{"id":5179,"date":"2025-12-19T15:40:04","date_gmt":"2025-12-19T15:40:04","guid":{"rendered":"https:\/\/microvibenews.com\/?p=5179"},"modified":"2025-12-19T15:40:04","modified_gmt":"2025-12-19T15:40:04","slug":"hacks-thefts-and-disruption-the-worst-data-breaches-of-2025","status":"publish","type":"post","link":"https:\/\/microvibenews.com\/?p=5179","title":{"rendered":"Hacks, thefts and disruption: The worst data breaches of 2025"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">Every year, TechCrunch looks back at the cybersecurity horrorshows of the past 12 months \u2014 from the biggest data breaches to hacks resulting in weeks of disruption \u2014 to see what we can learn. This year, the data breaches were like nothing we\u2019ve seen before.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Here\u2019s our look back at some of the biggest security incidents of 2025, starting with:<\/p>\n<p class=\"wp-block-paragraph\">The U.S. government remained one of the biggest targets in cyberspace. The year started with a brazen cyberattack by Chinese hackers on the U.S. Treasury, followed by the breaching of several federal agencies, including the <a href=\"https:\/\/techcrunch.com\/2025\/07\/23\/hundreds-of-organizations-breached-by-sharepoint-mass-hacks\/\">agency tasked with safeguarding U.S. nuclear weapons<\/a>, thanks to a SharePoint security flaw. <\/p>\n<p class=\"wp-block-paragraph\">All the while, the Russian hackers were stealing <a href=\"https:\/\/techcrunch.com\/2025\/08\/12\/russian-government-hackers-said-to-be-behind-us-federal-court-filing-system-hack-report\/\">sealed records from the U.S. Courts\u2019 filing system<\/a>, sending alarm bells ringing across the federal judiciary.<\/p>\n<p class=\"wp-block-paragraph\">But nothing quite came as close as DOGE ripping through federal government departments and databases in what became the <a href=\"https:\/\/techcrunch.com\/2025\/02\/07\/doge-biggest-breach-of-united-states-government-data-under-way\/\">biggest raid of U.S. government data in its history<\/a>.<\/p>\n<figure class=\"wp-block-image aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" height=\"453\" width=\"680\" src=\"https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/data-breaches-doge-2217856070.jpg?w=680\" alt=\"Tesla CEO Elon Musk, with a visible black eye, listens as U.S. President Donald Trump speaks to reporters in the Oval Office of the White House on May 30, 2025\" class=\"wp-image-3077706\" style=\"width:1014px;height:auto\" srcset=\"https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/data-breaches-doge-2217856070.jpg 1995w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/data-breaches-doge-2217856070.jpg?resize=150,100 150w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/data-breaches-doge-2217856070.jpg?resize=300,200 300w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/data-breaches-doge-2217856070.jpg?resize=768,512 768w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/data-breaches-doge-2217856070.jpg?resize=680,453 680w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/data-breaches-doge-2217856070.jpg?resize=1200,800 1200w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/data-breaches-doge-2217856070.jpg?resize=1280,853 1280w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/data-breaches-doge-2217856070.jpg?resize=430,287 430w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/data-breaches-doge-2217856070.jpg?resize=720,480 720w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/data-breaches-doge-2217856070.jpg?resize=900,600 900w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/data-breaches-doge-2217856070.jpg?resize=800,533 800w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/data-breaches-doge-2217856070.jpg?resize=1536,1024 1536w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/data-breaches-doge-2217856070.jpg?resize=668,445 668w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/data-breaches-doge-2217856070.jpg?resize=563,375 563w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/data-breaches-doge-2217856070.jpg?resize=926,617 926w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/data-breaches-doge-2217856070.jpg?resize=708,472 708w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/data-breaches-doge-2217856070.jpg?resize=50,33 50w\" sizes=\"auto, (max-width: 680px) 100vw, 680px\"\/><figcaption class=\"wp-element-caption\"><span class=\"wp-element-caption__text\">WASHINGTON, DC \u2013 MAY 30: Tesla CEO Elon Musk, with a visible black eye, listens as U.S. President Donald Trump speaks to reporters in the Oval Office of the White House on May 30, 2025 in Washington, DC.