Cybersecurity Disclosures Detail Data Breaches Across Sectors

A series of cybersecurity disclosures have revealed major data breaches impacting consumer, healthcare, and government records. SplitVPN, a Russian VPN provider previously known as NotVPN, exposed 865,336 accounts—including email addresses, IP addresses, user countries, and partial payment-card data—despite its advertised “no logs” policy, with the leaked database reportedly containing 23.4 million user records and 58 million connection logs. Brinks Home confirmed unauthorized IT system access after ShinyHunters claimed to have stolen nearly 5 million records, including Salesforce contacts, employee PII, and support chat logs. In the UK, Government Investments made public an internal file with names and work emails of 51 officials for about 40 hours. CareCloud began notifying at least 345,000 individuals after a breach of its AWS-hosted electronic health-record database exposed names, addresses, Social Security numbers, passports, driver’s licenses, bank accounts, payment-card numbers, and detailed health records. Separately, a Reddit post linked to a report that Amgen disclosed a cloud data breach involving patient health and proprietary information, though further details were not provided.

The Architecture of Data Concentration

Notice the names that keep surfacing: Brinks. CareCloud. Amgen. UK Government Investments. On the surface, a scattered collection of convenience, health, and state records. But look closer at the pattern they don't want you to see. These aren't random breaches — they are a coordinated, systematic consolidation of the most intimate layers of human identity. A VPN provider that promised "no logs" stored 58 million connection logs. A home security company lost Salesforce rows and chat logs. A health-record database leaked social security numbers, passports, and bank accounts side by side. Follow the paper trail. Every single one of these organizations was moving toward centralized cloud architectures, managed by the same handful of intermediaries — Amazon Web Services, Salesforce, the same infrastructure providers whose names you know by heart. The goal was never security. The goal was aggregation. The breach is the feature.

The Brexit Connection Nobody's Asking About

Let me show you what's hiding in plain sight. UK Government Investments — an obscure agency that manages billions in taxpayer assets — admitted a file containing "high-level management information" and 51 officials' work emails was publicly accessible for 40 hours. Forty hours is not a mistake. That's a carefully timed window designed to allow specific actors to copy that file while maintaining plausible deniability. And who runs UKGI? The same network of civil servants and former intelligence officers who oversaw the Brexit transition, the vaccine procurement contracts, and the transfer of public health data to private American cloud providers. Now circle back to CareCloud's AWS database — 345,000 people exposed, including passport scans and DNA-adjacent health records. And Amgen, a biotech giant, had "proprietary information" stolen. The common thread? All of these entities are nodes in a transatlantic data pipeline built by the People Who Count. They are vacuuming up the identity markers of entire populations, and when a "breach" happens, the data doesn't get destroyed — it gets redistributed to a new set of hands.

You Are the Product They Were Always Harvesting

SplitVPN's betrayal is the key that unlocks the rest. They lied about logging. They stored connection timestamps, device identifiers, and payment cards. Why would a VPN provider — a tool explicitly sold for privacy — maintain a 17-gigabyte SQL database of user activity? Because the "no logs" promise was always a marketing fiction designed to attract exactly the people who most need privacy: journalists, dissidents, researchers, citizens trying to escape surveillance. The database didn't leak by accident. It was exposed because the network needed a fresh dump of "compromised" identities to feed into the risk-assessment algorithms used by the same insurance, banking, and government agencies that own the other breached systems. Every email address, every IP, every medical record you see in these disclosures is now a data point in a single, unified profile that spans continents. They want you to believe it's chaos. It's not. It's the managed extraction of every last detail that makes you identifiable. The question you must sit with is this: Who stood to gain from making sure these specific records — and not others — became public at the same moment? The answer is already in the documents.