Today in Surveillance:

  • Cancer screening records reached the public breach index. Have I Been Pwned added a verified Exact Sciences entry on August 7 covering 10,869,543 email addresses, with dates of birth and personal health data among the exposed fields [1][2].
  • Alcon was added to the same index today. The eye care company's August 9 entry covers 218,395 email addresses of largely corporate contact data, from the same extortion campaign [3].
  • Flock pitched rideshare cars as license plate readers. A presentation for the Georgia Attorney General's office described a dashcam partnership covering 350k Uber, Lyft and delivery devices. Flock says it was never executed [4].
  • Cities dropping Flock are signing with Axon. Local reporting and government documents show a handful of US cities swapped Flock cameras for equivalent Axon systems [5].
  • A Kansas city moved meetings online with no public comment. Emporia went virtual for August 5 and 19 after a resident was arrested for clapping at a data center meeting [6].
  • NHS Tayside is investigating access to a dead child's medical records. The trust places the alleged breach in a working clinical area where staff access patient information [7].
  • Ransomware crews are aiming at middle management. Zscaler ThreatLabz found most victims in one campaign held manager-level titles or above, average age 46 [8].

Cancer Screening Records Land in the Public Breach Index

On August 7 Have I Been Pwned added a verified breach record for Exact Sciences. It lists a breach date of July 15, 2026 and 10,869,543 unique email addresses. The exposed data classes are dates of birth, email addresses, genders, names, personal health data, phone numbers and physical addresses [1].

The index ties the incident to a ShinyHunters extortion campaign in which the group claimed data from the company's cancer diagnostics business and later published it. The addresses belong to customers, patients and healthcare providers. Exact Sciences makes Cologuard, the at-home colorectal cancer screening test [1]. Abbott completed its acquisition of Exact Sciences on March 23, 2026 [9].

Abbott's public notice, quoted in the record, says "some of the impacted files contain personal information and/or personal health information," with fuller detail to follow once its review is complete [1]. The Register reported on August 7 that the intruders got in by calling staff and talking their way to access, and that the group claims far more stolen material than has been confirmed [2].

Here is why this beats a retail breach for damage. A password can be rotated. A record showing that a specific person, at a known address and date of birth, ordered a colorectal cancer screening test cannot be. That inference is permanent, and it now sits in a searchable dataset. The ShinyHunters 2026 breach tracker follows the wider campaign, and the Medtronic breach covers an earlier medical target.

Alcon Joined the Index Today

The most recent addition to Have I Been Pwned, timestamped August 9, is Alcon. The verified record lists a breach date of August 1, 2026 and 218,395 unique email addresses with names, phone numbers and physical addresses. The index calls the fields largely corporate business-to-business contact data and attributes them to the same pay-or-leak campaign that named Exact Sciences [3].

That makes two medical companies indexed from one campaign in three days. The Alcon set is smaller and, on the index's own reading, far less sensitive: business cards rather than patient histories. The harm depends on what the victim was storing.

Flock Pitched Rideshare Dashcams as License Plate Readers

Joseph Cox reported for 404 Media on August 7 that Flock Safety planned to pull license plate data from dashcams already installed in rideshare and delivery vehicles. The evidence is a Flock presentation prepared for the Georgia Office of the Attorney General in August 2025, released through a public records request filed by Jason Hunyar, a resident of Dunwoody, Georgia [4].

The presentation described the reach of the company's Georgia network and added: "Plus Nexar partnership which includes 350k Uber/Lyft and other delivery service devices." Nexar makes consumer dashcams. Flock told 404 Media it "never executed the partnership with Nexar" [4].

Consider what changes if a plan like that is executed. A fixed plate reader sits on a pole. It can be found, photographed, mapped and argued about at a council meeting, which is what the volunteer mapping in the DeFlock project enables. A camera in the windscreen of a car doing airport runs has no location to map and no council to petition.

Cancelling Flock Is Not the Same as Cancelling ALPR

404 Media reported on August 6 that a handful of US cities have removed Flock's automatic license plate reader cameras and immediately replaced them with equivalent systems from Axon, the law enforcement contractor. The reporting draws on local media accounts and government documents from around the country [5].

That is a corrective for anyone reading the cancellation wave as a win. Residents who spent months killing a Flock contract, the pattern tracked in the cancellation wave coverage, may find the same cameras back on the same poles under another logo. The objection was never the brand. It was warrantless plate logging and onward data sharing, and swapping suppliers addresses neither. Axon's role runs through Ring and Axon police access.

Emporia Moved Its Commission Meetings Behind a Screen

Matthew Gault reported for 404 Media on August 7 that Emporia, Kansas has moved city commission meetings online. On July 22, 2026 a resident, Lux Claridge, was arrested at a commission meeting about a proposed data center and charged with disorderly conduct and interference with police, after clapping [6].

Two days before the next meeting, the city announced: "In the interest of public safety, the Emporia City Commission meetings scheduled for Wednesday, August 5, 2026, and Wednesday, August 19, 2026, will be conducted virtually. No public comment period will be provided during either meeting." Mayor Becky Smith said the death threats behind the decision appeared to come from outside the community rather than from local residents [6].

