August 2026 delivered another wave of high-impact breaches, but the common thread was not just the volume of data exposed. Many of the month’s most significant incidents originated in third-party platforms, logistics providers, cloud applications, and other external systems that organizations rely on every day. From CEVA and ShipMonk to Metabase, McKesson, and Wesco, these breaches show how quickly risk can travel across connected vendor ecosystems and expose customers far beyond the original point of compromise. This month’s roundup looks at the most notable incidents reported in August, who was affected, what data was exposed, and what they reveal about the growing need for continuous visibility into third-party risk.
Anthropic Warns Infostealer Malware Is Hijacking Claude Sessions
On August 30, 2026, Anthropic warned some Claude users that infostealer malware had stolen active login sessions from compromised computers, allowing attackers to access accounts without necessarily needing passwords or two-factor authentication. The company linked the activity to malware families including Vidar, LummaC2, StealC, RedLine, Acreed, and Atomic Stealer, which can harvest browser cookies, credentials, and authenticated sessions. A key sign of compromise was unexpected Claude usage, with account limits appearing to refill and then being rapidly exhausted while users were inactive. Anthropic said the malware was not distributed through Claude itself and was likely already present on victims’ devices before their Claude sessions were stolen. The company has been revoking affected sessions, removing saved payment methods, refunding confirmed unauthorized charges, and urging users to remove the malware and change their credentials.
Ceva Logistics: When Your Shipping Vendor Becomes a Breach Vector for Dozens of Brands
A cyberattack on global shipping giant CEVA Logistics, which began on July 29, 2026, exposed customer data and disrupted operations across eight European warehouses. CEVA confirmed the intrusion to affected customers on August 1, while companies including Bol, De Bijenkorf, Ajax, ING, Ace & Tate, and Valve later reported that customer information had been compromised. The exposed data reportedly included names, home addresses, phone numbers, email addresses, and shipping details, while some retailers also experienced delivery delays and order cancellations. Valve said it learned of the breach on August 7 and notified customers who had recently purchased Steam hardware. As of August 10, Dutch authorities were investigating the incident, with the country’s data protection regulator reporting breach notifications from at least 10 organizations linked to the attack.
This is a textbook example of concentration risk in logistics infrastructure. Ceva’s clients handed it customer PII as a necessary byproduct of fulfillment — names, addresses, contact details — with no mechanism to independently verify how that data was protected. Each downstream company now faces customer notification obligations, regulatory scrutiny in multiple EU jurisdictions under GDPR, and reputational damage — for a breach they did not cause and may not have been able to prevent unilaterally.
This incident highlights why it is important to know which of your vendors holds your customers’ data, not just your company’s data. Logistics and fulfillment providers are often overlooked in third-party risk assessments because they don’t sit inside the IT perimeter. The Ceva breach demonstrates they belong on the same vendor risk register as your cloud infrastructure providers. Contract clauses requiring timely notification and audit rights are non-negotiable for any vendor with access to end-customer PII.
McKesson Breach: ShinyHunters Claims Theft of 284 Million Patient Records
On August 25, 2026, U.S. healthcare and pharmaceutical distribution giant McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and the theft of company data. The ShinyHunters extortion group claimed responsibility, alleging that attackers used voice phishing to compromise employee Okta accounts before accessing McKesson’s Salesforce and Snowflake environments. The group claims it exfiltrated roughly 1 TB of data over four days, potentially comprising around 284 million records containing names, addresses, dates of birth, Social Security numbers, medical record numbers, healthcare provider information, and other sensitive data. McKesson has confirmed that data was exfiltrated and warned customers of possible intermittent service disruptions, but has not confirmed ShinyHunters’ figures or determined the full scope and material impact of the incident. The company’s investigation remains ongoing.
Unlimited Technology Systems: The Healthcare Vendor Breach That Took 10 Months to Surface
Unlimited Technology Systems (UTS), a healthcare technology provider serving thousands of oncology and specialty practices, disclosed a data breach affecting 3,803,750 individuals. The company discovered the incident in October 2025 and determined that an unauthorized actor accessed and stole data from one of its commercial data centers between October 5 and October 10, 2025. Compromised information included names, contact details, Social Security numbers, medical record numbers, diagnoses, dates of service, insurance and claims information, and scanned documents such as driver’s licenses and government IDs, although UTS said full medical records, medical imaging, and financial account information were not involved. UTS reported the breach to the U.S. Department of Health and Human Services in late July 2026, and the incident was added to the HHS breach portal on August 6. The company said it had found no evidence of misuse as of its notification and is offering affected individuals two years of credit monitoring and identity theft protection services.
The 10-month gap between breach occurrence and public disclosure is not unusual in healthcare — it reflects both the complexity of forensic investigations and the structural delays built into HIPAA’s notification timelines. But for the 3.8 million individuals whose SSNs and health records were sitting in a threat actor’s hands for nearly a year, that timeline is unacceptable.
