Recent breaches in sectors such as healthcare and telecom have exposed millions of personal records, underscoring the need for stronger cybersecurity practices. The article also discusses software supply chain vulnerabilities and the importance of adopting secure coding and automated compliance tools.
Why These Recent Breaches Matter

Cyberattacks in healthcare, telecom, media streaming, and education have serious consequences for millions of people. This article highlights how several major organizations faced data breaches, the implications for customers, and the lessons learned about preventing future attacks. By understanding the scale and impact of these breaches, you’ll be better prepared to protect your data and recognize the importance of strong cybersecurity measures.
1. UnitedHealth’s Record-Breaking Ransomware Attack
Escalating Impact
In January 2025, UnitedHealth announced its data breach affected about 190 million individuals during the February 2024 Change Healthcare ransomware attack—nearly twice the initially reported figure of 100 million—making it the largest healthcare cyberattack in U.S. history. Hackers linked to the BlackCat (ALPHV) group allegedly stole 6 TB of sensitive data, including Social Security numbers, medical records, and billing information. They accessed the network through a stolen account credential that lacked multi-factor authentication, enabling deeper penetration into Change Healthcare’s systems.
Costly Ransom and Continued Disruption
UnitedHealth paid a $22 million ransom in hopes of recovering access to critical systems and ensuring the stolen data would be destroyed. Despite the payment, the information remained in circulation, proving that paying a ransom cannot fully guarantee data security. By late 2024, the breach caused over $2 billion in direct financial losses, disrupting billing and pharmacy services nationwide. Investigations also uncovered multiple additional extortion attempts, confirming the persistent ransomware threat facing large healthcare providers.
What Was Compromised
• Personal data: names, addresses, dates of birth, Social Security numbers
• Medical details: test results, diagnoses, treatment plans
• Financial records: billing statements, partial payment details, insurance data
TechCrunch reports final estimates of those affected may still shift. In response, security experts emphasize stronger authentication methods and comprehensive incident response protocols for all healthcare organizations.
2. TalkTalk Investigates Suspected Customer Data Theft

Ongoing Investigation Over Alleged Data Theft
In January 2025, UK telecommunications company TalkTalk initiated an investigation into a data breach involving a third-party supplier’s system. A hacker known as “b0nd” claimed responsibility, alleging that data from approximately 18.8 million current and former customers was compromised. The exposed information reportedly includes names, email addresses, last-used IP addresses, and phone numbers. TalkTalk clarified that no billing or financial details were affected and described the reported number of impacted customers as “wholly inaccurate and very significantly overstated.”
The breach is believed to have originated from CSG Ascendon’s subscription management platform, a service provider for TalkTalk. Both companies are actively investigating the incident. This event follows a previous data breach in 2015, where TalkTalk was fined £400,000 for security failings.
This case underscores ongoing security concerns in telecom. As investigations continue, TalkTalk is reviewing the practices of its external suppliers to strengthen cybersecurity.
3. Crunchyroll Credential Leak Rumors
![]()
Rumors of Leaked Credentials
A now-deleted post on X (formerly Twitter) claimed that around 50 Crunchyroll Premium accounts were exposed, attracting over a million views. Some leaked passwords appeared linked to older data breaches, and at least one contained the term “crunchyroll.” While the rumor spread fast, it largely involved weak or reused passwords, though it raised worries about a broader streaming services breach.
Company’s Response
Crunchyroll’s official statement confirmed no evidence of a system-wide compromise. The platform secured the flagged accounts and advised all subscribers to change passwords and monitor account activity. Another analysis indicated this incident was more about unauthorized credential sharing than a platform breach.
Security Reminders
Tip
Use unique passwords for each service, change passwords regularly to combat credential stuffing, and enable multi-factor authentication wherever available, as advised byesports.gg.
As covered on esports.gg, the X account that posted the rumor has been suspended.
4. PowerSchool’s K-12 Breach Affects Millions

PowerSchool, a leading education software provider, experienced a breach on December 28, 2024. Attackers gained access to its PowerSource support portal using compromised credentials. Allegedly, about 62 million student records and over 9 million teacher accounts from around 6,500 school districts were potentially exposed. Some states, notably North Carolina, reported higher risks, with 312,000 teachers’ Social Security numbers accessed.
Widespread Data Exposure
Stolen data included names, birthdates, addresses, phone numbers, and partial Social Security details. Certain districts warned of leaked medical notes (e.g., allergy information). As detailed in this breach notification, the scale of the incident highlights vulnerabilities in K-12 systems, prompting concerns about children’s future identity protection.
Lawsuits and Ransom Payment
Multiple class-action lawsuits allege PowerSchool’s security defenses were insufficient, claiming it failed to prevent the breach and omitted extra layers of protection like two-factor authentication. PowerSchool paid a ransom in an attempt to secure the destruction of stolen data.
5. Lessons for the Software Sector and Next Steps

Strengthening the Software Supply Chain
Recent events show that even trusted software can be exploited. Newly disclosed Git vulnerabilities (CVE-2024-50349 and CVE-2024-52006) demonstrate how attackers abuse credential prompts and hidden characters to gain unauthorized access. While upgrading to Git 2.48.1 helps, deeper defenses—like frequent code reviews, multi-factor authentication, and consistent patching—are critical. Global Big Data Security spending is projected to reach US$83.8 billion by 2030, reflecting the growing urgency to safeguard systems at every level.
Robust supply chain security also involves segmenting networks, going beyond regularly performing penetration tests and utilizing continuous monitoring of your entire supply chain, and adopting secure coding standards. By minimizing weak spots, organizations reduce the impact of any single attack.
Investing in Automated Compliance Tools
Staying on top of new vulnerabilities, regulatory updates, and third-party risks can overwhelm security teams. Automation platforms streamline these tasks by offering continuous risk monitoring and vendor evaluations. We can help you by providing real-time supply chain risk management and compliance insights.
Ultimately, a proactive strategy pays off—incorporating security measures during development, diligently patching vulnerabilities, and enforcing strong identity controls all help maintain trust. With fast-evolving threats, the software sector must prioritize constant vigilance and robust protection across the entire production lifecycle.