Breach news · Weekly digest

A quiet week, and why we are telling you anyway

One entry joined the public record in the last seven days. It is American, it is healthcare, and most British readers will not be in it. Here is what it is worth knowing anyway.

An isometric illustration in navy and terracotta on a pale ground: a half-open filing drawer holding a single folder, several sealed envelopes, a small key, a bound ledger, and a sorting tray whose compartments are empty.

We said at the start that if the answer was nothing, we would say nothing. This week the answer is nearly nothing, so this is a short one — and that is the point. A weekly roundup that finds something alarming every single week is not reporting, it is a subscription to anxiety.

What was added

Everything added to the public record in the seven days to 11 September is below. The figure shown is account records, which is not the same as people: one person with three accounts at the same service appears three times. Treat it as the size of the pile, not the size of the crowd.

Nothing was added to the public record in this window, or the catalogue is unavailable as this renders. Either way the full index is on the breach index.

What was in it

The single entry is McKesson, a large American healthcare distributor. The breach itself is dated 21 August; it reached the public record on 10 September, which is a fairly typical three-week gap between an incident and anyone outside being able to check for it.

What makes it worth a paragraph is the field list rather than the size. Alongside names, email addresses and phone numbers, it carries dates of birth, physical addresses and personal health data. No passwords.

  • Dates of birth and home addresses do not expire and cannot be reset. They are also exactly what data brokers buy, which is how a breach stops being an event and becomes a permanent listing.
  • Personal health data is in a different category again — under UK GDPR it is special category data, and it is the sort of detail that makes a scam call convincing rather than merely annoying.
  • No passwords were exposed, so the usual advice does not apply here. We are not going to tell you to change anything you do not need to change.

If you are a UK reader with no American healthcare history, you are almost certainly not in this one. We would rather say that plainly than leave you checking.

The part nobody reports

A breach ends. A data broker does not. Addresses and dates of birth taken from a breach are worth almost nothing to the people who took them and a great deal to firms that aggregate public and semi-public records for resale — which is legal, ongoing, and the reason the same details keep resurfacing years after the company that lost them apologised.

We publish every holder we act against, by name, so you can check whether the list is real rather than take our word for it.

Worth doing in a quiet week

A week with nothing new in it is the best week to deal with something old. Most people's worst exposure is not this week's breach; it is one from 2019 they never acted on.

  • Check your address once. It takes about thirty seconds and needs no password.
  • If anything comes back with a password in it, change it there and everywhere you reused it — regardless of how old the breach is.
  • If you are on the open electoral register, that is a bigger ongoing exposure than most breaches, and opting out is one free email to your council.
Check my addressFree, about thirty seconds, your own address only.

What this is based on

Write back

If something here was wrong, unclear, or you know more than we do, reply to support@nullivo.com. A person reads every one.

We publish some replies on the article. Nothing goes up without you saying yes first, and it appears under a nickname you pick rather than your name — we take out anything that would identify you. The community rules set out what we will and will not print.

Added since this went out

Breach news →