The week in breach news

This week: Welcome to the next evolution of The week in breach. In this week’s edition you’ll discover another airline hit by Scattered Spider, a controversial healthcare breach in Ontario and a data breach at FC Barcelona.

The week in breach news

North America

Hawaiian Airlines

Industry: Transportation & LogisticsExploit: Hacking

Hawaiian Airlines disclosed a cybersecurity incident that impacted some IT systems. The breach, discovered on June 23 and reported in a June 27 SEC filing, prompted immediate security measures. The company was quick to reassure passengers that flights were not delayed.

The hacker group Scattered Spider is suspected to be the perpetrator. The gang is also suspected to be behind recent hits on WestJet and Delta.

Source

How it could affect your business

Threat actors often target multiple organizations within the same industry in rapid succession.

North America

Aflac

Industry: InsuranceExploit: Hacking

Aflac has confirmed a data breach likely carried out by the cybercrime group Scattered Spider.

The breach exposed sensitive information, including names, claims and health data, Social Security numbers and other personal details tied to customers, employees, agents and beneficiaries within its U.S. operations.

The attack is part of a broader campaign targeting major insurers, with Erie Insurance Group and Philadelphia Insurance Companies also hit in recent weeks.

Source

How it could affect your business

A pattern of attacks in a particular industry could indicate an elevated level of danger for other businesses in that sector.

North America

Transamerica Retirement Services

Industry: FinanceExploit: Phishing

Transamerica Retirement Services alerted approximately 1,300 individuals to a potential data breach after discovering unauthorized access to an internal cloud-based application used for client management. The breach stemmed from a phishing attack in which an unknown actor posed as a Transamerica employee to gain access through the company’s call center.

The suspicious activity was first flagged on May 7, 2025, but the breach was not fully discovered until June 10. Affected clients were notified beginning June 26. The company has not yet disclosed what specific data may have been exposed.

Source

How it could affect your business

Organizations must invest in stronger authentication processes, employee training and real-time monitoring to detect and stop unauthorized access.

Europe

Radix

Industry: Nonprofit & Social ImpactExploit: Ransomware & Malware

Radix, a Zurich-based nonprofit health foundation, confirmed it was the target of a ransomware attack on June 16, resulting in 1.3TB of data leaking into the dark web. The Sarcoma ransomware group claimed responsibility, publishing the stolen archive on its data leak site.

The breach includes data linked to various undisclosed Swiss federal offices, although Radix says there is currently no indication that sensitive information from its partner organizations was compromised. The number of individuals affected remains unclear as investigations continue.

Source

How it could affect your business

Organizations that handle sensitive data tied to government entities must implement enterprise-grade cybersecurity measures.

North America

Ontario Health atHome

Industry: Aerospace & DefenseExploit: Business Email Compromise

Ontario’s privacy commissioner and Ontario Health are investigating a controversial data breach involving Ontario Health atHome. An estimated 200,000 former patients may have had their medical data exposed. The Ontario Liberal Party revealed the breach in a news release Friday, alleging that sensitive information was compromised in this incident dating back to March 17, 2025. However, the breach was not publicly disclosed until now.

The breach, initially described as a “system outage” by vendor Ontario Medical Supply, occurred in mid-March. An investigation later confirmed it was a cybersecurity attack. Exposed data may include names, contact details and medical supply information.

Source

How it could affect your business

Organizations must ensure vendors and service providers uphold strong cybersecurity, quick breach detection, clear communication and solid data protection.

Europe

Glasgow City Council

Industry: Government & Public SectorExploit: Third-Party Data Breach

Glasgow City Council is responding to a cybersecurity breach detected on June 19 that disrupted multiple online services, including planning applications, parking payments, school absence reporting and vital records ordering. Access to Strathclyde Pension Fund accounts was also suspended.

While there’s no evidence of compromised financial or payment data, the council alerted the Information Commissioner’s Office over possible personal data theft. Investigations are ongoing.

Source

How it could affect your business

It is critical that companies vet the IT practices of third-party vendors, a potential trouble spot that could lead to a pricey cyberattack or data breach.

Like what you're reading?

Subscribe now to get security news and information in your inbox every week

Upcoming Webinars

Join other IT professionals to connect, learn and level up. Get insights into the latest cybersecurity trends and technologies.

Autotask quarterly product innovation update

Autotask quarterly product innovation update

Read more
Autotask Tech Jam: Master the Accounting Hub for QuickBooks Online

Autotask Tech Jam: Master the Accounting Hub for QuickBooks Online

Read more
Compliance as a Service: The MSP revenue stream clients can't opt out of

Compliance as a Service: The MSP revenue stream clients can't opt out of

Read more