Strobesstrobes
Platform
Solutions
Resources
Customers
Company
Pricing
Book a Demo
Strobesstrobes

Strobes connects every exposure signal to autonomous action, so security teams fix what matters, prove what works, and stop chasing noise.

Book a DemoTalk to an expert
ISO 27001SOC 2CREST
  • Platform
  • Platform Overview
  • Agentic Exposure Management
  • AI Agents
  • Integrations
  • API & Developers
  • Workflows & Automation
  • Analytics & Reporting
  • Solutions
  • Exposure Assessment (EAP)
  • Attack Surface Management
  • Application Security Posture
  • Risk-Based Vulnerability Management
  • Adversarial Exposure Validation (AEV)
  • AI Pentesting
  • Pentesting as a Service
  • CTEM Framework
  • By Industry
  • Financial Institutions
  • Technology
  • Retail
  • Healthcare
  • Manufacturing
  • By Roles
  • CISOs
  • Security Directors
  • Cloud Security Leaders
  • App Sec Leaders
  • Resources
  • Blog
  • Customer Stories
  • eBooks
  • Datasheets
  • Videos & Demos
  • Exposure Management Academy
  • CTEM Maturity Assessment
  • Pentest Health Check
  • Security Tool ROI Calculator
  • Company
  • About Strobes
  • Meet the Team
  • Trust & Security
  • Contact Us
  • Careers
  • Become a Partner
  • Technology Partner
  • Partner Deal Registration
  • Press Release

Weekly insight for security leaders

CTEM research, agentic AI trends, and what's actually moving the needle.

© 2026 Strobes Security Inc. All rights reserved.

Privacy PolicyTerms of ServiceCookie PolicyAccessibilitySitemap
Back to Blog
Top Data Breaches in April 2025 That Made The Headlines
Data Breaches

Top Data Breaches in April 2025 That Made The Headlines

Shubham JhaApril 30, 20256 min read

Table of Contents

  • Major Data Breaches in April 2025
    • Yale New Haven Health System Breach
    • Blue Shield of California Breach
    • VeriSource Services Breach
    • Hertz Corporation Breach
    • Alternate Solutions Health Network Breach
    • PJM Interconnection Breach
    • WK Kellogg Co Breach
  • Trusted by leading enterprises like, GHX, Zoho, Darwinbox, Tricenties, and SHL
  • Trends and Observations
  • Conclusion
  • Citations

Authors

S
Shubham Jha

Share

Table of Contents

  • Major Data Breaches in April 2025
    • Yale New Haven Health System Breach
    • Blue Shield of California Breach
    • VeriSource Services Breach
    • Hertz Corporation Breach
    • Alternate Solutions Health Network Breach
    • PJM Interconnection Breach
    • WK Kellogg Co Breach
  • Trusted by leading enterprises like, GHX, Zoho, Darwinbox, Tricenties, and SHL
  • Trends and Observations
  • Conclusion
  • Citations

Authors

S
Shubham Jha

Share

As April 2025 drew to a close, it left a string of high-profile data breaches in its wake, rattling major organizations. Yale New Haven Health saw 5.5 million patient records exposed, and Hertz dealt with a breach impacting over a million customers. Attackers exploited vulnerabilities in emails, system setups, and third-party vendors, threatening personal data and critical services. This blog takes a hard look at the major April data breaches of 2025, breaking down their impact and the challenges they pose for securing sensitive information.

Data Breaches April 2025Major Data Breaches in April 2025

Yale New Haven Health System Breach

  • Detected on March 8, 2025, and disclosed on April 11, 2025, this breach affected 5.5 million individuals. Compromised data included names, dates of birth, addresses, phone numbers, email addresses, race/ethnicity, Social Security numbers, and medical record numbers. The electronic medical record system, financial accounts, payment information, and employee HR data were not accessed. Likely a ransomware attack, hackers copied data on the discovery day, but patient care was unaffected.
  • The largest breach of April 2025 by affected individuals, it highlights healthcare’s vulnerability to cyberattacks, with exposed data increasing risks of identity theft and medical fraud. Notifications began on April 14, with credit monitoring offered for those with exposed Social Security numbers.

Blue Shield of California Breach

  • Reported on April 9, 2025, this breach affected 4.7 million individuals due to a Google Analytics misconfiguration on company websites, active from April 2021 to January 2024. Data shared with Google Ads included names, family size, insurance plan details, city, zip code, account identifiers, medical claims, patient financial responsibility, and doctor search information. Discovered on February 11, 2025, the Google Ads connection was severed in January 2024.
  • The second-largest breach, it underscores risks of third-party vendor integrations in healthcare, raising significant privacy and regulatory compliance concerns. Notifications were sent to affected members.

VeriSource Services Breach

  • Disclosed on April 28, 2025, this breach affected 4 million individuals, primarily employees and dependents of client companies. The cyberattack occurred in February 2024, with unusual activity detected on February 28, 2024. Compromised data included names, addresses, dates of birth, gender, and Social Security numbers, varying by individual. The investigation concluded on April 17, 2025, with notifications starting April 23, 2025. Initial estimates in 2024 suggested 112,000 affected, but the scope expanded significantly.
  • A major breach in the HR outsourcing sector, it exposed sensitive employee data, increasing risks of identity theft. VeriSource offers 12 months of free credit monitoring and identity protection. No evidence of data misuse has been reported, and no ransomware group has claimed responsibility.

