Here’s your weekly #databreach news roundup:
Manpower, Canada’s House of Commons, Connex Credit Union, U.S. Judiciary, and Columbia University.
Manpower
Manpower notifies 145K people of a #databreach after attackers accessed its systems in Dec 2024.
— DevaOnBreaches (@DevaOnBreaches) August 17, 2025
Personal and corporate data, including IDs and financial info, were stolen by the RansomHub ransomware group.https://t.co/l1jvGpCE25
Manpower, a major staffing company within ManpowerGroup, has notified nearly 145,000 individuals that their personal data was compromised in a cyberattack that occurred between December 29, 2024, and January 12, 2025. The breach was discovered during an investigation into an IT outage at a Lansing, Michigan franchise. The RansomHub ransomware gang has claimed responsibility for the attack, stealing around 500GB of data, including sensitive personal and corporate information. Though the company did not confirm paying a ransom, the ransomware group’s removal of the data from their leak site suggests it was deleted. Manpower has strengthened its IT security and is offering affected individuals free credit monitoring and identity protection through Equifax while cooperating with the FBI in their investigation.
Canada’s House of Commons
The House of Commons of Canada is investigating a #databreach after a cyberattack on Friday, in which a Microsoft vulnerability was exploited to steal employee information, including names, titles, and contact details.https://t.co/dO9yWd1e0C
— DevaOnBreaches (@DevaOnBreaches) August 16, 2025
The House of Commons of Canada is investigating a data breach that occurred on Friday, where a threat actor exploited a Microsoft vulnerability to access a database containing sensitive employee information, including names, job titles, office locations, and email addresses. The breach, discovered on Monday, raised concerns about potential fraudulent activity targeting parliamentarians or exploiting the stolen data in scams. Although the specific Microsoft vulnerability exploited has not been disclosed, recent warnings have highlighted active threats targeting flaws in Microsoft SharePoint and Exchange. The Canadian Centre for Cyber Security is assisting with the investigation, but no direct attribution has been made to a particular threat actor or group.
Connex Credit Union
Connex Credit Union (CT) warns 70K+ members of a June #databreach exposing names, SSNs, account/debit information & IDs.https://t.co/lZch0CvJYi
— DevaOnBreaches (@DevaOnBreaches) August 13, 2025
Connex, one of Connecticut’s largest credit unions, notified tens of thousands of members that their personal and financial information was stolen in a data breach discovered on June 3, 2025. The breach, which occurred between June 2 and 3, compromised sensitive data such as names, account numbers, debit card information, Social Security numbers, and government IDs. While there’s no evidence yet that attackers accessed members’ accounts or funds, Connex warned of ongoing phishing scams, where attackers are impersonating the credit union’s employees. This incident follows a series of high-profile data breaches, including those linked to the ShinyHunters extortion group and Scattered Spider hacker collective, which have targeted various industries.
U.S. Judiciary
The U.S. Federal Judiciary confirms a cyberattack on its case management systems, which may have exposed sensitive documents. #databreach https://t.co/o3oijh8xbZ
— DevaOnBreaches (@DevaOnBreaches) August 10, 2025
The U.S. Federal Judiciary confirmed it was targeted by a cyberattack on its electronic case management systems, which house sensitive court documents, including sealed filings. While the majority of documents are public, certain confidential materials have been further secured with enhanced access controls to prevent further breaches. This follows a Politico report that detailed a breach affecting multiple federal districts, including systems like CM/ECF and PACER, which manage federal court documents. The Judiciary acknowledged escalating cyberattacks and is strengthening cybersecurity measures but stopped short of directly confirming a breach of confidential information. However, it implied that litigant data might have been impacted and is working with courts to mitigate the consequences.
Columbia University
A cyberattack on Columbia University in May exposed sensitive data of nearly 870K current/former students, employees, and applicants. Stolen info includes personal, financial, and health details. #databreachhttps://t.co/l2fr2y0kRB
— DevaOnBreaches (@DevaOnBreaches) August 10, 2025
In May 2025, an unknown hacker breached Columbia University’s network, stealing sensitive personal, financial, and health information of nearly 870,000 individuals, including current and former students, employees, and applicants. The breach was discovered in June after a systems outage, and an investigation revealed that certain files were accessed and stolen. The compromised data includes names, Social Security numbers, academic history, financial aid details, and insurance-related information. Although there is no evidence of misuse, the university is offering two years of free credit monitoring and identity theft services to affected individuals. While the breach did not impact medical records at the Columbia University Irving Medical Center, the university continues to work with external cybersecurity experts to enhance its defenses.