Top Data Breaches of December 2025: An Alarming End to a Turbulent Year

December 2025 capped off what has been a year marked by relentless cyberattacks and large-scale data exposures. Across sectors—from retail and education to financial services and telecommunications—multiple organizations disclosed breaches that compromised sensitive personal information, underscoring persistent security gaps and the evolving sophistication of digital threats.

1. Retail Exposure at Petco Reveals Highly Sensitive Data

One of the earliest reported breaches in December involved Petco, the nationwide pet retailer. A configuration error in one of the company’s software systems left files publicly accessible on the internet, exposing deeply sensitive customer information. The leaked data included full names, Social Security numbers, driver’s license numbers, and financial account details such as credit and debit card numbers.

Although the total number of affected individuals remains unclear, notices filed in several U.S. states confirmed that hundreds of customers were impacted. Petco promptly fixed the configuration issue and initiated notifications to affected parties along with identity protection services. This incident highlights how even simple misconfigurations can lead to significant privacy risks.


2. University of Phoenix Suffers Massive Third-Party Breach

Education institutions continued to be a prime target in December when the University of Phoenix disclosed a data breach linked to a third-party service provider. Unauthorized access to vendor-managed systems exposed information tied to students, applicants, and university employees—including full names, dates of birth, Social Security numbers, and internal IDs.

The breach affected approximately 3.5 million individuals, making it one of the largest educational data compromises of the year. While financial and payment card information was not accessed, the sheer volume of sensitive personal data triggered extensive notification and compliance actions. The incident serves as a stark reminder of the critical importance of oversight and robust access controls when working with third-party vendors.


3. Ransomware Forces Pharma Research Firm to Report Data Theft

In the pharmaceutical sector, Inotiv, a research services provider, disclosed a breach following a ransomware attack. Intruders gained unauthorized access to internal systems and extracted personal information, including names, addresses, dates of birth, and Social Security numbers of approximately 9,500 individuals.

Though no payment card or banking data was found in the stolen records, the event caused operational disruptions and required engagement with cybersecurity specialists and law enforcement. Inotiv also offered identity monitoring services to affected individuals as part of its response.


4. Freedom Mobile Reports Customer Data Exposure

Telecommunications provider Freedom Mobile revealed that unauthorized access to one of its internal systems had occurred, linked to a third-party system supporting customer operations. The compromised data included customer names, phone numbers, email addresses, billing addresses, and account identifiers.

While the company did not provide exact figures for the number of impacted customers, the breach triggered widespread notifications and regulatory reporting. Freedom Mobile responded by securing systems, restricting access, and enhancing protective measures. This case further underscores the risks third-party systems can pose when integrated into core business operations.


5. SoundCloud Member Data and Internal Disruption

Music streaming platform SoundCloud disclosed a breach involving unauthorized access to its internal systems. Though the company withheld specific details on the scale of impacted users, it confirmed that member data linked to internal operations had been taken. The incident also disrupted VPN access and prompted significant internal security measures, such as rotating credentials and tightening authentication controls.


6. 700Credit Breach Impacts Millions

Perhaps the most far-reaching breach of the month involved 700Credit, a U.S. credit reporting and verification provider. In this incident, threat actors accessed internal systems storing consumer credit and identity information used by auto dealerships, lenders, and financial partners.

The attack exposed the personal data of at least 5.6 million individuals, including full names, Social Security numbers, dates of birth, and driver’s license numbers. Given the nature of credit data, the potential for identity fraud and financial misuse is considerable. 700Credit’s response included restricting unauthorized access, engaging forensic investigators, and offering credit monitoring services to affected consumers.


Lessons from December’s Breaches

December 2025’s breach disclosures reveal several recurring themes in today’s cybersecurity climate:

  • Misconfigurations and simple errors can have deep consequences—sometimes equal to those of sophisticated attacks.
  • Third-party vendors remain a major weak point, as attackers increasingly target interconnected systems rather than direct infrastructure.
  • Large datasets of personal identifiers (such as Social Security numbers and dates of birth) are consistently targeted for their value on underground markets and ease of facilitating identity fraud.
  • Proactive monitoring and tighter access controls are essential, especially for organizations that manage or rely on critical personal and financial information.

As cybersecurity teams enter 2026, the hard-earned insights from these December breaches should inform stronger defensive strategies, better vendor oversight, and continuous configuration reviews to protect sensitive data in an ever-evolving threat landscape.