The week in breach news

This week: LVMH experiences a third data breach, this time at its Louis Vuitton U.K. division; bad passwords empower hackers to hit Foodstuffs in New Zealand; and 800,000 gamblers have their personal data exposed.

The week in breach news

North America

Bitcoin Depot

Industry: FinanceExploit: Hacking

Bitcoin Depot, a major U.S. bitcoin ATM operator, is notifying customers of a data breach that exposed personal information collected during cryptocurrency transactions. Exposed data may include names, phone numbers, driver's license numbers, home addresses, birthdates and email addresses, depending on the individual.

The company detected suspicious activity on June 23, 2023, and completed its internal investigation on July 18, 2024. However, an ongoing police investigation prevented it from notifying customers until July 2025.

Source

How it could affect your business

Organizations must prioritize swift internal investigations and transparent communication to avoid the erosion of customer trust.

North America

The Texas Department of Transportation

Industry: Government & Public SectorExploit: Hacking

The Texas Department of Transportation (TxDOT) confirmed a data breach on May 12, 2025, affecting nearly 300,000 crash report records after a hacker gained access through a single personal TxDOT account.

Exposed information includes names, addresses, driver's license and license plate numbers, insurance policy details and other crash-related data. The agency began notifying affected individuals by mail on July 9 and set up a dedicated hotline for those impacted.

Source

How it could affect your business

Even a single compromised account can lead to large-scale data exposure, underscoring the need for strong access controls and continuous monitoring.

North America

Flutter Entertainment

Industry: Media, Sports & EntertainmentExploit: Third-Party Data Breach

Flutter Entertainment, owner of gambling brands including Betfair and Paddy Power, disclosed a data breach affecting up to 800,000 of its 4.2 million average monthly players across its U.K. and Ireland brands. The company pointed to a breach at an unnamed service provider as the source of the incident.

Exposed data may include customers' IP addresses, email addresses and limited betting account information. Flutter says it has contained the incident and is working with cybersecurity experts to strengthen its defenses.

Source

How it could affect your business

This incident underscores the growing cybersecurity challenges large corporations face, particularly those in the online gambling sector.

North America

Rockerbox

Industry: FinanceExploit: Misconfiguration

Cybersecurity researchers discovered an unsecured archive traced to Rockerbox, a Texas-based consultancy specializing in tax credits. The exposed trove contained 287 GB of data and nearly 246,000 records, since secured.

Compromised records include names, addresses, emails, dates of birth, Social Security numbers, driver's license/ID numbers and employment and salary information tied to Work Opportunity Tax Credit documents, along with sensitive files such as DD214 military discharge forms.

Source

How it could affect your business

Careless database setup by technicians can have disastrous results for companies.

Europe

LVMH (Louis Vuitton UK)

Industry: RetailExploit: Hacking

LVMH is in the spotlight for another cyberattack this week, this time on its Louis Vuitton UK operations. The retailer disclosed that this incident exposed customer names, contact details and purchase history. The brand was quick to reassure customers that no financial data was compromised.

The breach, which occurred on July 2, marks the third LVMH-related cyber incident in three months, following similar attacks on Louis Vuitton’s Korean arm last week and Christian Dior Couture.

Source

How it could affect your business

Experiencing multiple data breaches in a short period of time can negatively impact consumers' trust in a brand.

Asia & Pacific

Nippon Steel Solutions

Industry: ManufacturingExploit: Zero-day vulnerability

Nippon Steel Solutions, a subsidiary of Nippon Steel, detected unauthorized activity on several servers. An investigation found that hackers exploited a zero-day flaw in the company's network equipment to access sensitive customer, partner and employee information.

Exposed customer data may include names, company affiliations, job titles, business email addresses, phone numbers and addresses; exposed partner data includes names and business emails. This follows a February 2025 attack on Nippon Steel USA by the BianLian ransomware group.

Source

How it could affect your business

Multiple cyberattacks on a company in a short period of time may cause potential partners to think twice before doing business with that company.

Australia & New Zealand

Foodstuffs Ltd.

Industry: RetailExploit: Hacking

New Zealand grocery retailer Foodstuffs Ltd. detected attempts by scammers to access a limited number of its New World Clubcard accounts using automated password-guessing tools. The company says its systems remain secure and no payment card data was compromised.

As a precaution, Foodstuffs temporarily disabled the New World dollars redemption feature and removed stored payment tokens from affected accounts, and is asking impacted users to reset passwords with stronger passphrases.

Source

How it could affect your business

Bad actors are increasingly turning to automated tools to make attacks faster and more effective.

Like what you're reading?

Subscribe now to get security news and information in your inbox every week

Upcoming Webinars

Join other IT professionals to connect, learn and level up. Get insights into the latest cybersecurity trends and technologies.

Datto RMM quarterly product innovation update

Datto RMM quarterly product innovation update

View event
NIS2: van compliance-verplichting naar omzetkans voor MSP’s

NIS2: van compliance-verplichting naar omzetkans voor MSP’s

View event
The New Playbook for MSP Growth: Websites, SEO, AI, and Automation That Actually Convert

The New Playbook for MSP Growth: Websites, SEO, AI, and Automation That Actually Convert

View event