<\/span><span class=\"wp-block-image__credits\"><strong>Image Credits:<\/strong>Kevin Dietsch \/ Getty Images<\/span><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">The Trump administration\u2019s Department of Government Efficiency, or DOGE as it was widely known, led by Elon Musk and his band of private sector lackeys, <a href=\"https:\/\/techcrunch.com\/2025\/03\/17\/doge-staffer-violated-treasury-rules-by-emailing-unencrypted-personal-data\/\">violated federal protocols<\/a> and <a href=\"https:\/\/techcrunch.com\/2025\/07\/15\/doge-staffer-with-access-to-americans-personal-data-leaked-private-xai-api-key\/\">defied common security practices<\/a>. They <a href=\"https:\/\/techcrunch.com\/2025\/08\/26\/doge-uploaded-live-copy-of-social-security-database-to-vulnerable-cloud-server-says-whistleblower\/\">ransacked federal databases of citizens\u2019 data<\/a>, despite warnings of <a href=\"https:\/\/techcrunch.com\/2025\/02\/01\/senator-warns-of-national-security-risks-after-elon-musks-doge-granted-full-access-to-sensitive-treasury-systems\/\">the national security risks<\/a> and conflicts of interests over Musk\u2019s overseas business dealings. Legal experts say that DOGE staffers are \u201cpersonally liable\u201d under U.S. hacking laws, though a court would also have to agree.<\/p>\n<p class=\"wp-block-paragraph\">Musk\u2019s subsequent, very public falling out with President Trump saw the billionaire leave DOGE, and left staffers fearing that <a href=\"https:\/\/techcrunch.com\/2025\/11\/24\/doge-days-are-over-as-trump-disbands-elon-musks-team-of-federal-cost-cutters\/\">they could face federal charges<\/a> without his protection.<\/p>\n<p class=\"wp-block-paragraph\">In late September, senior executives at American corporate giants <a href=\"https:\/\/techcrunch.com\/2025\/10\/09\/dozens-of-organizations-had-data-stolen-in-oracle-linked-hacks\/\">began receiving threatening emails<\/a> from a prolific ransomware and extortion group called Clop. The emails included an attached copy of their personal information \u2014 and a ransom demand for several million dollars not to publish it.<\/p>\n<p class=\"wp-block-paragraph\">Months earlier, the Clop gang had quietly exploited a never-before-seen vulnerability in Oracle\u2019s E-Business software, a suite of applications used for hosting a company\u2019s core business information, such as financial and human resources records, supply chain data, and customer databases. The vulnerability allowed Clop to steal reams of sensitive employee data, including data belonging to executives, from <a href=\"https:\/\/techcrunch.com\/2025\/10\/09\/dozens-of-organizations-had-data-stolen-in-oracle-linked-hacks\/\">dozens of organizations<\/a> that rely on Oracle\u2019s software.<\/p>\n<p class=\"wp-block-paragraph\">Oracle had no idea until it was caught out in October as it was <a href=\"https:\/\/techcrunch.com\/2025\/10\/06\/clop-hackers-caught-exploiting-oracle-zero-day-bug-to-steal-executives-personal-data\/\">scrambling to patch the vulnerability<\/a>. It was too late, though: the hackers had already stolen gobs of data from <a rel=\"nofollow\" href=\"https:\/\/cyberscoop.com\/university-pennsylvania-oracle-e-business-suite-clop-attacks\/\">universities<\/a>, <a rel=\"nofollow\" href=\"https:\/\/www.bartshealth.nhs.uk\/news\/cl0p-cyberattack-update-18178\/\">hospitals and health systems<\/a>, <a rel=\"nofollow\" href=\"https:\/\/cyberscoop.com\/washington-post-oracle-clop-attacks\/\">media organizations<\/a>, and more.<\/p>\n<p class=\"wp-block-paragraph\">This was Clop\u2019s most recent mass-hacking campaign. The group had previously exploited flaws in enterprise file-transfer services, such as <a href=\"https:\/\/techcrunch.com\/2023\/03\/24\/fortra-goanywhere-clop-ransomware\/\">GoAnywhere<\/a>, <a href=\"https:\/\/techcrunch.com\/2023\/06\/05\/microsoft-clop-moveit-hacks-victims\/\">MOVEit<\/a>, and <a href=\"https:\/\/techcrunch.com\/2024\/12\/24\/clop-ransomware-gang-takes-credit-for-latest-mass-hack-that-breached-dozens-of-companies\/\">Cleo Software<\/a>, which tech giants use to share large amounts of information over the internet.