The Week in Breach News: 05/21/25 – 05/27/25

This week: Ransomware disrupts care in Ohio; human error exposes customer data at an agentic AI firm; luxury retailers face new cyber challenges; and 6 finance-themed phishing resistance videos debut in BullPhish ID.

See the evolution of the MSP business in our infographic 7 Key Stats From the 2025 MSP Benchmark Survey. DOWNLOAD IT>>

U.S.A – Tiffany & Co
https://www.chosun.com/english/industry-en/2025/05/26/ORM5MULB7NEM7EBUFVXHVLSB4A/
Exploit: Hacking
Industry: Retail
Tiffany & Co. has confirmed a cybersecurity breach affecting customers in South Korea, marking the second such incident involving an LVMH Moët Hennessy Louis Vuitton brand in recent months. The breach, which occurred on April 8, involved unauthorized access to a third-party vendor platform used to manage customer information. According to an email notification sent by Tiffany Korea to impacted customers on May 26, the company verified on May 9 that personal data belonging to individuals in South Korea had been compromised. The exposed data includes customer names, addresses, phone numbers, email addresses, internal ID numbers and purchase history.
How It Could Affect Your Customers’ Business: Companies must audit and monitor third-party platforms regularly to ensure data protection measures are up to date.
Kaseya to the Rescue: Learn how Tailored Threat Response with RocketCyber Dynamic Remediation speeds up incident response with automation to minimize damage. GET THE FEATURE SHEET>>
Kettering Health
https://therecord.media/kettering-health-system-ohio-cyberattack
Exploit: Ransomware
Industry: Healthcare
A cyberattack has disrupted hospital operations across Ohio-based Kettering Health, causing widespread outages and delays in patient care at 14 hospitals and more than 100 outpatient facilities. The incident began on May 20 and led to a system-wide technology failure that prevented staff from accessing key patient care systems for five days. As a result, many elective inpatient and outpatient procedures were postponed, and the hospital network’s call center was knocked offline. IT staff reportedly discovered a ransom note identifying the attacker as the Interlock ransomware gang. The healthcare network said it is continuing to investigate the attack and working to restore full functionality while prioritizing patient safety and care.
How It Could Affect Your Customers’ Business: The incident highlights the ongoing threat ransomware poses to critical infrastructure, particularly in the healthcare sector.
Kaseya to the Rescue: Learn proven strategies for mitigating both malicious and accidental insider risk to keep businesses out of trouble in our Guide to Insider Risk. DOWNLOAD IT>>
Cellcom
Exploit: Ransomware
Industry: Telecommunications
Wisconsin-based mobile carrier Cellcom confirmed a cyberattack caused the widespread service outage that began on May 14, disrupting voice and SMS services across Wisconsin and Upper Michigan. Initially attributed to technical issues, the company later acknowledged the cyberattack after an internal investigation. Cellcom assured customers that sensitive personal data was not affected, as the attack targeted a separate part of its network. Data services, iMessage, RCS messaging and 911 remained functional throughout the incident. The company said it is working with external experts, the FBI and state officials to resolve the incident.
How It Could Affect Your Customers’ Business: Organizations must be prepared for cyberattacks that can impact core service delivery, even if customer data is not compromised.
Kaseya to the Rescue: Get tips to strengthen a company’s defenses and bolster its cyber resilience with our Building a Cyber-Resilient Business checklist. GET THE CHECKLIST>>
Serviceaide
https://www.hipaajournal.com/serviceaide-data-breach
Exploit: Misconfiguration
Industry: Business Services

Serviceaide, a San Jose-based IT support provider that leverages agentic AI, reported a major data breach affecting almost 500,000 patients of Catholic Health’s six-hospital system in Buffalo, New York. Serviceaide discovered an Elasticsearch database containing patient electronic protected health information had been publicly accessible without authentication from September 19 to November 5, 2024. The exposed data included sensitive details such as names, dates of birth, Social Security numbers, medical records, insurance, treatment, prescriptions and login credentials. Serviceaide is notifying affected individuals and continuing its investigation.
How it Could Affect Your Customers’ Business: Employee errors can result in expensive and embarrassing disasters for their employers – but training can stop trouble before it starts.
Kaseya to the Rescue: Maximize your security on a lean budget with the insights you’ll find in our infographic 5 Ways to Squeeze More From a Tight Security Budget. DOWNLOAD IT>>

Discover user protection for the modern workforce in our eBook Kaseya 365 User Protection Business Case. GET IT>>

Germany – Adidas
https://www.retail-insight-network.com/news/adidas-cyberattack-data-breach
Exploit: Hacking
Industry: Retail
German sportswear brand Adidas confirmed a data breach involving unauthorized access to consumer contact details through a third-party customer service provider. The company said bad actors snatched contact information of people who had been in touch with its help desk. No sensitive information like passwords or payment data was affected. The company said it quickly contained the incident, launched an investigation with cybersecurity experts and is taking steps to strengthen its data protection. Earlier in May 2025, Adidas disclosed data breaches in its Turkish and South Korean arms.
How it Could Affect Your Customers’ Business: Even when core systems are secure, external vendors can introduce significant security gaps.
Kaseya to the Rescue: Identify the must-have features in a user protection solution and explore how to build a robust user protection strategy in our Modern User Protection Buyer’s Guide. GET IT>>
U.K. – West Lothian Council
https://www.bbc.com/news/articles/cpw77gj8v98o
Exploit: Ransomware
Industry: Government

