Identity Security
Fifteen Months, One Phone Call: How the Same Attack Went From Marks & Spencer to Apollo Global Management
The same attack technique ran from UK retail in April 2025 to Wall Street in July 2026. Fifteen months, public the entire time, and the controls that stop it are neither new nor expensive.
Amazon's One Medical Confirms a "Limited" Breach. ShinyHunters Claims 8.8 Terabytes and a Deadline. Only One of Those Is Verified.
On June 13, One Medical disclosed unauthorized access to a third-party file storage system holding archived records from its legacy Iora Health and One Medical Seniors patients, describing the scope as a limited subset of files at nine named clinics. Days earlier, on June 18, ShinyHunters posted One Medical to its dark-web leak site, claimed 8.8 terabytes of stolen data, and gave the company until June 22 to begin negotiating before publication. ShinyHunters has released no sample data, so the claim is unverified. This is the same actor, the same playbook, and the same trust gap Cloudskope documented in the Canvas/Instructure breach: a company describing the smallest defensible version of events while a threat actor describes the largest. For boards in healthcare and any regulated-data business, the lesson is not which number to believe. It is to treat both as unproven until the evidence settles it, and to plan for the larger one.
Most Common Passwords in 2026: What the Data Shows
The 2026 password data: 123456 is still #1, 65% of users reuse passwords across breaches. What boards and CISOs should be doing about it.
30 Biggest Data Breaches of All Time
Ranked by records: Yahoo, NPD, LinkedIn, Marriott, Canvas, T-Mobile, Equifax, Target, Capital One, Change Healthcare — and the regulatory fallout each produced.
Scattered Spider Plea: The Playbook Is Now Commoditized
Scattered Spider operative 'TylerB' pleaded guilty. The real threat isn't the arrest — it's that the social engineering playbook is now commoditized.
Microsoft Edge Stored Every Password in Cleartext
Microsoft Edge has been storing saved passwords in cleartext on disk. Any process with disk access can read them. What it means for enterprise password hygiene.
.png)

.png)