October 2025 Data Breach Round Up

Listen to this post – click on the play button below or read along:

Loading the Elevenlabs Text to Speech AudioNative Player...

From high-profile technology providers like F5 Networks and Ribbon Communications to global consumer brands such as MANGO and Toys “R” Us, the month’s incidents underscored how both direct attacks and third-party breaches can expose millions of records and disrupt trust. As attackers increasingly exploit supply chain dependencies and third-party access points, organizations face growing pressure to validate not only their own controls but also those of their vendors and partners. At Findings, we help enterprises and suppliers alike navigate this challenge. Findings provides real-time visibility into security posture, automating compliance checks, and monitoring risk across entire supply chains. As these breaches reveal, protecting your own perimeter is no longer enough. You need continuous, evidence-based assurance that every connected entity is secure.

F5 Networks: Nation-State Actors Steal Source Code and Zero-Days

In October 2025, F5 disclosed that a sophisticated nation-state threat actor had maintained long-term access to its systems, exfiltrating files from its BIG-IP product development and engineering environments. The stolen data included portions of BIG-IP source code and details about undisclosed vulnerabilities, though F5 reported no evidence of exploitation or compromise of customer data, build pipelines, or NGINX and Distributed Cloud systems. The company engaged cybersecurity firms CrowdStrike, Mandiant, NCC Group, and IOActive to contain and validate the incident’s scope, confirming that no critical vulnerabilities had been weaponized. F5 has since issued updates for BIG-IP, F5OS, BIG-IP Next for Kubernetes, and related products, urging customers to patch immediately. Additional hardening, monitoring, and EDR integrations were implemented as part of F5’s broader remediation and transparency effort. We recently published all the key details and guidance you need to know about this incident in our latest blog post — read it here

Gmail Credential Exposure Affecting 183 Million Accounts (October–November 2025)

In late October 2025, reports surfaced that 183 million Gmail credentials had been exposed in a large-scale data aggregation leak, prompting urgent warnings for users to change their passwords. The data, first flagged by Have I Been Pwned, originated from multiple breaches across the internet and included email addresses and associated passwords, potentially granting access to linked accounts. While Google clarified that its systems were not directly breached and that “reports of a Gmail security breach” were inaccurate, it acknowledged that compromised credentials remain a serious threat. The company advised users to reset passwords found in leaked datasets, enable two-factor authentication, and adopt passkeys as a safer, passwordless alternative. Google noted a sharp rise in credential theft methods—particularly infostealers and token hijacking—underscoring the need for stronger authentication practices.

Toys “R” Us Canada Customer Data Leak

Toys “R” Us Canada has notified customers of a data breach after threat actors leaked stolen customer records on the dark web. The company first learned of the leak when a hacker posted samples of the data online, later confirmed as authentic through a third-party forensic investigation. The exposed data varies by individual and may include names, physical and email addresses, and phone numbers, though no passwords or payment card details were compromised. Following the discovery, Toys “R” Us Canada engaged cybersecurity experts, enhanced its IT security systems, and began notifying privacy regulators in Canada. Customers have been urged to remain vigilant against phishing attempts or fraudulent messages impersonating the brand.

Sotheby’s Data Breach Exposes Employee Financial Information

Sotheby’s, one of the world’s leading auction houses, disclosed a data breach after discovering that threat actors had stolen sensitive information from its systems. Initially believed to involve customer data, the company later confirmed the incident affected employees, with exposed details including full names, Social Security numbers, and financial account information. The breach was detected on July 24, 2025, and a two-month investigation followed to determine the scope of impact and validate what data had been compromised. Sotheby’s has since notified affected individuals and is offering 12 months of free identity protection and credit monitoring through TransUnion. While no ransomware group has claimed responsibility, the incident adds to a history of security issues at the company, including previous payment data theft and supply chain attacks.

MANGO Data Breach via Compromised Marketing Provider

Spanish fashion retailer MANGO has confirmed a data breach stemming from unauthorized access at one of its external marketing service providers. The exposed data, limited to marketing contact information, includes customers’ first names, countries, postal codes, email addresses, and phone numbers—while last names, financial data, ID documents, and login credentials remain secure. MANGO emphasized that its own systems and corporate infrastructure were not impacted and that all business operations continue normally. Upon detecting the incident, the company activated its internal security protocols, notified the Spanish Data Protection Agency (AEPD), and informed relevant authorities in line with GDPR requirements. As a precaution, customers were advised to stay alert for phishing attempts or fraudulent communications, with MANGO reiterating that it never requests personal or banking information by email or phone.

