The Top 5 Data Breaches of July, and What to Do About Them

With a week still on the calendar, July has already put tens of millions of records into criminal hands. Almost none of it involved anyone “hacking” in the movie sense. Attackers logged in with stolen credentials, talked employees out of access, or walked through a vendor’s forgotten door.
Here are the five breaches that mattered most this month, why each one matters to you even if you have never heard of the company, and the proactive steps that keep you off the next list.
The Top 5 Breaches of July
1. Conduent: 62.2 million people. The breach at business services giant Conduent, first disclosed earlier this year, expanded dramatically in July, reporting to more than 62.2 million affected individuals, with Social Security numbers, medical information, and health insurance data among the exposed records. Most victims have never heard of Conduent. That is the point: it processes data on behalf of government agencies and major companies, meaning your information can be breached at a firm you never chose to do business with. (Bright Defense breach tracker)
2. KDDI: 14.2 million email logins across six ISPs. Japanese telecom KDDI disclosed that attackers exploited a third-party software vulnerability in an email platform it operates for five other internet providers, exposing up to 14.22 million email addresses and passwords. Reporting indicates only some of those passwords were hashed. One shared system, six companies’ customers, one point of failure. (Privacy Guides roundup)
3. NYC Health + Hospitals: 1.8 million people, including biometrics. July reporting tied the breach at the nation’s largest public health system to roughly 1.8 million people, with stolen data including medical records, Social Security numbers, banking data, and, most troublingly, fingerprints and palm prints. A password can be rotated. A palm print is yours exactly once. (Bright Defense breach tracker)
4. Panera Bread: millions of customer contact records. Panera confirmed a breach involving customer contact information after millions of records were reportedly released publicly, with Have I Been Pwned analyzing the exposed dataset. Contact records sound harmless until you remember what they fuel: convincing, personalized phishing at scale. (TechRepublic ranking)
5. Aura: 900,000 records via a phone call. An identity protection company was breached when an attacker used voice phishing to compromise a single employee account, accessing roughly 900,000 marketing records tied to a 2021 acquisition. No malware, no zero-day. One convincing phone call to one person. If it can happen to a security company, it can happen anywhere. (TechRepublic ranking)
For the running list beyond these five, TechCrunch’s worst breaches of 2026 and SharkStriker’s July tracker are both worth bookmarking.
The Proactive Habits That Keep You off the Next List
Turn on multi-factor authentication everywhere that matters. If the defining attack of 2026 is logging in with stolen credentials, the defining defense is making a password insufficient on its own. Use an authenticator app or hardware key rather than text-message codes where possible, and start with email, banking, and any account that can reset the others. KDDI’s 14 million exposed passwords are a crisis for accounts without MFA and a non-event for accounts with it.
Use a password manager and retire every reused password. One reused password converts someone else’s breach into a master key for your life. A password manager gives every account a unique, strong credential so a breach anywhere stays contained there. This is the cheapest, highest-return security habit that exists.
Freeze your credit. With Social Security numbers moving in bulk through the Conduent and NYC Health + Hospitals breaches, a credit freeze at all three bureaus turns stolen identity data into a dead end. It is free and takes minutes.
Treat urgency as the red flag. Aura’s breach began with one persuasive phone call. Expect the same play aimed at you, dressed as a breach notification, a bank alert, or an IT reset that references real details about you. Any request pairing urgency with credentials or payment gets verified through a channel you already trust, like calling back on a known number.
Audit continuously, and use the fall as your reset. Exposure is maintenance, not a one-time cleanup. As we head into fall, with kids going back to school, new devices and accounts entering the household, and routines changing, take the moment to reevaluate your cybersecurity health the way you would schedule an annual physical. Run your email through Have I Been Pwned. Search your name and city and file removal requests with the data broker sites that surface. Review what school and activity forms actually require before handing over family data. Then put a recurring block on the calendar and do it again each quarter, because the brokers restock and the breaches keep coming.
July’s five biggest breaches share one lesson: you cannot control whether a company holding your data gets breached, and this month has made clear that companies you have never heard of are holding plenty of it. What you control is whether a breach over there becomes a crisis over here. MFA, unique passwords, a frozen credit file, a verification habit, and a standing audit routine are the difference. Set them up now, because the month is not finished and neither is the list.
At ProAlign, we spend our days doing what bad actors do, except we do it to protect the people, events, and organizations who hire us. We work with live event security teams, venues, and executive protection details to surface the exposures before someone else does.