The first month of 2026 looked a lot like the last month of 2025.
Ledger customers exposed through Global-e breach
Customer data was exposed through a breach at Global-e, the payment processor that handles their e-commerce transactions. The compromised data includes customer names, addresses, emails, phone numbers and order information.
Global-e processes payments for a lot of major retailers, so Ledger probably was not the only company affected. ShinyHunters claims to have over 200 million records from multiple Global-e clients.

ShinyHunters, a ransomware group focused on mass data leaks through third-party platforms.
This is the third time Ledger customer information has been leaked since 2020. Each time it happened through a different third-party breach. Ledger might have good security internally, but their customers keep getting exposed because suppliers in the chain get compromised.
If you use payment processors or e-commerce platforms, you should assume that the customer data you send them will eventually leak. Limit what you share and have a response ready for when it happens.
Healthcare ransomware continues
Healthcare providers continued to be heavily targeted throughout January. Several major incidents were disclosed this month:
Covenant Health: Qilin ransomware group took 852GB covering nearly 480,000 patients across multiple states. Social Security numbers, medical histories, treatment records. The attack occurred in May 2025 but was only recently disclosed.
HealthBridge Chiropractic: Hit by Qilin on Jan 6.

Qilin, a ransomware group applying pressure through healthcare disruption.
Apex Spine and Neurosurgery: Over 12GB stolen by Interlock ransomware.

Vulnerability in a Department of Foreign Affairs and Trade website identified and reported through responsible disclosure
Healthcare remains the top ransomware target because downtime directly affects patient care. When systems go offline in a hospital, lives are at risk. That creates massive pressure to pay ransoms quickly. The economics work so the attacks keep coming.
If you’re in healthcare or any sector where downtime creates immediate operational or safety risks, Incident response plans need to account for scenarios where patient care is disrupted.
Looking ahead
The threat landscape heading into February looks the same as it did in December. The same pressures are still present and the same types of organisations still carry the highest risk.
Early in the year is when this exposure is easiest to address. Reviewing what data is shared with vendors and how incidents would be handled is far simpler now than once customers are involved and systems are under strain.