Conduent Data Breach Exposes Personal and Health Information of 10.5 Million People

Business process outsourcing giant Conduent has confirmed that a cyberattack originating in late 2024 exposed sensitive personal and health information of more than 10.5 million individuals. The breach, which was later linked to the Safepay ransomware gang, compromised data including names, Social Security numbers, birth dates, health insurance details, and medical information. While Conduent maintains that there is currently no evidence of misuse, the scale of exposure—spanning multiple U.S. states—suggests the true impact could be even greater. The company initially discovered the breach in January 2025, revealing that attackers had gained access months earlier, on October 21, 2024. Notifications to affected individuals began in October 2025, with state filings confirming millions impacted in Oregon, Texas, and Washington. Those affected have been urged to monitor credit reports and consider fraud alerts or security freezes, though Conduent has not offered identity protection services.

Prosper Data Breach Allegedly Exposes Information of 17.6 Million Users

Peer-to-peer lending platform Prosper has confirmed a significant data breach that exposed the personal information of approximately 17.6 million customers and loan applicants. Detected on September 2, 2025, the intrusion allowed attackers to access databases containing sensitive data such as names, Social Security numbers, government-issued IDs, employment and credit status, income details, birth dates, addresses, and IP information. Although Prosper maintains there is no evidence that customer funds or accounts were compromised, the company acknowledged that confidential and proprietary data was obtained through unauthorized queries. The financial firm has reported the incident to authorities and is cooperating with law enforcement, while offering affected individuals free credit monitoring once the investigation clarifies the full scope of exposure. Prosper emphasized that its customer-facing operations were not impacted, though the company has yet to validate the full findings reported by Have I Been Pwned.

Ribbon Communications Breached by Suspected State-Linked Hackers

Telecommunications provider Ribbon Communications has confirmed a cyber intrusion attributed to a suspected nation-state actor that gained access to its IT network as early as December 2024. The breach, detected in September 2025 and disclosed in an SEC filing on October 23, affected systems serving major clients including U.S. government agencies, telecom providers, and global infrastructure organizations. While Ribbon reports no evidence that “material information” was stolen, investigators found that files belonging to several customers were accessed via two compromised laptops outside the company’s main network. The company has contained the intrusion, is collaborating with law enforcement and cybersecurity experts, and anticipates limited financial impact. Security analysts noted the attack’s similarities to prior campaigns by China-linked group Salt Typhoon, which has previously targeted telecom firms worldwide, suggesting the breach may be part of a broader espionage effort against critical communications infrastructure.

Discord Third-Party Vendor Breach Exposes Limited User Data

On October 23, 2025, Discord disclosed a security incident stemming from a breach of its third-party customer service provider, 5CA, which led to unauthorized access to certain user data. The compromise affected users who had interacted with Discord’s Customer Support or Trust & Safety teams, with roughly 70,000 individuals potentially having government ID photos exposed—used by the vendor for age verification. Additional impacted data may include usernames, contact details, partial billing information, IP addresses, and message exchanges with support agents. Discord emphasized that no passwords, authentication data, or platform messages were compromised. The company immediately revoked the vendor’s access, launched an investigation with a forensic firm, and notified affected users and authorities. Discord stated it continues to strengthen oversight of third-party partners and cooperate with law enforcement in response to the extortion-motivated attack.

Why Continuous Trust Matters More Than Ever

From stolen source code and credential leaks to vendor compromises and state-backed espionage, October 2025 breaches show how quickly risk can ripple through entire ecosystems. They’re a reminder that cybersecurity isn’t just about protecting your own systems, but also about knowing who you’re connected to, and how those connections are secured. Findings helps organizations turn that uncertainty into visibility by continuously monitoring vendors, automating compliance, and detecting threats in real time. The goal isn’t just to react to the next incident, it’s to prevent it. Today, trust can’t be assumed. It has to be verified.

See how teams catch vendor breaches before they spread

Already have an account?

Get Started with Findings

* indicates required

We Use Cookies.

This website uses cookies to enhance your browsing experience, analyze site traffic, and improve our services. By continuing to use this site, you consent to our use of cookies in accordance with our privacy policy. You can manage your cookie preferences at any time through your browser settings.