The week in breach news

This week: Years-old leaked credentials and missing multifactor authentication led to a data breach across more than 50 multinational companies. Other incidents include a phishing attack on CIRO exposing data tied to more than 750,000 individuals and a cyberattack on Central Maine Healthcare compromising information from more than 145,000 patients.

The week in breach news

North America

Canadian Investment Regulatory Organization (CIRO)

Industry: Finance Exploit: Phishing

Canada's national self-regulatory body, CIRO, revealed that hackers compromised the personal information of approximately 750,000 individuals in an August 2025 cyberattack.

Following a detailed forensic investigation, CIRO confirmed the full scope of the incident, which it first detected on August 11 and disclosed on August 18 last year. The attack, stemming from a phishing campaign, impacted its member firms and their registered employees. Exposed data includes annual income, dates of birth, government-issued ID numbers, phone numbers, investment account numbers, Social Insurance numbers and account statements. CIRO noted that since it does not store passwords, PINs or security questions, none of those were affected.

At this time, CIRO says it has no evidence that the compromised information has been misused or surfaced on the dark web, but the organization will continue to monitor for signs of abuse.

Source

How it could affect your business

Phishing campaigns are becoming more convincing as attackers increasingly use AI to craft realistic messages. Organizations should combine user awareness training with stronger email security, multifactor authentication and continuous monitoring for suspicious activity.

North America

Multiple MNCs

Industry: Technology Exploit: Hacking

A cybercriminal compromised more than 50 multinational companies without any advanced exploit, exposing sensitive corporate and customer data across multiple industries.

A threat actor known as Zestix (also tracked as Sentap) stole and listed the data from dozens of global enterprises for sale on the dark web. The breach required no sophisticated exploitation techniques — the attacker relied entirely on valid credentials sourced from infostealer malware logs. Affected organizations span multiple sectors, including Iberia Airlines, Burris & Macomber, Maida Health, Intecro Robotics and Pickett & Associates. Without multifactor authentication in place, the attacker logged in directly to corporate file-sharing portals to exfiltrate data.

The stolen credentials were traced to several infostealer variants, including RedLine, Lumma and Vidar. In some cases, the credentials had been exposed for years before being weaponized.

Source

How it could affect your business

Infostealer malware quietly collects login credentials that attackers can exploit months or years later. Organizations should use dark web monitoring to spot exposed credentials early and enforce multifactor authentication to prevent stolen logins from being abused.

North America

Central Maine Healthcare

Industry: Healthcare Exploit: Hacking

Central Maine Healthcare confirmed that a data breach it experienced last year compromised the personal, treatment and health insurance information of more than 145,000 patients.

The health care provider detected unusual activity within its IT network on June 1, 2025. Further investigation revealed that an unauthorized party had gained access to its environment as early as March 19, 2025. Exposed data includes names, dates of birth, Social Security numbers, treatment details, provider names, dates of service and health insurance information, impacting 145,381 patients.

The organization stated it has enhanced its monitoring and alerting capabilities to help prevent similar incidents and advised affected individuals to review statements from healthcare providers and insurance plans.

Source

How it could affect your business

Attackers can remain undetected inside networks for months, quietly collecting sensitive data. Continuous threat monitoring and timely alerting are critical to spot suspicious activity early and limit impact before data is exposed.

Europe

AZ Monica

Industry: Healthcare Exploit: Hacking

A Belgian general hospital network, AZ Monica, was forced to shut down all servers, cancel scheduled procedures and transfer critical patients after a cyberattack disrupted its operations.

On January 13, the hospital network experienced a serious IT outage and proactively shut down all servers across its campuses in Deurne and Antwerp. AZ Monica confirmed it launched an investigation and notified police and prosecutors, though it has not shared other details about the intrusion.

While some reports mentioned possible ransom demands, hospital officials and authorities have not yet confirmed whether ransomware was involved.

Source

How it could affect your business

Breaches in healthcare do not just compromise sensitive information but also affect patient safety by forcing hospitals to cancel procedures and divert critical patients. Healthcare providers need rapid threat detection and continuous monitoring to spot intrusions early.

Asia & Pacific

Kyowon

Industry: Education Exploit: Ransomware & Malware

South Korean conglomerate Kyowon confirmed a ransomware attack that disrupted its operations and may have exposed customer data.

Kyowon Group, which operates across education, publishing, media and technology, detected abnormal activity in its network on January 10, 2025. The company immediately activated its incident response plan and isolated affected servers to stop the attack from spreading. Signs suggest data may have leaked, though the full impact on customer information is still under investigation.

According to reports, attackers gained access through an externally exposed server connected to the internet, then moved into Kyowon's internal systems, allowing ransomware to spread across multiple subsidiaries.

Source

How it could affect your business

Defending against ransomware is a race against time. Proactive monitoring is critical for detecting suspicious activity early, and encrypted, ransomware-resilient backups allow businesses to restore data without paying a ransom.

Like what you're reading?

Subscribe now to get security news and information in your inbox every week

Upcoming Webinars

Join other IT professionals to connect, learn and level up. Get insights into the latest cybersecurity trends and technologies.

Autotask quarterly product innovation update

Autotask quarterly product innovation update

Read more
Autotask Tech Jam: Master the Accounting Hub for QuickBooks Online

Autotask Tech Jam: Master the Accounting Hub for QuickBooks Online

Read more
Compliance as a Service: The MSP revenue stream clients can't opt out of

Compliance as a Service: The MSP revenue stream clients can't opt out of

Read more