In-depth analysis of significant data breaches and cyber incidents. Understand what happened,
who was affected, and what your organisation can learn from each event.
Disclaimer
These advisories summarise publicly reported cybersecurity incidents for educational purposes.
All information is sourced from publicly available reports and may include claims that are
unverified or disputed. See individual advisories for full source citations and disclaimers.
Healthcare / Academic Research · United States · March 2026
Analysis of the University of Hawai'i Cancer Center ransomware attack affecting up to 1.24 million individuals. Legacy research data from the 1990s exposed including SSNs.
United States Up to approximately 1.24 million individuals
Analysis of the Loblaw Companies data breach where hackers accessed customer contact information from Canada’s largest food and pharmacy retailer, which operates 2,400+ stores.
Canada Undisclosed; Loblaw operates 2,400+ stores and has 18 million loyalty programme members
Data Brokerage / Identity Verification · United States · March 2026
Analysis of the Infutor data exposure affecting approximately 677 million records of US consumer data, including Social Security Numbers, reportedly caused by a misconfigured Elasticsearch database.
United States Approximately 676,798,866 unique records
Business Process Outsourcing / Technology Services · Canada · March 2026
Analysis of the TELUS Digital breach where ShinyHunters allegedly stole close to 1 petabyte of data, reportedly including BPO customer data for 28 companies, using credentials from the Salesloft Drift breach.
Canada Close to 1 petabyte of data allegedly stolen; BPO customer data for reportedly 28 major companies
Manufacturing / Chemicals · Netherlands · March 2026
Analysis of the Anubis ransomware attack on AkzoNobel where the group claims to have stolen 170GB of data including passport scans and confidential agreements from the global paints and coatings manufacturer.
Analysis of the Odido data breach affecting over 6 million individuals in the Netherlands. Social engineering attack bypassed MFA and exposed customer data including IBANs and identity document metadata.
Netherlands Over 6.5 million individuals and approximately 600,000 businesses
Healthcare / Medical Devices · United States · March 2026
Analysis of the Handala group’s destructive wiper attack on Stryker Corporation, which reportedly wiped up to 200,000 devices across 79 countries using the company’s own Microsoft Intune platform.
United States 80,000 to 200,000 devices reportedly wiped across 79 countries
Healthcare IT / Revenue Management · United States · March 2026
Analysis of the TriZetto Provider Solutions data breach affecting over 3.4 million patients. An 11-month unauthorised access to healthcare claims processing systems exposed SSNs and health data.
United States Over 3.4 million individuals (and growing)
Education / Government / Arts · Norway · March 2026
Analysis of the Den kulturelle skolesekken (DKS) data breach in Norway exposing approximately 1.3 million records from the national cultural education programme.
Norway Approximately 1.3 million records (claimed)
Identity Verification / Fintech · Global · February 2026
Analysis of the IDMerit KYC data exposure affecting approximately 1 billion identity verification records across 26 countries due to a misconfigured MongoDB database.
Government IT Services / Healthcare · United States · February 2026
Analysis of the Conduent ransomware breach affecting over 25 million individuals including government benefits recipients. SafePay group claimed to have exfiltrated 8TB of data.
United States Over 25 million individuals (and growing)
Analysis of the Under Armour data breach with 72 million customer records allegedly leaked by the Everest ransomware group after a failed extortion attempt.
United States 72 million email addresses; 191 million total records
Analysis of the alleged Match Group breach reportedly exposing 10 million records from Hinge, Match.com, and OkCupid via claimed compromise of marketing analytics partner.
Analysis of the Central Ozarks Medical Center breach affecting 11,818 individuals' health data.
United States 11,818 individuals
No advisories match these filters
Try widening your selection or clearing the filters.
Frequently asked questions
What is a ScruteX breach advisory?
A breach advisory is an in-depth, plain-English analysis of a significant, publicly reported data breach or cyber incident. Each advisory summarises what happened, who was affected, the likely attack vector, and the practical lessons other organisations can draw from the event.
How are incidents selected?
Our research team prioritises incidents by scale, sector relevance, novelty of the attack technique, and how much other defenders can learn from them. We focus on incidents that have been publicly disclosed through reputable reporting, regulatory filings, or the affected organisation's own notifications.
How can my organisation be removed from an advisory?
Advisories are compiled solely from publicly available information for educational purposes and do not imply fault or negligence. If you represent an organisation featured here and believe any detail requires correction, email hello@scrutex.ai and our team will review it promptly.