Summary

  • Total number of incidents disclosed: 30
  • Total number of confirmed breached records: over 17,300,000

Welcome to another monthly round-up of monthly cyber attack and data breach news. At least 30 publicly disclosed incidents came to light in August 2025 across the finance, healthcare, telecoms, government, retail, education and technology sectors.

Based on disclosures with usable figures, more than 17.3 million records were confirmed to have been breached this month. The actual figure is likely to be higher, given that several incidents did not release exact numbers but involved large datasets.

Top 5 incidents by number of records affected

Bouygues Telecom (France)

  • Records affected: 6.4 million
  • Data: Contact details, contract information, IBAN bank account numbers
  • Cause: Ransomware attack and data exfiltration by a criminal group
  • Status: Confirmed; systems secured; regulators and clients notified

Salesforce supply-chain campaign (multiple victims)

  • Records affected: At least 5.6 million confirmed (4.46m at TransUnion, 1.1m at Farmers Insurance, plus exposures at Google, Cisco, Pandora, Chanel, Workday and Air France–KLM)
  • Data: Business contact details and customer PII, including names, addresses, dates of birth, driver’s licence numbers and, in TransUnion’s case, unredacted Social Security numbers
  • Cause: OAuth token theft at Salesloft/Drift exploited by the ShinyHunters/Scattered Spider group to infiltrate Salesforce instances across multiple organisations
  • Status: Confirmed; victims disclosed incidents individually; investigation continues

DaVita Inc. (USA)

  • Records affected: 2.7 million
  • Data: Names, addresses, dates of birth, Social Security numbers, medical diagnoses and treatments, insurance details
  • Cause: Ransomware intrusion (March–April); attackers exfiltrated and encrypted data
  • Status: Confirmed; BlackCat/ALPHV suspected; disclosure on 22 August

Columbia University (USA)

  • Records affected: 868,969
  • Data: Social Security numbers, contact details, academic records, financial aid data, health insurance information
  • Cause: May 2025 hack of university systems by an unknown threat actor
  • Status: Confirmed; disclosure 7 August; credit monitoring offered

Orange Belgium

  • Records affected: 850,000
  • Data: Full names, telephone numbers, SIM card numbers, PUK codes, tariff plans
  • Cause: July network breach of telecom systems
  • Status: Confirmed; disclosure 20 August; regulator notified

Trends in August 2025

  • Salesforce supply-chain campaign dominates: The ShinyHunters/Scattered Spider-linked campaign against Salesforce environments hit major firms including Google, Cisco, Farmers Insurance, Pandora, Chanel, Workday and TransUnion.
  • Telecoms under pressure: Bouygues Telecom and Orange Belgium reported large breaches affecting millions of customers, following July’s Orange France incident.
  • Healthcare remains a prime target: DaVita (2.7 million patients) and Healthcare Services Group (624,000 individuals) underscore the persistent risk to health data.
  • Education and research exposed: Columbia University disclosed nearly 870k records; the Italian hotel ID leak showed how guest verification processes can be exploited.
  • Government services disrupted: The US Federal Judiciary, Canada’s House of Commons and Maryland’s MTA all reported serious cyber attacks impacting sensitive systems.

Key vulnerabilities exploited

  • OAuth/SaaS integrations: The Salesloft breach enabled attackers to pivot into multiple Salesforce environments (TransUnion, Farmers, Google Ads, etc.).
  • SharePoint zero-day: CVE-2025-53770 exploited in the Canada House of Commons breach and the Colt Technology Services attack.
  • Ransomware and exfiltration: Groups such as ALPHV/BlackCat (DaVita) and Qilin (Nissan Creative Box) used combined encryption and theft strategies.
  • Cloud misconfigurations and third-party risks: Pi-hole (donor emails exposed via WordPress plugin flaw) and Auchan (loyalty programme) highlight supply-chain weaknesses.
  • Hacktivism and geopolitics: Cyber Anarchy Squad (Russia) and Iranian-aligned groups (Israel’s Internet Rimon) demonstrated continuing hacktivist and state-backed activity.

