August’s biggest story was not about how fast attackers moved. It was about how long it took anyone to notice.
August’s defining story was not about a sophisticated attack. It was about a breach that happened in March, quietly grew from 345,000 victims to 3.75 million, and only landed in patient mailboxes five months later. The technical incident lasted eight hours; the disclosure process took all summer.
Here is what happened and what it means for your business.
The Breaches
1. CareCloud: 3.75 Million Patients, Five Months to Find Out
CareCloud, a cloud-based EHR and billing platform used by over 45,000 US healthcare providers, confirmed a March breach of its AWS environment ultimately affected 3,756,469 patients. The initial disclosure covered just 345,000 people; the true scope was eleven times larger and took until August to surface.
Stolen data includes Social Security numbers, government IDs, medical records, bank account details, and full credit card numbers including CVV codes for a subset of victims.
How it happened: Unauthorized access to CareCloud’s AWS environment for six days in March. The full scope was not understood for five months after that (which is five months of exposure patients had no way to protect themselves from).
2. RingCentral: 1.6 Million Business Accounts, ShinyHunters Again
RingCentral, used by more than 600,000 businesses globally, disclosed a breach where ShinyHunters claimed 1.6 million accounts were exposed, with names, email addresses, phone numbers, and physical addresses confirmed by Have I Been Pwned. RingCentral is not a consumer app; it is the phone system thousands of companies rely on daily, and the contact data exposed makes targeted vishing attacks considerably more convincing.
How it happened: A social engineering campaign consistent with the vishing pattern ShinyHunters has used across dozens of 2026 incidents. One person. One call. Familiar story by now.
3. IBM’s 2026 Breach Report: The Number Every SMB Should See
IBM’s 2026 Cost of a Data Breach Report put the US average breach cost at $11.5 million. For small businesses, the average cyber insurance claim reached $264,000 while the median small business holds just $12,100 in cash, a 22-to-1 gap between what a breach costs and what most small businesses have on hand to absorb it. Ocean City Radio found out what that gap looks like in practice when a single cyberattack forced the station to shut down permanently in May.
What this means for your business: Cyber insurance, tested backups, and a recovery plan are not optional extras. They are what separates the businesses that survive from the ones that do not.
4. Apollo Global Management: A Major Hedge Fund on the Breach List
Apollo Global Management, one of the largest alternative investment managers in the world with over $600 billion in assets under management, confirmed a cybersecurity incident in August. The full scope is still being assessed.
How it happened: Still under investigation. Apollo has confirmed the incident and is working with external forensic specialists.
5. Critical Infrastructure: Power Grids and Water Systems
UK power infrastructure and Minnesota municipal water systems both faced cyberattacks in August, bringing critical infrastructure back into the conversation months after Iranian-linked groups targeted US water and energy facilities earlier this year. Neither resulted in confirmed service disruption, but both are a reminder that attackers are not limiting themselves to corporate networks.
How it happened: Nation-state actors exploiting internet-exposed industrial control systems, consistent with CISA’s warnings from earlier this year.
Not sure if your business has exposure from any of August’s incidents? → Schedule a free security assessment with Rob.
What August Is Telling Us
CareCloud’s breach happened in March, the initial disclosure covered 345,000 people, and five months later the real number was 3.75 million. The ITRC’s H1 2026 report put it in context: 471 million victim notices in the first half of 2026 alone, with supply chain attacks generating 280 million of those from just 38 initial breaches. The leverage attackers get from a single vendor compromise is not shrinking.
Ask yourself the same three questions we come back to every month:
- Do you know which vendors hold your customer or employee data, and how quickly they would notify you if something went wrong?
- If your business communications platform was breached tonight, what would that mean for your clients?
- Are you actually reading breach notifications your vendors send, or are they going unread?
If any answer is uncertain, that is where to start.
The businesses that don’t get breached aren’t lucky; they are prepared.





