Shadow AI is already using your data. Get the complimentary Gartner® report. Read the report

Breach Report

Data Breach Report: May 2025 Edition

Coinbase, Marks & Spencer, Ascension, Coca-Cola, Adidas and LexisNexis in a single month. The recurring threads were third-party vendors, insiders and outdated software.

PKWARE

By PKWAREProductivity Protected

Share on social media

May 2025 was another hard month for data security. Large data breaches hit firms in finance, retail, healthcare, and tech.

The same three gaps came up again and again: third-party vendors, insider threats, and old software.

Coinbase faced a large extortion attempt tied to overseas support contractors. Marks & Spencer was badly disrupted by a ransomware attack that reports link to IT outsourcing.

Ascension, Coca-Cola, Adidas, and LexisNexis were hit as well. Each case shows how large and complex data breaches have become. Each one also shows why a security plan has to cover vendors.

Coinbase

Coinbase is a leading cryptocurrency exchange, founded in 2012. It serves millions of users around the world. They use it to buy, sell, and store digital assets such as Bitcoin and Ethereum.

In May 2025, Coinbase reported a major data breach. The cause was an insider threat: overseas customer support contractors. Coinbase found the breach after a $20 million extortion demand on May 11, 2025.

The breach exposed user data. It did not touch any funds or cryptographic keys. Costs could reach $400 million, and the case has raised concerns about the security of third-party contractors.

  • Scale of the Breach: The breach affected 69,461 users.
  • Type of Data Exposed: Attackers took names, contact details, partial Social Security numbers, masked banking data, and ID images.
  • Cause of the Breach: Overseas customer support contractors leaked data, starting December 26, 2024.

Official Notification: coinbase.com

Marks & Spencer

Marks & Spencer (M&S) is a British retailer founded in 1884. It is known for its clothing, food, and home products. It runs more than 1,400 stores worldwide.

In May 2025, M&S was hit by a major cyberattack. Reports name the “Scattered Spider” group. The group used DragonForce ransomware to lock virtual machines and steal customer data, and online retail systems were badly disrupted.

Reports also link the breach to weak points at Tata Consultancy Services, the IT outsourcing partner for M&S. The attack is likely to cost £300 million ($400 million) in lost profit. Recovery runs into July 2025.

  • Scale of the Breach: The breach likely affected hundreds of thousands of customers. Exact numbers are not confirmed.
  • Type of Data Exposed: Attackers stole customer data. No payment details or login credentials have been confirmed as taken.
  • Cause of the Breach: A ransomware attack by the “Scattered Spider” group. It used DragonForce malware against virtual machines, and it may have exploited weak points in third-party IT systems.

Notification: corporate.marksandspencer.com

Ascension

Ascension is one of the largest nonprofit healthcare systems in the United States. It runs more than 140 hospitals and 40 senior care facilities across 19 states, with a focus on patient-centered care.

In May 2025, Ascension reported a major data breach that involved third-party vendors. It exposed patient data of the kind used for medical identity theft.

Two things caused it. A former business partner was running out-of-date software. A cloud system run by a third party was also breached.

Hundreds of thousands of people were affected, and the case points to weak vendor security.

  • Scale of the Breach: The breach affected 437,019 patients.
  • Type of Data Exposed: Attackers took protected health information (PHI). It included data that suits medical identity theft and fraud.
  • Cause of the Breach: A former business partner used out-of-date software. Weak points in a third-party vendor’s cloud system also played a part.

Coca-Cola

The Coca-Cola Company is a global drinks giant founded in 1886. It is known for its soft drinks. It sells in more than 200 countries through a wide network of bottlers and distributors.

In May 2025, the Everest ransomware group claimed a data breach at Coca-Cola’s Middle East business. The target was its Dubai bottling partner, Coca-Cola Al Ahlia Beverages Company.

The company ignored the ransom demands. The group then leaked 1,104 files of employee data on dark web forums. Reports of the breach came out on May 22, 2025.

The files held personal and HR data. That raises the risk of identity theft, and it may bring scrutiny from regulators.

  • Scale of the Breach: The leak exposed personal data on 959 employees, mostly in Middle East operations.
  • Type of Data Exposed: Full names, addresses, phone numbers, emails, banking details, salary records, passports, visas, and internal HR files such as admin account records.
  • Cause of the Breach: The Everest ransomware group got into the systems, likely through stolen credentials or third-party weak points, and it targeted a Middle East distributor.

Adidas

Adidas is a German sportswear giant founded in 1949. It is a leading global brand in athletic clothing, footwear, and accessories. It sells in more than 100 countries.

In May 2025, Adidas reported a data breach. Hackers reached consumer data through a third-party customer service provider. The data was contact details for customers who had used its helpdesk.

Reports of the breach came out on May 23, 2025. No financial data was taken. Even so, the exposed details raise the risk of phishing and identity theft.

Adidas is now telling affected customers. It is also working with security experts to look into the breach and limit the harm.

  • Scale of the Breach: Adidas has not given an exact number. Reports suggest the breach may affect 544,395 people, including customers in Turkey.
  • Type of Data Exposed: Mostly names, email addresses, phone numbers, and possibly home addresses and birth dates.
  • Cause of the Breach: Hackers got into the systems of a third-party customer service provider. They used weak points there to reach consumer data.

LexisNexis

LexisNexis Risk Solutions is part of RELX and was founded in 1970. It is a major data broker based in Alpharetta, Georgia. It sells analytics and risk management services to banks, insurers, and law enforcement.

In May 2025, LexisNexis reported a major data breach. Someone had reached its GitHub account without permission.

The company found out on April 1, 2025, after a tip from an unknown third party. The breach itself took place on December 25, 2024.

It exposed personal data on more than 364,000 people. LexisNexis is offering two years of free identity protection and credit monitoring to those affected. It also faces possible class-action suits, and the case has raised concerns about how data brokers guard their data.

  • Scale of the Breach: The breach affected 364,333 people.
  • Type of Data Exposed: Names, phone numbers, email and postal addresses, Social Security numbers, driver’s license numbers, and dates of birth.
  • Cause of the Breach: An outside party reached the data through a compromised LexisNexis GitHub account on a third-party software development platform.
PKWARE

PKWARE

Productivity Protected

PKWARE has been securing sensitive data for over 40 years. We’ve earned the trust of 21 of the 25 largest banks in the U.S. Our team delivers modern, data-centric security solutions organizations can rely on.