Shadow AI is already using your data. Get the complimentary Gartner® report. Read the report

Breach Report

Data Breach Report: February 2025 Edition

Mars Hydro, Genea Fertility, Orange Group, DISA Global, Finastra and Hospital Sisters Health System. From billions of leaked IoT records to ransomware aimed squarely at clinical data.

PKWARE

By PKWAREProductivity Protected

Share on social media

The February 2025 edition of our Data Breach Report highlights some of the most significant cybersecurity incidents affecting organizations across various industries. This month’s breaches reveal critical vulnerabilities in cybersecurity defenses. They range from massive data leaks exposing billions of records to targeted ransomware attacks compromising highly sensitive information. Companies spanning IoT technology, healthcare, telecommunications, financial services, and government contractors have all suffered major security lapses. That puts millions of individuals at risk of identity theft, financial fraud, and privacy violations. In this report, we break down the key details of each breach. That includes the scale of the exposure, the types of data compromised, and the underlying causes that led to these incidents.

Mars Hydro

The Mars Hydro data breach in February 2025 is a significant event. It highlights the vulnerabilities within the Internet of Things (IoT) landscape.

  • Scale of the Breach: A massive 2.7 billion records were exposed in this data breach. That shows the sheer volume of compromised data.
  • Type of Data Exposed: The types of data exposed included very sensitive information such as Wi-Fi passwords, IP addresses, and email addresses. These create severe security risks.
  • Cause of the Breach: The cause of the breach was a misconfigured, non-password-protected database. That reveals a critical failure in basic security measures.

Genea Fertility Clinic

The Genea Fertility Clinic data breach in February 2025 resulted from a sophisticated cyberattack by the “Termite” ransomware gang. This incident compromised highly sensitive patient data. That included personally identifiable information and detailed medical records.

  • Scale of the Breach: Approximately 940.7GB of data was exfiltrated. That shows the significant volume of patient information that was compromised.
  • Type of Data Exposed: The breach exposed highly sensitive data. That included personally identifiable information like names and addresses, and critical medical details such as Medicare numbers, medical histories, and treatment records. It places patients at considerable risk.
  • Cause of the Breach: The initial cause of the breach was the exploitation of a vulnerability within a Citrix server. That allowed the attackers to gain unauthorized access to Genea’s network and patient management systems.

Genea Cyber Incident – Update and Support Resources: genea.com.au

Orange Group

The Orange Group data breach in February 2025 stemmed from a cyberattack executed by the hacker “Rey,” associated with the HellCat ransomware group. This incident primarily affected Orange Romania. It resulted in the exposure of over 600,000 records. Exploiting vulnerabilities in Orange’s systems, the attacker gained unauthorized access and exfiltrated sensitive data. That data included customer and employee information, email addresses, and partial payment card details.

  • Scale of the Breach: Over 600,000 records were exposed, and approximately 6.5GB of data was exfiltrated. That shows a significant compromise of Orange Group’s information.
  • Type of Data Exposed: The types of data exposed included sensitive information such as 380,000+ unique email addresses, source code, invoices, contracts, customer and employee records, and partial payment card details of Romanian customers. These present various risks to those involved.
  • Cause of the Breach: The cause of the breach involved the exploitation of compromised credentials and vulnerabilities within Orange’s Jira software and internal portals. That allowed the attacker unauthorized access to their systems.

DISA Global

The DISA Global Solutions data breach was discovered in April 2024. Notification letters were sent to affected individuals around February 2025, revealing a significant delay. This incident compromised the sensitive personal information of over 3.3 million people. That information included Social Security numbers, financial account details, government-issued IDs, and full names.

  • Scale of the Breach: Over 3.3 million individuals’ personal information was compromised. That indicates a large-scale exposure of sensitive data.
  • Type of Data Exposed: The types of data exposed included highly sensitive information such as Social Security numbers, financial account details, government-issued identification documents, and full names.
  • Cause of the Breach: The cause of the breach was a cyberattack that infiltrated DISA’s systems. Unauthorized access occurred over a prolonged period. That highlights vulnerabilities in their cybersecurity defenses.

Finastra

The Finastra data breach was detected in November 2024, with unauthorized access dating back to October 31st. It involved a compromise of a Secure File Transfer Platform (SFTP) used for technical support. This resulted in the exposure of personal information, including names and financial account details, of individuals whose data was contained within the accessed files. Finastra is a global financial technology company. It conducted an investigation with cybersecurity experts, notified law enforcement, and began notifying affected individuals in February 2025.

  • Scale of the Breach: The breach involved unauthorized access to a Secure File Transfer Platform (SFTP). That indicates a compromise of files containing customer data. The specific number of affected individuals is still being assessed.
  • Type of Data Exposed: The types of data exposed included personal information such as names and financial account information. That poses risks related to financial fraud and identity theft.
  • Cause of the Breach: The cause of the breach was unauthorized access to Finastra’s Secure File Transfer Platform (SFTP) used for technical support. That highlights vulnerabilities in their third-party vendor security.

Hospital Sisters Health System

The Hospital Sisters Health System (HSHS) data breach stemmed from a cyberattack in August 2023. It resulted in the compromise of over 882,000 individuals’ personal and health information. The attack occurred in 2023. But the full scope of individuals affected was released in February 2025.

  • Scale of the Breach: Over 882,000 individuals’ personal and health information was compromised. That represents a significant exposure of sensitive patient data.
  • Type of Data Exposed: The types of data exposed included highly sensitive information such as names, Social Security numbers, medical records, health insurance details, and treatment information.
  • Cause of the Breach: The cause of the breach was a cyberattack that resulted in unauthorized access to HSHS’s network. That indicates vulnerabilities in their cybersecurity defenses which allowed malicious actors to infiltrate their systems.

Data Breach Notification: maine.gov

PowerSchool

The PowerSchool data breach in February 2025 compromised the sensitive information of approximately 62 million students. That makes it a major cybersecurity incident within the education sector. The breach exposed a wide range of highly sensitive data, including grades, medical histories, Social Security numbers, and restraining order details. It raises significant concerns about student privacy and security.

  • Scale of the Breach: Approximately 62 million student records were compromised. That indicates a massive breach affecting a significant portion of the student population.
  • Type of Data Exposed: The types of data exposed included highly sensitive information such as grades, medical histories, Social Security numbers, and restraining order details.
  • Cause of the Breach: The cause of the breach was a cyberattack that exploited vulnerabilities in PowerSchool’s systems.

GrubHub

The GrubHub data breach in February 2025 compromised the personal and financial information of customers, merchants, and drivers, due to a sophisticated cyberattack. The breach exposed customer names, addresses, order histories, merchant financial details, driver information, and partial credit card data. It raises concerns about identity theft and financial fraud.

  • Scale of the Breach: The breach affected a significant number of customers, merchants, and drivers, though the precise number is still being investigated. That indicates a widespread compromise of GrubHub’s user base.
  • Type of Data Exposed: The types of data exposed included customer names, addresses, order histories, merchant financial information, driver personal information, and partial credit card data.
  • Cause of the Breach: The cause of the breach was a sophisticated cyberattack that exploited vulnerabilities in GrubHub’s systems.
PKWARE

PKWARE

Productivity Protected

PKWARE has been securing sensitive data for over 40 years. We’ve earned the trust of 21 of the 25 largest banks in the U.S. Our team delivers modern, data-centric security solutions organizations can rely on.