A Metabase Zero-Day Takes Down an Entire Customer Base
On August 6, 2026, business intelligence platform Metabase disclosed that attackers had exploited a previously unknown zero-day vulnerability affecting versions 1.58 and above of its software. The flaw could allow attackers to gain administrator-level access, change application settings, steal stored database credentials, access connected data, and export information from affected environments. Computer maker Framework later confirmed that attackers had accessed its Metabase Cloud instance and stolen personal information belonging to all of its customers, including names, email addresses, phone numbers, and physical addresses, although payment information was not exposed. Metabase said its cloud customers had already been patched, while self-hosted users were urged to upgrade immediately, revoke active sessions, rotate credentials, and review logs for suspicious activity. The incident highlights how a vulnerability in a third-party platform can quickly become a downstream data breach for its customers.
This is the analytics and business intelligence vendor blind spot made concrete. BI tools like Metabase, Looker, Tableau, and their equivalents regularly hold copies or live connections to production customer databases. They are often provisioned quickly, by growth or analytics teams rather than security teams, and may sit outside the formal vendor assessment process. A zero-day exploit against a BI vendor is, effectively, a direct hit on whatever production data that tool can query.
Wesco International: Supply Chain Distributor Hit by ExfilSquad
In August 2026, global supply chain and distribution company Wesco confirmed it was investigating a cybersecurity incident involving its cloud-based CRM environment after the data extortion group ExfilSquad claimed to have stolen company information. ExfilSquad alleged that it exfiltrated 2.6 million records containing customer and employee personal information, account and contact data, CRM profiles, business identifiers, authentication metadata, and access information, and later published the data after its ransom negotiation deadline expired. Wesco said the incident was detected quickly and that its investigation found no evidence of ransomware or other malware, with business operations continuing normally. The company also said it does not believe payment card data, financial account information, or other sensitive customer or employee information is at risk, although it has not confirmed the full scope of ExfilSquad’s claims. Wesco has not disclosed how the attackers gained access to the CRM environment.
Supply chain distribution companies occupy a peculiar risk position: they sit at the intersection of industrial OT environments and modern SaaS CRM stacks. Wesco’s incident reflects what happens when that boundary is poorly defended. The exposure of authentication metadata in particular raises the possibility of credential reuse attacks against Wesco’s downstream clients.
Trezor via ShipMonk: The Hardware Wallet Breach That Didn’t Touch the Hardware
On August 10, 2026, hardware wallet maker Trezor was notified that its third-party shipping provider, ShipMonk, had suffered a data breach exposing information belonging to approximately 13,689 customers. The incident affected customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal, primarily those who received orders between May 10 and August 8, with 11,742 customers having names, email addresses, phone numbers, and shipping addresses exposed and another 1,947 experiencing partial exposure. Trezor said its own systems and devices were not compromised, but warned that the leaked contact information could be used for targeted phishing, impersonation, and other social engineering attacks. ShipMonk reportedly said the unauthorized access was linked to a vulnerability in Metabase, the same analytics platform that disclosed exploitation of a zero-day flaw earlier in August. Trezor notified affected customers directly and said it was working with ShipMonk to determine the full scope and timeline of the incident.
This breach mirrors the Ceva/Framework pattern: the attack surface was not the primary vendor’s product but the logistics layer that wraps it. Trezor’s security posture for its core product (the wallet) is strong. ShipMonk’s was not. The downstream risk to Trezor customers — whose identity as crypto asset holders is now in threat actor hands — is disproportionate to the apparent sensitivity of the data stolen.
The CloudVRM Lens: What These Breaches Demand From Vendor Risk Programs
Each of the breaches above exposes a gap that a mature, continuous vendor risk management program is specifically designed to close. Here’s how to map the lessons:
| Gap Exposed | CloudVRM Response |
|---|---|
| Logistics/fulfillment vendors not in scope | Full vendor inventory with automatic tiering by data access type |
| 117-day average disclosure delay | Continuous monitoring + dark web and breach intelligence feeds |
| BI tools treated as low-risk | Data-flow-aware risk classification across all vendor categories |
| Credential exposure not detected | Real-time credential monitoring integrated into vendor risk scores |
| Downstream cascade impact unknown | Nth-party visibility and supply chain mapping |
| Annual assessments vs. real-time threat | Continuous risk signal ingestion, not point-in-time assessments |
The Ceva breach alone damaged ING, Bol, De Bijenkorf, Ajax, Ace & Tate, and Valve. Six organizations, one vendor, one breach window of four days. Black Kite’s data says the average vendor breach now hits 5.28 downstream companies. That’s not a worst-case scenario. That’s the average.
The question for security and procurement leaders isn’t whether your vendors will be breached. It’s whether you’ll know about it in time to act.
How Findings.co Approaches This Problem
Findings CloudVRM is built on the premise that vendor risk is a continuous, operational problem — not a compliance checkbox. That means:
- Continuous monitoring across your vendor ecosystem, not annual questionnaire cycles
- Automated vendor inventory that captures the full scope of your third-party relationships — including logistics providers, BI tools, and other non-obvious data holders
- Breach intelligence integration that surfaces exposure events — including dark web credential dumps — before vendors self-disclose
- Nth-party visibility that maps your supply chain dependencies so a Ceva-type cascade doesn’t catch you blind
- Risk-tiered workflows that prioritize vendor remediation based on actual data access and sensitivity context, not just vendor size
The August breach landscape is a practical syllabus in why vendor risk management cannot remain reactive. Organizations using CloudVRM have the operational foundation to move faster than the 117-day silent window which helps them know when a vendor is compromised, which of their own assets are at risk, and what to do next.