The West Lothian Council in Scotland confirmed a ransomware attack on its education network, impacting IT systems across 13 secondary schools, 69 primary schools and 61 nurseries. The Interlock group claimed responsibility. While most stolen data appears related to operational matters like lesson planning, officials now believe some personal information may also have been compromised. The council was quick to assure the public that confidential pupil, financial and social work records were not stored in the impacted system. The affected network was quickly isolated, and there is no evidence that other council systems were breached. However, the council warned it has not ruled out the theft of sensitive medical or social work data. Parents, carers and staff are being notified, and Police Scotland is leading the investigation.
How it Could Affect Your Customers’ Business: Schools and councils must treat cybersecurity and ransomware preparedness essential to protecting public services and vulnerable populations.
Kaseya to the Rescue: Discover how Kaseya 365 User delivers comprehensive protection beyond the endpoint without breaking the bank. GET THE EBOOK>>
U.K. – Peter Green Chilled
https://therecord.media/peter-green-chilled-ransomware-uk-logistics-company
Exploit: Hacking
Industry: Transportation & Logistics

Logistics firm Peter Green Chilled has been hit by a ransomware attack, disrupting supplies of refrigerated foodstuffs to several regional supermarkets in Somerset, including Aldi, Tesco and Sainsbury’s. Although the attack occurred two weeks ago, the company informed smaller food producers only late last week that some orders could not be processed due to the cyber incident. Peter Green Chilled said transport operations were unaffected but declined to detail the impact on its IT systems.
How it Could Affect Your Customers’ Business: Supply chain disruptions from cyberattacks can have widespread impact beyond just the targeted company.
Kaseya to the Rescue: Explore the biggest challenges professionals contended with in 2024 and the impact of AI on cybersecurity in the Kaseya Cybersecurity Survey 2024. GET THE REPORT>>

Take a deep dive into why an AI-powered anti-phishing solution is a smart financial choice. GET EBOOK>>


6 new finance-themed phishing training videos for BullPhish ID
Six brand new phishing resistance training kits featuring video lessons in English, Swedish and Portuguese are ready for you to use in your next training campaign.
- Coinbase – Account is Under Review, U.S. English
- Coinbase – New withdrawal, U.S. English
- Nubank – Sua fatura foi fechada, Portuguese
- Nubank – Finalizar cadastro, Portuguese
- Nubank – Atualizacio de dados cadastrais, Portuguese
- IKEA – Du är en av vinnarna, Swedish
Learn more in the BullPhish ID Release Notes.

Learn how to spot today’s most dangerous cyberattack & get defensive tips in Phishing 101 GET EBOOK>>

When trouble strikes, will you be ready?
No business can afford the downtime, lost productivity and other punishing costs of a cyberattack. Learn how to create an incident response plan that will help you minimize expenses and get back to work faster in our eBook How to Build an Incident Response Plan.

Get expert advice for protecting your organization’s most vulnerable gateway in this infographic. DOWNLOAD IT>>

Close the Deal: Using SaaS Security & Dark Web Data to Win Clients
June 4, 2025 | 1:00 PM ET
Differentiating your MSP business can be challenging. Fortunately, there are a few things you can do to stand out from the pack. In this webinar, Kaseya’s Patrick Sullivan and BJ Bateman will show you how to close more deals by using two powerful sales accelerators: SaaS Cybersecurity Assessments and Dark Web Live Data Searches. REGISTER NOW>>
June 3: Mastering IT Risk Management: Leveraging Tools for Comprehensive Security Assessments REGISTER NOW>>
May 30: Kaseya 365 Ops in Action REGISTER NOW>>
June 3: Kaseya+Datto Connect Local: New York City Symposium REGISTER NOW>>
June 17 – 19: Kaseya DattoCon Europe REGISTER NOW>>
July 3: Kaseya+Datto Connect Local: Perth REGISTER NOW>>
July 15: Kaseya+Datto Connect Local: Montreal REGISTER NOW>>
August 28: Kaseya+Datto Connect Local: Brisbane REGISTER NOW>>
September 4: Kaseya+Datto Connect Local: Adelaide REGISTER NOW>>
October 6 – 8: Kaseya DattoCon Miami REGISTER NOW>>
October 28 – 30: Kaseya DattoCon Asia-Pacific REGISTER NOW>>

Do you have comments? Requests? News tips? Complaints (or compliments)? We love to hear from our readers! Send a message to the editor.
Partners: Feel free to reuse this content. When you get a chance, email [email protected] to let us know how our content works for you!

Read our case studies and see how MSPs and businesses have benefited from using our solutions. READ NOW>