeek
  • Questel · CyberInsider · DeXpose · XposedOrNot
  • RingCentral · SecurityWeek · Have I Been Pwned
  • ReliaQuest · SecurityWeek
Tags
data breaches August 2026McKesson data breachShinyHuntersCarhartt data breachvishing attackBaxter International breachbiggest data breaches 2026CTEM

Stop chasing vulnerabilities Start reducing exposure

See how Strobes AI agents validate and fix your most critical exposures automatically.

Book a Demo
Continue Reading

Related Posts

Top data breaches July 2026
Data BreachesAI Security

Top 8 Data Breaches and Exposures of July 2026

The 8 confirmed data breaches of July 2026, from a 78-million-account Suno leak to rogue AI agents breaching Hugging Face and Anthropic. What happened and how to defend.

Aug 1, 202620 min
Top databreaches june 2026
Data BreachesSupply Chain Security

Top 8 Data Breaches and Exposures of June 2026

The 8 confirmed data breaches of June 2026, from a 24-billion-record credential dump to ShinyHunters' PeopleSoft and Klue OAuth campaigns. What happened and how to defend.

Jun 30, 202613 min
Top Databreaches of May 2026
Data BreachesSupply Chain Security

Top 8 Data Breaches of May 2026

The 8 confirmed data breaches of May 2026, from the 275M-record Canvas LMS breach to GitHub's VS Code supply chain attack, and how to defend against each pattern.

Jun 3, 202622 min