July 2025 Data Breach Round Up: Major Cybersecurity Incidents

Listen to this post – click on the play button below or read along:

July 2025 data breach round up
Loading the Elevenlabs Text to Speech AudioNative Player...

If you thought cybersecurity couldn’t get any scarier, July 2025 proved us all wrong. This wasn’t just another month of “routine” data breaches—it was a perfect storm that left over 3 million people wondering if their most personal information was now for sale on the dark web. From your grandmother’s insurance records to classified military communications, cybercriminals seemed to have an appetite for everything.

What made July particularly unsettling was how these attacks played out like a coordinated symphony of chaos. Insurance companies found themselves in the crosshairs of social engineers who sweet-talked their way past security systems. University students discovered their academic lives had been an open book for months. Even our own military found that Chinese hackers had been quietly reading their mail for nearly a year.

The common thread? These weren’t random attacks by basement-dwelling hackers. These were sophisticated operations that exploited the very relationships we depend on—the trust between companies and their vendors, the cloud services we can’t live without, and the interconnected digital ecosystem that keeps modern business running.

The Human Cost: Real People, Real Impact

Allianz Life Insurance Company – When Trust Gets Hijacked

July 16, 2025 – The day 1.4 million people got very bad news

Picture this: You’ve been dutifully paying your life insurance premiums for years, trusting Allianz Life to protect both your financial future and your personal information. Then one day, you get a letter that makes your stomach drop.

The attack didn’t even target Allianz directly. Instead, cybercriminals played the long game, targeting a third-party company that managed Allianz’s customer relationship system. Through what cybersecurity experts call social engineering—basically conning employees into giving up access—these digital thieves walked away with the personal details of nearly every Allianz Life customer in America.

We’re talking about everything that makes identity theft a nightmare: Social Security numbers, financial information, insurance claims (including those embarrassing medical ones you’d rather keep private), and policy details. The attackers didn’t just grab and run either—they took their time, methodically collecting data like digital archaeologists excavating your entire financial life. For the 1.4 million affected customers, this means years of credit monitoring, changing account numbers, and that nagging feeling that someone, somewhere, knows way too much about their personal business.

Source: CBS News – Allianz Life data breach affects majority of 1.4 million U.S. customers

Microsoft SharePoint – When Your Office Platform Becomes a Highway for Hackers

July 18, 2025 – Chinese hackers turn collaboration tools into espionage weapons

SharePoint servers—those behind-the-scenes platforms that help teams collaborate and share documents—became the unexpected stars of July’s cybersecurity nightmare. Chinese hackers, operating under the ominous code name “Storm-2603,” found critical vulnerabilities that Microsoft didn’t even know existed yet (that’s what makes them “zero-day” attacks—zero days to prepare a defense).

What started as typical espionage quickly escalated into something more sinister. These weren’t just spies looking to steal secrets anymore—they began deploying ransomware, essentially holding entire organizations hostage for money. Around 100 organizations worldwide found their SharePoint systems compromised, turning everyday collaboration tools into gateways for digital intruders.

The scariest part? This attack showed how nation-state hackers are evolving. They’re no longer just interested in stealing secrets for their governments—they’re also getting into the cybercrime business, blending espionage with old-fashioned extortion. For the affected organizations, it meant dealing with both the violation of having foreign agents in their systems and the very real threat of having their operations shut down by ransomware.

Source: Microsoft Security Blog – Disrupting active exploitation of on-premises SharePoint vulnerabilities

Columbia University – When Your Alma Mater Becomes an Open Book

May 2025 incident – August 2025 disclosure

Imagine finding out that your entire academic history—from that embarrassing freshman year GPA to your current graduate school applications—has been accessible to cybercriminals for months. That’s exactly what happened to nearly 870,000 people connected to Columbia University.

This wasn’t just about current students. The breach reached back through decades of university records, exposing everyone from recent graduates to people who applied but never attended. Social Security numbers, financial aid information, health records from campus medical centers, and academic transcripts all became part of a cybercriminal’s treasure trove.

What makes this particularly frustrating for victims is the timeline. The attack happened in May, but people didn’t find out until August. That’s three months of not knowing their information was compromised—three months when they could have been monitoring their credit, changing passwords, or taking other protective measures. For students already struggling with debt and uncertain career prospects, this breach added the extra burden of potential identity theft to their list of worries.

Source: BleepingComputer – Columbia University data breach impacts nearly 870,000 individuals

U.S. Army National Guard – When the Protectors Get Infiltrated

March 2024-March 2025 – Nine months of invisible enemies

For nine months, Chinese hackers calling themselves “Salt Typhoon” had a front-row seat to American military operations. They weren’t just stealing random files—they were systematically mapping out National Guard networks, stealing administrative passwords, and intercepting communications between military units.

Think about what this means for the men and women serving in the National Guard. Their personal information, duty schedules, unit communications, and operational details were all potentially compromised. This isn’t just a privacy violation—it’s a national security crisis that could affect military readiness and put service members at risk.

The breach went undetected for nine months, meaning these foreign agents had nearly a year to study American military networks, understand communication patterns, and potentially identify vulnerabilities they could exploit in future operations. For military families, this breach raises uncomfortable questions about the security of the systems that are supposed to protect both national interests and the people who serve.