Hertz Corporation Breach

  • Disclosed on April 14, 2025, this breach affected 1,000,175 individuals across Hertz, Dollar, and Thrifty brands. Confirmed on February 10, 2025, it stemmed from zero-day vulnerabilities in Cleo’s file transfer platform exploited by the Clop ransomware gang in October and December 2024. Compromised data included names, contact information, dates of birth, credit card details, driver’s licenses, and workers’ compensation claims. A small subset had Social Security numbers, government IDs, passports, or injury-related data exposed. Hertz’s network was not directly impacted.
  • A significant breach due to its scale and sensitive data exposed, it heightens risks of fraud and identity theft. Hertz is offering two years of free identity protection through Kroll and reported the incident to law enforcement. The Clop gang’s involvement underscores third-party vendor risks.

Alternate Solutions Health Network Breach

  • Reported on April 14, 2025, this breach affected 93,589 individuals. Unauthorized access to an email account, discovered on February 14, 2025, exposed names, dates of birth, addresses, driver’s license numbers, physician/clinician names, clinical information, diagnostics, treatment details, and limited Social Security numbers. Notifications began on April 14, 2025.
  • A smaller but significant healthcare breach, it increases risks of identity theft and medical fraud. The email account was secured, and an investigation was launched, highlighting the need for robust email security in healthcare.

PJM Interconnection Breach

  • In April 2025, threat actor l33tfg claimed to have breached PJM Interconnection LLC, affecting over 4,000 customer database entries. Leaked data included names, email addresses, and phone numbers, critical for North America’s largest electric transmission system.
  • Though smaller, the breach’s target, critical infrastructure, raises energy security concerns. Specific response measures are unclear, but investigations and notifications are likely underway.

WK Kellogg Co Breach

  • Disclosed on April 4, 2025, this breach involved employee and vendor data stolen via Cleo’s file transfer platform, exploited by the Clop ransomware gang on December 7, 2024. Discovered on February 27, 2025, it affected an unknown number of individuals, with at least one Maine employee’s name and Social Security number confirmed compromised. WK Kellogg used Cleo for HR file transfers.
  • The breach’s scope remains unclear, but exposed HR data poses identity theft risks. WK Kellogg offers one year of free identity theft protection through Kroll. The incident, linked to Clop’s broader Cleo attacks, emphasizes third-party vendor vulnerabilities.

Trusted by leading enterprises like, GHX, Zoho, Darwinbox, Tricenties, and SHL

Strobes helped organizations continuously manage threats, reduce vulnerabilities, and stay compliant, powered by AI-driven security expertise.

Schedule a Free Strategy Call Explore Solutions

Trends and Observations

  • Healthcare Dominance: Yale, Blue Shield, and Alternate Solutions highlight healthcare’s ongoing cybersecurity challenges, with ransomware and mis-configurations as key threats.
  • Third-Party Risks: Hertz, WK Kellogg, and VeriSource breaches underscore vulnerabilities in third-party vendors like Cleo, emphasizing the need for robust vendor security.
  • Critical Infrastructure: The PJM breach signals growing threats to essential services, necessitating enhanced protections.
  • Data Sensitivity: Exposed data, including PHI and PII, increases risks of identity theft, fraud, and privacy violations across all breaches.

Conclusion

April 2025 revealed critical data security weaknesses, with breaches impacting healthcare, car rentals, and food industries. Yale New Haven Health’s 5.5 million affected patients and Hertz’s over one million compromised records highlight the risks to personal data. From email hacks to third-party vendor issues, these incidents threaten identity theft and service disruptions. Companies must prioritize proactive measures like risk-based vulnerability management and regular penetration testing to strengthen defenses, secure partnerships, and protect customers in a data-driven world.

Citations

  • Yale New Haven Health Data Breach
  • Blue Shield California Health Data Leak
  • VeriSource Data Breach
  • Hertz Data Breach
  • WK Kellogg Data Breach
  • PJM Interconnection Breach
  • Alternate Solutions Health Network Breach
Tags
data breachesData Breaches in April 2025

Stop chasing vulnerabilities Start reducing exposure

See how Strobes AI agents validate and fix your most critical exposures automatically.

Book a Demo
Continue Reading

Related Posts

Top 10 Data Breaches of April 2026 - Monthly Security Briefing
Data BreachesCybersecurity

Top 10 Data Breaches of April 2026

The biggest data breaches of April 2026 ranked and analyzed, from Checkmarx supply chain poisoning to Salesforce misconfigurations and ransomware hitting two major US banks.

May 1, 202615 min
Vercel security breach 2026 featured image
Data BreachesCybersecurity

The Vercel Hack: How One AI Tool Compromised the Infrastructure Behind Millions of Websites

Vercel's April 2026 security breach started with one AI tool's OAuth approval. Here is the full attack chain, blast radius, and what every security team must do now.

Apr 20, 202613 min
The Worst Data Breaches of March 2026 featured image
Data Breaches

The Worst Data Breaches of March 2026

Nine confirmed data breaches across the US and Europe in March 2026, from a 200,000-device wipe at Stryker to 15.8 million patient records stolen at Cegedim Sante. Here is what happened, breach by breach, and what the pattern tells defenders.

Apr 2, 20269 min