<\/p>\n<p class=\"wp-block-paragraph\">Salesforce customers had a rough year after two separate data breaches at downstream tech companies allowed hackers to steal a billion records of customer data stored in Salesforce\u2019s cloud.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Hackers targeted at least two companies, <a href=\"https:\/\/techcrunch.com\/2025\/09\/08\/salesloft-says-drift-customer-data-thefts-linked-to-march-github-account-hack\/\">Salesloft<\/a> and <a href=\"https:\/\/techcrunch.com\/2025\/11\/21\/google-says-hackers-stole-data-from-200-companies-following-gainsight-breach\/\">Gainsight<\/a>, both of which allow their customers to handle and analyze the data that they store in Salesforce.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">By breaching these companies directly, the hackers gained access to all of the data through their customer connections to Salesforce. Some of the largest tech giants had data stolen in the breaches, including Bugcrowd, Cloudflare, Google, Proofpoint, Docusign, GitLab, Linkedin, SonicWall and Verizon.<\/p>\n<p class=\"wp-block-paragraph\">A hacking collective known as Scattered Lapsus$ Hunters, made up of members from different hacking groups, including ShinyHunters, published a <a href=\"https:\/\/techcrunch.com\/2025\/10\/03\/hacking-group-claims-theft-of-1-billion-records-from-salesforce-customer-databases\/\">data leak site advertising the stolen records<\/a> in exchange for a ransom paid by the victims. New victims are still rolling in.<\/p>\n<p class=\"wp-block-paragraph\">Hackers tore through the U.K. retail sector earlier this year, stealing data from <a href=\"https:\/\/techcrunch.com\/2025\/05\/13\/marks-spencer-confirms-customers-personal-data-was-stolen-in-hack\/\">Marks &amp; Spencer<\/a> and at least <a href=\"https:\/\/techcrunch.com\/2025\/07\/16\/uk-retail-giant-co-op-confirms-hackers-stole-all-6-5-million-customer-records\/\">6.5 million customer records from the Co-op<\/a>. The back-to-back hacks sparked outages and disruption across the retailers\u2019 networks, and some grocery shelves went empty as the systems used to support the retailers were knocked out. <a rel=\"nofollow\" href=\"https:\/\/www.bbc.com\/news\/articles\/cpq5w324pd3o\">Luxury store Harrods<\/a> was also later hacked.<\/p>\n<figure class=\"wp-block-image aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" height=\"489\" width=\"680\" src=\"https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/jag-land-rover-2238334107.jpg?w=680\" alt=\"BIRMINGHAM, UNITED KINGDOM - SEPTEMBER 30: An aerial view of JLR signage at the Jaguar Land Rover vehicle manufacturing plant in Castle Bromwich on September 30, 2025 in Birmingham, United Kingdom.\" class=\"wp-image-3077707\" style=\"width:1014px;height:auto\" srcset=\"https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/jag-land-rover-2238334107.jpg 1995w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/jag-land-rover-2238334107.jpg?resize=150,108 150w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/jag-land-rover-2238334107.jpg?resize=300,216 300w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/jag-land-rover-2238334107.jpg?resize=768,552 768w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/jag-land-rover-2238334107.jpg?resize=680,489 680w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/jag-land-rover-2238334107.jpg?resize=1200,863 1200w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/jag-land-rover-2238334107.jpg?resize=1280,920 1280w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/jag-land-rover-2238334107.jpg?resize=430,309 430w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/jag-land-rover-2238334107.jpg?resize=720,518 720w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/jag-land-rover-2238334107.jpg?resize=900,647 900w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/jag-land-rover-2238334107.jpg?resize=800,575 800w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/jag-land-rover-2238334107.jpg?resize=1536,1104 1536w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/jag-land-rover-2238334107.jpg?resize=668,480 668w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/jag-land-rover-2238334107.jpg?resize=522,375 522w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/jag-land-rover-2238334107.jpg?resize=858,617 858w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/jag-land-rover-2238334107.jpg?resize=708,509 708w, https:\/\/techcrunch.com\/wp-content\/uploads\/2025\/12\/jag-land-rover-2238334107.jpg?resize=50,36 50w\" sizes=\"auto, (max-width: 680px) 100vw, 680px\"\/><figcaption class=\"wp-element-caption\"><span class=\"wp-element-caption__text\">An aerial view of JLR signage at the Jaguar Land Rover vehicle manufacturing plant in Castle Bromwich on September 30, 2025 in Birmingham, United Kingdom, following its hack and data breach.