Source: NBC News – National Guard was hacked by China’s ‘Salt Typhoon’ group, DHS says

Compumedics USA – When Your Medical History Goes Public

July 2025 – The VanHelsing ransomware strikes healthcare

Getting medical care requires an enormous amount of trust. You share your most intimate health details with doctors, trusting that information will stay between you and your healthcare providers. For 318,000 people connected to Compumedics USA, that trust was shattered by the VanHelsing ransomware group.

This wasn’t just about names and addresses getting stolen. We’re talking about detailed medical records—diagnoses, treatment histories, prescription information, and insurance details. Imagine having your mental health treatment history, chronic condition management, or sensitive medical procedures potentially exposed to cybercriminals who might sell that information to the highest bidder.

Healthcare breaches are particularly insidious because medical information can’t just be changed like a credit card number. Your diabetes diagnosis, your history of depression, your cancer treatment—these become permanent parts of your identity that could potentially be used for discrimination, blackmail, or insurance fraud. For the affected patients, this breach means constantly worrying about who might have access to their most private medical information.

Source: VirusS – Compumedics Ransomware Attack Led to Data Breach Impacting 318,000

Aflac Insurance – The Phone Call That Started It All

June 12, 2025 – When being helpful becomes harmful

Sometimes the biggest security breaches start with something as simple as a helpful employee answering a phone call. That’s essentially what happened at Aflac, where sophisticated social engineers convinced someone to give them access to internal systems.

The attackers didn’t use fancy hacking tools or exploit complex software vulnerabilities. They used psychology. They probably called pretending to be from IT support, maybe claiming there was an urgent security issue that required immediate access. Someone, trying to be helpful and follow what they thought were legitimate instructions, unknowingly handed over the keys to customer data.

The result? Sensitive customer information including Social Security numbers, health insurance claims, and medical records all became accessible to cybercriminals. For Aflac customers, this meant dealing with the reality that their most personal information—including potentially embarrassing medical claims—might now be in the hands of people who definitely don’t have their best interests at heart.

Source: Strategic Revenue – Aflac Hit by Sophisticated Cyberattack

Dell Technologies – When Even Test Data Becomes a Target

July 2025 – Extortionists get creative with demonstration systems

Dell’s breach was different from the others—it targeted the company’s Customer Solution Centers, the specialized environments where Dell demonstrates products to potential clients. The World Leaks extortion group (formerly known as Hunters International) made off with 1.3 terabytes of files, which sounds terrifying until you realize most of it was fake data used for demonstrations.

But that didn’t stop the extortionists from trying to shake Dell down. They essentially said, “Pay us, or we’ll release all this data and embarrass you publicly.” It’s a bit like a burglar stealing prop jewelry from a theater and then demanding ransom money, but the threat to Dell’s reputation was real enough.

This attack showed how cybercriminals are getting more creative about what they consider valuable. Even if the data wasn’t real customer information, the potential for business disruption and reputation damage was enough to make it a worthwhile target for extortion.

Source: BleepingComputer – Dell confirms breach of test lab platform by World Leaks extortion group

The Bigger Picture: Why This Matters to Everyone

July 2025 taught us some uncomfortable truths about our connected world. The biggest lesson? Your security is only as good as the security of every company you’ve never heard of that handles your data.

Take Allianz Life’s customers. They didn’t choose to do business with whatever third-party company managed Allianz’s customer database. They probably didn’t even know it existed. But when that company got social engineered, 1.4 million people’s personal information became vulnerable. That’s the new reality of supply chain attacks—your data is only as secure as the weakest link in a chain you can’t even see.

The insurance industry’s rough July wasn’t coincidental. Cybercriminals have figured out that insurance companies are goldmines of personal and financial information, often with security investments that haven’t kept pace with the value of what they’re protecting. When you add health insurance into the mix, you get a perfect storm of highly sensitive data that’s extremely valuable to identity thieves.

Meanwhile, the healthcare attacks on companies like Compumedics show how cybercriminals are getting smarter about targeting the suppliers and technology companies that serve multiple healthcare networks. Breach one vendor, potentially access patient data from dozens or hundreds of healthcare providers. It’s efficient from a criminal perspective, and terrifying from everyone else’s.

What This Means for Your Business

The July 2025 breaches sent a clear message: traditional security thinking is dead. You can build the highest walls around your own systems, but if a vendor gets compromised through a simple phone call (like Aflac), all that investment in perimeter security becomes worthless.

Your customers and employees are counting on you to not just secure your own data, but to ensure that every vendor, cloud provider, and business partner you work with takes security seriously. Because when they fail, you fail, and everyone pays the price.

The solution isn’t more firewalls or better passwords—it’s comprehensive vendor risk management.

Findings helps you see the full picture of your supply chain security. Instead of hoping your vendors are as security-conscious as you are, you’ll know. Our platform continuously monitors and assesses your entire vendor ecosystem, identifying weak spots before they become front-page news.

Because in a world where a social engineering attack on a company you’ve never heard of can expose your customers’ most sensitive data, hope isn’t a strategy. Visibility is.

Don’t let July 2025 be a preview of your company’s future headlines. Take control of your vendor risk today.

See how teams catch vendor breaches before they spread

Already have an account?

Get Started with Findings

* indicates required

We Use Cookies.

This website uses cookies to enhance your browsing experience, analyze site traffic, and improve our services. By continuing to use this site, you consent to our use of cookies in accordance with our privacy policy. You can manage your cookie preferences at any time through your browser settings.