The week in breach news

Some of the biggest names in health care, energy and technology found themselves on this week’s list of cyberattack victims, exposing the sensitive data of millions. The May 2026 ransomware attack on DentaQuest has now been confirmed as the largest health care data breach reported this year, while a breach at Sydney-based Origin Energy may have compromised the information of nearly 900,000 customers. Meanwhile, hackers continued to target critical infrastructure, including water utilities across multiple U.S. states, and semiconductor giant Analog Devices faced two separate cybersecurity incidents in quick succession.

United States

DentaQuest

Industry: Health care Exploit: Ransomware & Malware

The May 2026 ransomware attack on DentaQuest, one of the largest dental and vision benefits administrators in the U.S., has now been confirmed to have affected 15 million individuals.

The incident first came to light on May 20, and DentaQuest’s investigation determined that attackers had access to the organization’s network between May 17 and May 20. The victim count, now published on the Oregon Attorney General’s data breach reporting website, is almost six times higher than the number initially claimed by the ShinyHunters extortion gang. In May, the group published 234 GB of DentaQuest data on its dark web leak site, claiming it related to 2.6 million individuals.

The incident now ranks as the largest health care data breach reported so far in 2026 and the fourth largest among nearly 7,900 HIPAA data breaches reported since federal regulators began tracking such incidents in September 2009.

Source

How it could affect your business

DentaQuest is one of a growing number of organizations across multiple sectors that have fallen victim to data theft attacks linked to the ShinyHunters gang, highlighting the increasing scale and persistence of modern ransomware and extortion campaigns. Organizations should strengthen their defenses through proactive threat monitoring, layered security controls and rapid incident detection, while maintaining ransomware-resilient backups and a robust business continuity and disaster recovery (BCDR) strategy to enable fast recovery and minimize operational disruption following an attack.

Australia & New Zealand

Origin Energy

Industry: Energy & Natural Resources Exploit: Hacking

Sydney-based energy provider Origin Energy believes the information of approximately 0.9 million current and former customers was accessed during a recent data security breach.

Origin Energy, one of Australia’s largest energy providers, supplies electricity, fossil gas, LPG and internet services to more than 4.8 million homes and businesses. The company said it first became aware of a potential security threat in early July but initially did not believe it was credible. After an initial review, Origin now estimates that a significant proportion of the approximately 900,000 affected individuals are former customers and says those impacted will be notified in the coming days.

According to Origin, the compromised information may include customers’ names, addresses, dates of birth, phone numbers and account information, as well as the last four digits of credit cards or the last three digits of bank account numbers.

Source

How it could affect your business

A data exposure of this scale could fuel widespread spear-phishing campaigns, with attackers using stolen personal information to craft highly convincing emails, text messages and phone scams. Individuals should remain cautious of unsolicited communications requesting personal or financial information, avoid clicking on unexpected links or attachments and verify the authenticity of any requests before taking action.

United States

U.S. water utilities

Industry: Government & Public Sector Exploit: Hacking

The Federal Bureau of Investigation (FBI) and the Environmental Protection Agency (EPA) have warned that hackers are breaking into internet-connected programmable logic controllers (PLCs) at water utilities, disrupting operations across multiple facilities in several U.S. states.

Without disclosing the full scope of the attacks or identifying all affected states, the FBI and EPA said in a joint statement that multiple incidents had occurred. According to the agencies, attackers remotely accessed internet-connected control systems, changed administrator passwords and caused operational disruptions, including flooding and pressure loss, which could allow untreated groundwater to seep into water pipes. Meanwhile, Minnesota and Michigan have confirmed attacks on several of their water facilities.

The warning comes just days after federal agencies updated an advisory on ongoing Iranian cyberthreats targeting U.S. critical infrastructure. However, investigators have not publicly linked the latest attacks on water utilities to Iran.

Source

How it could affect your business

Cyberattacks on U.S. critical infrastructure have increased significantly in recent years, with water utilities, energy providers and other essential services becoming frequent targets. Organizations that work with government agencies or operate critical infrastructure should strengthen their cyber defenses through continuous monitoring, network segmentation, strong identity and access controls, timely patch management, secure remote access and regularly tested incident response and business continuity plans to improve resilience against evolving threats.

North America

Analog Devices

Industry: Technology Exploit: Hacking

Semiconductor company Analog Devices disclosed a data breach that it detected in June after identifying unauthorized access to certain systems.

The Massachusetts-based chip manufacturer said in a filing with the U.S. Securities and Exchange Commission (SEC) that it detected the incident on June 23 and immediately activated its incident response process. An investigation conducted with the assistance of external cybersecurity experts determined that certain files had been exfiltrated, although the full scope of the breach remains under review. The company said the incident did not disrupt operations and that it is not aware of the stolen files being leaked or misused.

Meanwhile, the filing also referenced a separate cybersecurity incident unrelated to the June intrusion. Although Analog Devices did not provide additional details, reports suggest it may be linked to claims by the ExfilSquad ransomware group that it had stolen more than 570,000 records relating to Analog Devices customers.

Source

How it could affect your business

Organizations should remember that a single cyberattack is not always the end of the story. Even if a ransom is paid or an incident is contained, attackers may return to exploit the same weaknesses, or another threat actor may compromise the network through a different vulnerability. The most effective defense is to continuously strengthen your cybersecurity posture through proactive monitoring, timely patching, strong access controls, layered security and regularly tested incident response and recovery plans.

North America

Omnicell

Industry: Health care Exploit: Ransomware & Malware

Several dark web monitoring sites are reporting that California-based health care technology company Omnicell has been named as the recent victim of a data breach.

According to posts by the Everest ransomware group, the attackers stole 1 TB of data from Omnicell, a provider of medication management and pharmacy automation systems used by health care organizations worldwide. The group claims the stolen archive includes source code, SQL databases, credentials, firmware, deployment packages and other sensitive assets. However, neither Omnicell nor independent cybersecurity researchers have confirmed the alleged breach, and no public proof of the stolen data has been released.

If the claims prove to be accurate, this will mark the second major cybersecurity incident affecting Omnicell in recent years. In 2022, the company suffered a ransomware attack that disrupted some of its products, services and internal systems.

Source

How it could affect your business

Few users understand the step-by-step process behind how ransomware attacks unfold, even though phishing remains one of the most common entry points for these attacks. Educating employees on how ransomware campaigns work can significantly reduce organizational risk. Our Understanding phishing guide explains how ransomware attacks progress and the critical role phishing plays in enabling them, helping organizations strengthen user awareness and prevent ransomware from causing widespread operational damage.

Like what you're reading?

Subscribe now to get security news and information in your inbox every week

Upcoming webinars & events

Join our upcoming events and webinars for expert insights, practical strategies and the latest cybersecurity trends.

INKY Tech Jam: From flagged to fixed – mastering email analysis & threat response

August 20, 2026 11:00 AM EDT

Learn how to investigate, analyze and resolve suspicious emails with confidence in this INKY Tech Jam. Discover how to use the Observations page, understand mail flow architecture and manage quarantine effectively to diagnose issues faster and strengthen email security for your clients or corporate users.

Register Now

Kaseya Security quarterly product innovation update

August 25, 2026 11:00 AM EDT

Discover the latest innovations across Kaseya’s integrated security portfolio in this exclusive quarterly product update. Learn how new AI-powered capabilities, deeper platform integrations and enhanced detection, response, visibility and protection features are helping MSPs and corporate IT teams strengthen security while reducing operational complexity.

Register Now