Threats against officials are real and cities have to respond. This response still removes the one venue where residents can object to a data center on the record, and removes it for both meetings rather than the one that prompted the concern. Without public comment, opposition stops existing in the minutes.

NHS Tayside Is Investigating Access to a Dead Child's Records

Connor Jones reported for The Register on August 7 that NHS Tayside is investigating alleged unauthorised access to the medical records of a nine-year-old girl who died on August 3, 2026. Her identity became public on August 7 after a man was charged in connection with her death. The reporting places the incident at Ninewells Hospital in Dundee [7].

The trust said it "is currently investigating the circumstances of an alleged data breach which happened in a working clinical area where staff access patient information," and that any breach would be recorded, investigated and, where appropriate, reported to the Information Commissioner's Office. The Register reported the trust declined to say who accessed the data or what information was involved [7].

Record snooping is the oldest failure mode in health data and the hardest to design out, because the people doing it already hold legitimate credentials. Access logging catches it afterwards; it does not prevent it.

Ransomware Crews Are Profiling Middle Management

Carly Page reported for The Register on August 9 on Zscaler ThreatLabz research into who ransomware operators actually go after. Across 351 victims at 334 organisations in one campaign tracked over a month, nearly two thirds held manager-level titles or above, the average age was 46, and three quarters worked in accounting and finance, sales, operations, HR or marketing. The research frames the shift as one toward business authority rather than technical access: the target is whoever can move an invoice, not whoever holds domain admin. Zscaler also reported blocked ransomware attempts up 146% over the past year, public extortion cases up 70%, and stolen data volume up 92% [8].

That connects back to the first item. The Exact Sciences intrusion reportedly began with a phone call to staff rather than an exploit [2]. Attackers are researching org charts, and the raw material is the professional profile data traded in every breach on this list.

What to Watch

Wednesday, August 19. Emporia's second scheduled virtual commission meeting, announced with no public comment period. Watch whether the commission restores in-person attendance or comment before it [6].

Abbott's follow-up notice. The company said fuller information would come once its review is complete. Individual notifications and an account of which files held health information are the next disclosures to look for [1].

More names in the same campaign. Two companies from one extortion campaign were indexed within three days. Watch the breach index for further additions attributed to it [1][3].

Whether NHS Tayside reports to the ICO. The trust says a breach would be reported where appropriate. Whether a formal report follows is the test of that wording [7].

Fleet-based plate scanning. Flock says the Nexar partnership was never executed, but the pitch shows it sees consumer dashcam fleets as plate-reader infrastructure. Watch for the same idea elsewhere [4].

Sources

  1. Have I Been Pwned - Exact Sciences breach record, added August 7, 2026. https://haveibeenpwned.com/api/v3/breach/ExactSciences
  2. The Register - ShinyHunters called cancer diagnostics biz and tricked staffers into giving them access. Now they've dumped 10.9M email addresses (August 7, 2026). https://www.theregister.com/cyber-crime/2026/08/07/shinyhunters-called-cancer-diagnostics-biz-and-tricked-staffers-into-giving-them-access-now-theyve-dumped-109m-email-addresses/5284857
  3. Have I Been Pwned - Alcon breach record, added August 9, 2026. https://haveibeenpwned.com/api/v3/breach/Alcon
  4. 404 Media, Joseph Cox - Flock Pitched a Plan To Turn Uber and Lyft Drivers Into Roaming Surveillance Vehicles (August 7, 2026). https://www.404media.co/flock-pitched-a-plan-to-turn-uber-and-lyft-drivers-into-roaming-surveillance-vehicles/
  5. 404 Media, Joseph Cox - Cities Are Ditching Flock, Immediately Replacing It With Axon License Plate Readers (August 6, 2026). https://www.404media.co/cities-are-ditching-flock-immediately-replacing-it-with-axon-license-plate-readers/
  6. 404 Media, Matthew Gault - City That Arrested Person for Clapping at Data Center Meeting Moves to Virtual Meetings for 'Public Safety' (August 7, 2026). https://www.404media.co/city-that-arrested-person-for-clapping-at-data-center-meeting-moves-to-virtual-townhalls-for-public-safety/
  7. The Register, Connor Jones - Scot NHS trust probes access to medical records of 9-year-old girl after man arrested on suspicion of murder (August 7, 2026). https://www.theregister.com/security/2026/08/07/nhs-tayside-investigates-breach-concerning-data-of-dead-girl/5284815
  8. The Register, Carly Page - Ransomware gangs skip the CEO, head straight for the 40-something IT manager (August 9, 2026). https://www.theregister.com/security/2026/08/09/ransomware-gangs-skip-the-ceo-head-straight-for-the-40-something-it-manager/5284499
  9. Abbott - Press release archive, recording completion of the Exact Sciences acquisition on March 23, 2026. https://abbott.mediaroom.com/