List of data breaches and cyber attacks disclosed in August 2025

Disclosure dateOrganisationCountrySectorIncident typeRecords affected
01 August 2025Pi-hole ProjectGlobalSoftware (Ad-blocking)Data breach (exposed donor info via plugin vulnerability)30,000
01 August 2025Cycle & Carriage SingaporeSingaporeAutomotiveData breach (unauthorised CRM access, data exfiltration)147,000
01 August 2025Genoa Community HospitalUSAHealthcareData breach (email account compromise)Unknown
04 August 2025ChanelFranceRetail (Fashion)Data breach (Salesforce CRM compromise via vishing)Unknown
05 August 2025Cisco SystemsUSATechnologyData breach (vishing-led CRM account compromise)Unknown
05 August 2025Public Broadcasting Service (PBS)USAMediaData breach (internal data leak by insider)3,997
05 August 2025PandoraDenmarkRetailData breach (Salesforce CRM compromise via OAuth abuse)Unknown
05 August 2025Google (Ads CRM)USATechnologyData breach (Salesforce CRM compromise via vishing)Unknown
06 August 2025Air France–KLMFrance, NetherlandsAviationData breach (third-party customer service system hack)Unknown
07 August 2025Bouygues TelecomFranceTelecomCyber attack (ransomware – data theft)6,400,000
07 August 2025Columbia UniversityUSAEducationData breach (network hack, data theft)868,969
08 August 2025US Federal JudiciaryUSAGovernment (Judiciary)Cyber attack (breach of court document system)Unknown
10 August 2025Connex Credit UnionUSAFinancialData breach (unauthorized system access, data theft)172,000
12 August 2025Manpower (Lansing franchise)USAStaffing/HRData breach (ransomware attack – data theft)144,189
13 August 2025Multiple Italian HotelsItalyHospitalityData breach (booking system hacks, identity data theft)~90,000 (ID scans)
14 August 2025Canada House of CommonsCanadaGovernmentCyber attack (SharePoint 0-day exploit, data theft)Unknown
18 August 2025Workday, Inc.USATechnology (HR software)Data breach (third-party CRM compromise via social engineering)Unknown
18 August 2025Bragg Gaming GroupCanadaOnline GamingCyber attack (unauthorized access to IT systems)Unknown (internal data only)
19 August 2025Business Council of New York StateUSANon-profit (Business org)Data breach (network hack, data theft)47,329
20 August 2025Orange BelgiumBelgiumTelecomData breach (internal systems breach, data theft)850,000
20 August 2025Investment Projects (Russia)RussiaFinance (Investment platform)Cyber attack (hacktivist breach, data leak)Unknown
21 August 2025Colt Technology ServicesUKTelecomCyber attack (ransomware – data theft, service outage)Unknown (up to 1M documents)
22 August 2025DaVita Inc.USAHealthcareData breach (ransomware – patient data theft)2,700,000
24 August 2025Internet RimonIsraelTelecom (ISP)Cyber attack (nation-state hack, service disruption)Unknown (service disrupted)
25 August 2025Farmers InsuranceUSAInsuranceData breach (third-party CRM compromise – data theft)1,100,000
25 August 2025Auchan (retail)FranceRetailData breach (loyalty program database hack)“Several hundred thousand”
25 August 2025Nissan (Creative Box)JapanAutomotiveData breach (ransomware – IP theft)Unknown (4 TB of data)
25 August 2025Maryland Transit Admin-istrationUSATransport-ationCyber attack (IT outage – transit scheduling system)Unknown
26 August 2025Healthcare Services Group (HSG)USAHealthcare supportData breach (network intrusion, data theft)624,000
26 August 2025Salesloft, Inc.USACloud softwareSupply-chain attack (OAuth token theft enabling data breaches)Unknown
28 August 2025TransUnion LLCUSAFinancial (Credit bureau)Data breach (Salesforce supply-chain attack – data theft)4,461,511
28 August 2025MathWorksUSASoftware (Engineering)Data breach (ransomware – internal systems)10,476

Discover your vulnerabilities before attackers do

To avoid falling victim to cyber attacks, it’s critical to understand where you are most vulnerable to attack. Then you can close any security gaps before it’s too late.

Don’t leave your vulnerabilities to chance. Collaborate with a team that understands your risks and delivers actionable solutions.

Contact our penetration testing experts today to discuss your security needs.