<\/span><span class=\"wp-block-image__credits\"><strong>Image Credits:<\/strong>Christopher Furlong \/ Getty Images<\/span><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">But a major cyberattack targeting Jaguar Land Rover, one of the country\u2019s biggest employers, left a dent in the U.K. economy. A September <a href=\"https:\/\/techcrunch.com\/2025\/09\/10\/jaguar-land-rover-says-data-stolen-in-disruptive-cyberattack\/\">hack and data breach<\/a> saw JLR\u2019s car plant <a href=\"https:\/\/techcrunch.com\/2025\/09\/17\/jaguar-land-rover-to-pause-production-for-third-week-due-to-cyberattack\/\">stall production for months<\/a> as the company worked to get its systems back up and running.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The fallout affected JLR\u2019s suppliers across the U.K., some of whom went out of business altogether. The U.K. government ended up <a href=\"https:\/\/techcrunch.com\/2025\/09\/29\/uk-government-bails-out-jaguar-land-rover-with-1-5b-loan-after-hack-disrupts-vehicle-production-for-weeks\/\">guaranteeing a bailout to the tune of \u00a31.5 billion<\/a> to ensure Jaguar Land Rover employees and suppliers got paid during the shutdown. <\/p>\n<p class=\"wp-block-paragraph\">U.K. security experts said the <a rel=\"nofollow\" href=\"https:\/\/www.bbc.com\/news\/articles\/cy9pdld4y81o\">breach was the most economically damaging cyberattack<\/a> to hit the United Kingdom in history, showing that disruption may be more valuable for financially motivated hackers than stolen data.<\/p>\n<p class=\"wp-block-paragraph\">South Korea experienced a major data breach every month this year, and the personal data of millions of its citizens was compromised thanks to security lapses and shoddy data practices at the country\u2019s biggest tech and phone providers.<\/p>\n<p class=\"wp-block-paragraph\">The country\u2019s largest phone company, <a href=\"https:\/\/techcrunch.com\/2025\/05\/08\/a-timeline-of-south-korean-telco-giant-skts-data-breach\/\">SK Telecom, was hacked and 23 million customer records<\/a> were exposed; several cyberattacks were attributed to its hostile North Korean neighbor; and a <a rel=\"nofollow\" href=\"https:\/\/www.govtech.com\/question-of-the-day\/how-much-government-data-was-lost-in-a-data-center-fire-in-south-korea\">massive data center fire<\/a> wiped out years of Korean government data that wasn\u2019t backed up.<\/p>\n<p class=\"wp-block-paragraph\">But the cherry on data breach cake was the months-long theft of some 33 million customers\u2019 personal information from Coupang, the country\u2019s retail giant that some call Asia\u2019s Amazon. The <a href=\"https:\/\/techcrunch.com\/2025\/12\/01\/koreas-coupang-says-data-breach-exposed-nearly-34m-customers-personal-information\/\">data theft began in June<\/a>, but wasn\u2019t detected until November, and ultimately led to the <a href=\"https:\/\/techcrunch.com\/2025\/12\/10\/ceo-of-south-korean-retail-giant-coupang-resigns-after-massive-data-breach\/\">company\u2019s chief executive<\/a> resigning.<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2025\/12\/19\/hacks-thefts-and-disruption-the-worst-data-breaches-of-2025\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Every year, TechCrunch looks b&hellip; <\/p>\n","protected":false},"author":1,"featured_media":5180,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[249],"tags":[2349,1662,2539,2766,4808,1323,2351,1837,4809],"_links":{"self":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/posts\/5179"}],"collection":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5179"}],"version-history":[{"count":0,"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/posts\/5179\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/media\/5180"}],"wp:attachment":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5179"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5179"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5179"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}