Here’s your weekly #databreach news roundup:
LastPass, Xsolis, Tata Electronics, Kodak, Novo Nordisk, Nintendo, Klue, and London Hydro.
Xsolis
Xsolis, a U.S. healthcare technology company that provides AI software to over 600 hospitals and health insurers, suffered a phishing attack in January 2026 that allowed hackers to access sensitive data of about 1.4 million people. The stolen information may include names, addresses, dates of birth, Social Security numbers, health insurance details, and medical treatment records. Although the company says it has not found any misuse of the data, it has reported the incident to law enforcement, reset passwords, improved security measures, increased employee cybersecurity training, and is notifying affected individuals by mail. Those affected are also being offered 12 months of free identity monitoring and identity theft protection through Kroll.
LastPass
LastPass revealed that hackers accessed some customer support data after stealing OAuth tokens during the Klue supply chain attack. The attackers used these stolen credentials to access LastPass’s Salesforce environment, exposing customer names, phone numbers, email addresses, physical addresses, support case details, and sales-related information. However, LastPass confirmed that its password vaults, products, and infrastructure were not compromised. The company has disabled Klue access, rotated affected tokens, informed law enforcement, and warned customers to be cautious of phishing attempts and to never share their master passwords.
Tata Electronics
Tata Electronics, a major Indian electronics and semiconductor manufacturer that supplies companies like Apple and Tesla, confirmed it suffered a cyberattack after hackers claimed to have stolen over 630GB of company data. The leaked files reportedly include emails, SAP information, and documents related to customers such as Apple and Tesla, although the full extent of the breach has not been independently verified. Tata said it quickly responded to the incident and that its business operations were not affected, but it has not disclosed what data was compromised or how many people or organizations were impacted. Reports also suggest Apple is investigating the incident and that the attackers demanded a ransom.
Kodak
Kodak confirmed that hackers temporarily gained unauthorized access to a limited amount of company data and is investigating the incident with the help of cybersecurity experts and law enforcement. The company said there is no threat to its systems or business operations, but it has not revealed how the attackers gained access. The ShinyHunters hacking group has claimed responsibility, alleging it stole over 2.2 million customer records containing personal information and internal company data, and has threatened to leak the stolen information if its demands are not met. However, Kodak has not verified these claims.
Novo Nordisk
The cyber extortion group FulcrumSec claims it stole more than 1 terabyte of data from pharmaceutical company Novo Nordisk after spending over two months inside its network. The group says the stolen data includes source code, information on existing and future drugs, clinical trial data, employee, doctor, and patient information, and details about manufacturing facilities. After Novo Nordisk refused to pay a $25 million ransom, the hackers said they are considering selling some of the stolen data. Novo Nordisk acknowledged a cybersecurity incident involving unauthorized access to some internal systems and said it is working with authorities, but the company has not confirmed the hackers’ claims or the authenticity of the leaked data.
Nintendo
Nintendo of America confirmed that hackers accessed employee survey data through TinyPulse, a third-party employee feedback platform, but said its own systems were not compromised and no customer or financial data was affected. The company stated that the exposed information is limited to internal survey content involving a small number of employees, most of it several years old. However, the Shadowbyt3$ hacking group claims it also stole employee personal information, including names, email addresses, bank statements, and tax forms, and demanded a $2 million ransom. Nintendo is working with the service provider to investigate the incident, while the hackers’ broader claims have not been independently verified.
Klue
A supply chain attack targeting the third-party app Klue Battlecards allowed hackers to steal customer data from companies using Salesforce by exploiting an old test credential and stealing OAuth tokens, which bypassed normal security protections. The attackers, identified as the Icarus extortion group, used automated tools to copy business data such as contacts, email addresses, sales messages, and price quotes from several companies, including Huntress, Jamf, Recorded Future, Tanium, Gong, Insurity, and Sprout Social. Salesforce confirmed that its platform was not vulnerable and disabled Klue’s integration to stop the attack. Organizations using Klue have been advised to revoke and replace affected OAuth tokens and passwords to prevent further unauthorized access.
London Hydro
London Hydro, a Canadian electricity provider, is investigating a cybersecurity incident that may have exposed customer information, including names, addresses, contact details, account and billing numbers, service addresses, pricing plans, and meter information. The company said sensitive financial data such as bank account details, payment card information, dates of birth, and government IDs were not affected. However, it has not disclosed how the breach happened, whether data was stolen, how many customers were impacted, or if its operational systems were compromised. London Hydro is advising customers to be alert for phishing scams, fake bills, and suspicious requests for payment or account information.