Recent Breaches
Breaches
2026PowerSchool62.4M stolen62.4M records stolen2026DISA Global Solutions3.3M stolen3.3M records stolen2026Globe Life850K stolen850K records stolen2026Co-operative Group6.5 million members (names, contact details, dates of birth) stolen6.5 million members (names, contact details, dates of birth) records stolen2026HarrodsAttempted intrusion, limited disruption stolenAttempted intrusion, limited disruption records stolen2026Legal Aid Agency (Ministry of Justice)2.1 million applicants (financial, criminal, contact data since 2010) stolen2.1 million applicants (financial, criminal, contact data since 2010) records stolen2026Adidas UKCustomer contact details (subset) stolenCustomer contact details (subset) records stolen2026Peter Green ChilledOrder and logistics data stolenOrder and logistics data records stolen2026Jaguar Land RoverProduction and IT systems disrupted stolenProduction and IT systems disrupted records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin stolenCheck-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026Co-operative Group6.5 million members (names, contact details, dates of birth) stolen6.5 million members (names, contact details, dates of birth) records stolen2026HarrodsAttempted intrusion, limited disruption stolenAttempted intrusion, limited disruption records stolen2026Legal Aid Agency (Ministry of Justice)2.1 million applicants (financial, criminal, contact data since 2010) stolen2.1 million applicants (financial, criminal, contact data since 2010) records stolen2026Adidas UKCustomer contact details (subset) stolenCustomer contact details (subset) records stolen2026Peter Green ChilledOrder and logistics data stolenOrder and logistics data records stolen2026Jaguar Land RoverProduction and IT systems disrupted stolenProduction and IT systems disrupted records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin stolenCheck-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026PowerSchool62.4M stolen62.4M records stolen2026DISA Global Solutions3.3M stolen3.3M records stolen2026Globe Life850K stolen850K records stolen
View All →
Breaking NewsUpdated as information becomes available
Back to Knowledge Vault
Breach AnalysisBreaking18 July 20264 min read

Seven Million Driver Records, Halted Taxis and Agentic Ransomware: What This Week Tells Us About Data Exposure

A single week in July 2026 brought a seven million record insurance breach in the United States, a malware shutdown at Japan's largest taxi operator, mobile network spying against US military personnel, and the first documented agentic ransomware operation. The common thread is data that lived where attackers could reach it.

Mark Fermor

Mark Fermor

Director & Co-Founder, Firevault

Share
Fractured driver licence dissolving into magenta and cyan data streams beside a taxi silhouette, illustrating the week's cybersecurity incidents

Author: Mark Fermor, Director and Co-Founder, Firevault. Analysis of the week ending 17 July 2026, drawing on reporting by PCMag, the Financial Times, Security Affairs, Business Insider and Sysdig.

AssuranceAmerica: close to seven million drivers exposed

The headline breach of the week hit AssuranceAmerica, a motor insurance provider operating across fourteen states in the United States. Attackers walked away with personal data on close to seven million drivers, including contact details, driving licence information, vehicle records and claims history. The scale only became public because Maine's state notification law forced disclosure, a reminder that regulatory transparency is often the only reason customers ever learn what has happened to their information.

For anyone whose data now sits on a criminal forum, the practical exposure is long lived. Licence numbers, vehicle identifiers and claims narratives do not rotate the way a compromised password does. They feed identity fraud, targeted phishing and insurance manipulation for years.

Nihon Kotsu: malware halts Japan's largest taxi fleet

In Tokyo, Japan's largest taxi operator Nihon Kotsu was forced to take booking and dispatch systems offline after a malware infection. Passengers were left without rides while the company worked to contain the incident and understand its origin. Security Affairs carried the full account, including the company's public apology.

The lesson is one Firevault has made before. When operational systems live on the same network as the data attackers want, a security incident becomes a service outage. Customers feel it long before the incident response report is written.

US military phones targeted through SS7

The Financial Times reported that attackers in the Middle East have been probing mobile and advertising technology networks to locate devices belonging to US military personnel stationed in the region. The method involves the long known SS7 signalling flaw, used as a ping to flush out handset locations. Senator Ron Wyden described it as potentially the first use of commercially available data to spy on American personnel during an active conflict.

The uncomfortable truth is that the surveillance economy sells the same signals to everyone. Once mobile location data and advertising identifiers are collected at scale, adversaries can buy or steal what allies collected for marketing.

Jade Puffer: the first agentic ransomware

Researchers at Sysdig, reported by Business Insider, revealed Jade Puffer, believed to be the first documented example of agentic ransomware. A large language model is given the objective, chooses the targets, selects the tooling, executes the intrusion, encrypts what it finds and reports back on progress. The techniques are not new. The automation is.

What used to require a team of operators can now be handed to a model overnight. That changes the economics of ransomware and shortens the time defenders have between initial access and encryption. It also removes the human bottleneck that historically limited how many organisations could be attacked in parallel.

What connects these four stories

Each incident involves data or systems that were reachable from the open internet at the moment attackers chose to act. Insurance records held in a live application. Dispatch systems running on a connected network. Mobile identifiers moving through commercial signalling. Corporate estates waiting for an autonomous agent to knock on the door.

Perimeter controls, detection tooling and incident response all matter. None of them prevent the underlying condition, which is that sensitive data sits online by default and depends on continuous defence to stay private.

The Firevault view

Offline Secure Storage takes the opposite starting position. A vault is physically disconnected outside authorised access periods. There is no session for a remote attacker to hijack, no service to enumerate and no automated agent that can reach the drive when it is powered down. Access is one to one, per user, within defined windows, with sessions that end automatically after 120 minutes.

Agentic ransomware only accelerates a trend we have described for two years. The organisations that fare best are the ones that treat their most sensitive records, keys, evidence, matter files and successor data as offline by default and reconnect them only when a person needs them. Everything else is a race between attacker automation and defender attention.

Practical next steps

For individuals affected by the AssuranceAmerica disclosure, monitor credit files, enable multi factor authentication on financial accounts and be sceptical of any inbound contact referencing your policy. For operators of critical services, assume that connected dispatch, booking and identity systems will be targeted and rehearse the manual fallback. For anyone holding data that would cause harm if exposed, ask a simple question. Does this need to be online right now, or can it live offline until someone actually needs it?

Sources: PCMag UK, Financial Times, Security Affairs, Business Insider, Sysdig research disclosure.

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

Share this article

Breaking News
Breach Analysis18 July 20264 min read

Seven Million Driver Records, Halted Taxis and Agentic Ransomware: What This Week Tells Us About Data Exposure

A single week in July 2026 brought a seven million record insurance breach in the United States, a malware shutdown at Japan's largest taxi operator, mobile network spying against US military personnel, and the first documented agentic ransomware operation. The common thread is data that lived where attackers could reach it.

Seven Million Driver Records, Halted Taxis and Agentic Ransomware: What This Week Tells Us About Data Exposure
Mark Fermor
Published by Mark Fermor, Director & Co-Founder