Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AITexas Hearing Institute Ransomware Attack Affects 30,000 Patients
Texas Hearing Institute suffered a ransomware attack by the Interlock group affecting 29,744 patients, with 540 GB of data stolen including SSNs, diagnosis information, and financial data. Two additional healthcare breaches were reported: Family Partnerships of Central Florida (8,151 affected by MoneyMessage threat group) and SportsMed Physical Therapy in New Jersey (3,400 affected via email compr
AIAesto Health Data Security Incident Affects Multiple Healthcare Provider Clients
Aesto Health, a Birmingham-based healthcare technology provider specializing in data migration and EHR exchanges, experienced a data breach affecting its AWS infrastructure between December 2-18, 2025, compromising sensitive patient information including SSNs, medical records, and financial data. The incident impacted over two dozen healthcare provider clients and hundreds of thousands of patients
AIZOLL Medical Pays $3.5 Million to Settle Data Breach Lawsuit
ZOLL Medical Corporation has agreed to a $3.5 million settlement following a January 2023 data breach that exposed personal and health information of over 1 million individuals, primarily LifeVest wearable defibrillator patients. The settlement, which received preliminary court approval, consolidates 15 class action lawsuits alleging HIPAA violations, negligence, and failure to implement adequate
AIData Breaches Announced by Five HIPAA-Regulated Entities
Five HIPAA-regulated entities across the United States have disclosed data breaches affecting over 86,000 individuals combined, with incidents ranging from network intrusions to email account compromises. The breaches exposed sensitive patient and employee information including Social Security numbers, medical records, financial data, and health insurance details. All affected organizations are of
AIOnePoint Patient Care and Clay-Platte Family Medicine Settle Data Breach Lawsuits
OnePoint Patient Care and Clay-Platte Family Medicine have reached settlements totaling $3.115 million to resolve class action lawsuits stemming from 2024 data breaches affecting over 1.7 million individuals. The lawsuits alleged negligence in implementing adequate cybersecurity measures, with hackers gaining unauthorized access to protected health information including Social Security numbers and
AILong-running Data Theft Campaign Targeting Salesforce, ServiceNow
A sophisticated data theft campaign dubbed 'City-Forum' has been actively targeting enterprise cloud platforms Salesforce and ServiceNow since at least March 2025. The campaign employs custom-built tooling to compromise organizations across multiple industry sectors, representing a significant threat to enterprise SaaS environments.
AIData Breaches Announced by Five Small Healthcare Organizations
Five small healthcare organizations have disclosed data breaches affecting patient information, with incidents ranging from ransomware attacks to email account compromises occurring between October 2025 and May 2026. The breaches exposed sensitive patient data including names, Social Security numbers, medical records, and health insurance information, with threat actors Genesis ransomware group an
Data Breaches Reported by Sunshine Health; Health Payment Systems
Two healthcare-related organizations have reported significant data breaches affecting thousands of individuals. Sunshine Health, a Florida Medicaid insurer, fell victim to a vishing attack compromising 41,569 individuals' protected health information, while Health Payment Systems, a Wisconsin billing company, experienced an email security incident affecting 9,380 patients with unauthorized access
Data Breaches Announced by Loma Linda University Health & UCLA Health
Two major California healthcare systems have disclosed separate data breach incidents affecting patient information. Loma Linda University Health experienced a breach when patient data from a research study was inadvertently uploaded to an external AI platform, while UCLA Health reported improper disclosure of patient information to an outside healthcare provider over a 16-month period. Both organ
California Child Care Company Discovers 9-Year Employee Data Leak
Child Care Resource Center, a California non-profit, disclosed a nine-year data breach involving an employee forwarding internal files containing personal data to an external email account from October 2016 to October 2025. While the practice was intended to facilitate work duties rather than data theft, the organization lost control of sensitive information and cannot rule out unauthorized access
AICanadian Man Pleads Guilty in Snowflake Extortions
Connor Riley Moucka, a 26-year-old Canadian cybercriminal, has pleaded guilty to orchestrating a massive data breach campaign targeting over 165 Snowflake cloud storage customers, including AT&T, TicketMaster, and other major enterprises. The attacks exploited accounts lacking multi-factor authentication, resulting in the theft of billions of sensitive customer records and over $2.5 million in ran
Settlements Resolve Data Breach Lawsuits Against McKenzie Health System & Aspire Health Alliance
Two healthcare organizations, McKenzie Health System in Michigan and Aspire Health Alliance in Massachusetts, have reached settlements to resolve class action lawsuits stemming from data breaches in 2025 and 2023 respectively. McKenzie Health's breach affected 58,839 individuals and offers two years of credit monitoring plus up to $4,000 in reimbursement or $50 cash payments, while Aspire Health A
AISnowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People
Connor Riley Moucka, a 26-year-old Canadian, pleaded guilty to multiple federal charges including computer fraud and wire fraud related to the 2024 Snowflake customer account breaches. The attacks compromised at least 165 organizations and exposed personal data of over 100 million individuals, with Moucka personally profiting at least $495,000 from the scheme.
Data Breach Lawsuits Settled by Omni Healthcare & Western Montana Clinic
Two healthcare organizations, Omni Healthcare Financial Holdings and Western Montana Clinic, have reached settlements in class action lawsuits following data breaches affecting 16,852 and 8,255 individuals respectively. Both breaches exposed sensitive protected health information including Social Security numbers, medical records, and treatment details, with lawsuits alleging failures to implement
AIAI Notetaker Lets Hackers Spy on Government, Corporate Video Calls
A security vulnerability in tl;dv, an AI-powered meeting notetaker, stemmed from a Google Firebase misconfiguration that exposed sensitive meeting data. The flaw allowed unauthorized users to query other users' meeting information and potentially gain access to ongoing video calls, posing significant risks to government and corporate communications.
AmGen Announces Cyberattack and Data Breach Involving Patient Data
Biopharmaceutical company Amgen disclosed a material cybersecurity incident involving unauthorized access to third-party cloud storage systems, resulting in the exfiltration of proprietary data, patient protected health information, and other sensitive data. The company detected the breach in July 2026, immediately activated its incident response plan, and filed an 8-K with the SEC, though it does
AIPNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web
The Police National Legal Database (PNLD) suffered a data breach that exposed contact information of U.K. police officers, government officials, and criminal justice professionals on the dark web. The compromised data, discovered on July 26, included names, organizational affiliations, and work email addresses of law enforcement personnel, government partners, and PNLD customers.
FMC Services Agrees to $2.15M Settlement to End Data Breach Lawsuit
FMC Services LLC, a Texas-based primary care clinic operator, has agreed to a $2.15 million settlement to resolve a consolidated class action lawsuit stemming from a 2022 cyberattack that exposed protected health information of over 233,000 individuals. The breach compromised sensitive data including Social Security numbers, health records, and personal identifiers, leading to claims of negligence
Clinical Registry Solutions; Jason R Egbert OD PC; VNC Health Announce Data Breaches
Three healthcare-related organizations have announced data breaches affecting patient information in early 2026. Clinical Registry Solutions experienced an Akira ransomware attack compromising patient and employee data, while First Sight Family Vision and VHC Health were impacted by breaches at their third-party vendors RXNT and Xsolis respectively, exposing sensitive patient information including
