#WeeklyRoundup

Weekly Databreaches Roundup Week 33-2025

August 18, 2025
week-33-2025

Here’s your weekly #databreach news roundup:

Manpower, Canada’s House of Commons, Connex Credit Union, U.S. Judiciary, and Columbia University.

Manpower

manpowergroup

Manpower, a major staffing company within ManpowerGroup, has notified nearly 145,000 individuals that their personal data was compromised in a cyberattack that occurred between December 29, 2024, and January 12, 2025. The breach was discovered during an investigation into an IT outage at a Lansing, Michigan franchise. The RansomHub ransomware gang has claimed responsibility for the attack, stealing around 500GB of data, including sensitive personal and corporate information. Though the company did not confirm paying a ransom, the ransomware group’s removal of the data from their leak site suggests it was deleted. Manpower has strengthened its IT security and is offering affected individuals free credit monitoring and identity protection through Equifax while cooperating with the FBI in their investigation.

Canada’s House of Commons

The House of Commons of Canada is investigating a data breach that occurred on Friday, where a threat actor exploited a Microsoft vulnerability to access a database containing sensitive employee information, including names, job titles, office locations, and email addresses. The breach, discovered on Monday, raised concerns about potential fraudulent activity targeting parliamentarians or exploiting the stolen data in scams. Although the specific Microsoft vulnerability exploited has not been disclosed, recent warnings have highlighted active threats targeting flaws in Microsoft SharePoint and Exchange. The Canadian Centre for Cyber Security is assisting with the investigation, but no direct attribution has been made to a particular threat actor or group.

Connex Credit Union

Connex, one of Connecticut’s largest credit unions, notified tens of thousands of members that their personal and financial information was stolen in a data breach discovered on June 3, 2025. The breach, which occurred between June 2 and 3, compromised sensitive data such as names, account numbers, debit card information, Social Security numbers, and government IDs. While there’s no evidence yet that attackers accessed members’ accounts or funds, Connex warned of ongoing phishing scams, where attackers are impersonating the credit union’s employees. This incident follows a series of high-profile data breaches, including those linked to the ShinyHunters extortion group and Scattered Spider hacker collective, which have targeted various industries.

U.S. Judiciary

The U.S. Federal Judiciary confirmed it was targeted by a cyberattack on its electronic case management systems, which house sensitive court documents, including sealed filings. While the majority of documents are public, certain confidential materials have been further secured with enhanced access controls to prevent further breaches. This follows a Politico report that detailed a breach affecting multiple federal districts, including systems like CM/ECF and PACER, which manage federal court documents. The Judiciary acknowledged escalating cyberattacks and is strengthening cybersecurity measures but stopped short of directly confirming a breach of confidential information. However, it implied that litigant data might have been impacted and is working with courts to mitigate the consequences.

Columbia University

Columbia University

In May 2025, an unknown hacker breached Columbia University’s network, stealing sensitive personal, financial, and health information of nearly 870,000 individuals, including current and former students, employees, and applicants. The breach was discovered in June after a systems outage, and an investigation revealed that certain files were accessed and stolen. The compromised data includes names, Social Security numbers, academic history, financial aid details, and insurance-related information. Although there is no evidence of misuse, the university is offering two years of free credit monitoring and identity theft services to affected individuals. While the breach did not impact medical records at the Columbia University Irving Medical Center, the university continues to work with external cybersecurity experts to enhance its defenses.

Discover more from Data Breach Insights

Subscribe now to keep reading and get access to the full archive.

Continue reading