---
title: This Month in Data Leaks | August 2025 OpenVPN
description: "What happened this month: Google’s breach, spilled Tea, and other August highlights (plus: how to avoid them)"
image: https://blog.openvpn.net/hubfs/Blog%20Single%20Large%20copy.png
---

- [Blog](https://blog.openvpn.net)
- [Industry News](https://blog.openvpn.net/tag/industry-news)

# This Month in Data Leaks: Google’s Breach, Spilled Tea, and Other August Highlights (Plus: How to Avoid Them)

Aug 25, 2025 •  4 min read

![](https://blog.openvpn.net/hubfs/Blog%20Single%20Large%20copy.png)

Share

- <https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fblog.openvpn.net%2Fdata-leaks-august-2025&title=This%20Month%20in%20Data%20Leaks%3A%20Google%E2%80%99s%20Breach%2C%20Spilled%20Tea%2C%20and%20Other%20August%20Highlights%20%28Plus%3A%20How%20to%20Avoid%20Them%29&summary=What+happened+this+month%3A+Google%E2%80%99s+breach%2C+spilled+Tea%2C+and+other+August+highlights+%28plus%3A+how+to+avoid+them%29&source=>
- <https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fblog.openvpn.net%2Fdata-leaks-august-2025>
- <https://twitter.com/intent/tweet?url=https%3A%2F%2Fblog.openvpn.net%2Fdata-leaks-august-2025&text=This+Month+in+Data+Leaks%3A+Google%E2%80%99s+Breach%2C+Spilled+Tea%2C+and+Other+August+Highlights+%28Plus%3A+How+to+Avoid+Them%29>
- <https://blog.openvpn.net/data-leaks-august-2025>

This Month in Data Leaks | August 2025 OpenVPN

13:16

By Heather Walters

## It's been quite the summer.

From CRM leaks to airline passenger data turbulence, this past month delivered a steady stream of reminders that cybersecurity is still very much a team sport — and sometimes, one with surprising fumbles.

Whether the issue was a misconfigured third-party platform or an overly casual approach to app development, the common thread is clear: access control and visibility matter more than ever.

Here’s a breakdown of what went wrong, what it means for your business, and how to avoid starring in next month’s breach roundup.

### 🚨 Google’s Salesforce Database got hit by ShinyHunters

What happened: [Hackers breached a Salesforce CRM database used by Google](https://techcrunch.com/2025/08/06/google-says-hackers-stole-its-customers-data-in-a-breach-of-its-salesforce-database/), gaining access to internal sales data tied to small and medium businesses. This includes contact info, deal notes, and a fresh reminder that storing everything in one place can go very wrong.

The cause: A third-party platform (Salesforce) with access to sensitive internal data. Likely no network segmentation or Zero Trust guardrails around that data.

Your move:

- Apply Zero Trust access controls to SaaS platforms.
- Isolate sensitive systems with private routing.
- Audit third-party integrations — and monitor them like you would your own infrastructure.

### 🫣 Tea App spills... everything

What happened: The “Tea” app — where users anonymously review men — [accidentally leaked](https://www.npr.org/2025/08/02/nx-s1-5483886/tea-app-breach-hacked-whisper-networks) driver’s licenses, selfies, and private messages. That data quickly showed up on 4chan and X. So much for anonymity.

The cause: A poorly secured storage bucket. Possibly rushed development (“vibe coding,” in the app’s own words). Definitely a lack of secure-by-design thinking.

Your move:

- Avoid the “ship fast, fix security later” mindset.
- Store PII behind encrypted, access-controlled systems.
- Vet vendors and tools — especially AI-powered apps that move fast and break trust.

### 🧑‍💻 PBS leaks internal employee info — via Discord

What happened: Personal info for nearly 4,000 PBS employees [was leaked on a Discord server](https://www.techradar.com/pro/security/pbs-reveals-data-breach-after-company-info-leaked-on-discord) tied to “PBS Kids.” Names, job titles, emails, departments, and supervisors — all now in the wild.

The cause: Informal comms platforms + sensitive info = bad combo. Likely no DLP or monitoring for internal data exposure.

Your move:

- Don’t treat Discord (or Slack, or Teams) as a secure vault.
- Lock down internal data with access policies that follow people, not just devices.
- Monitor traffic for accidental exfiltration — it’s not always malicious.

### ✈️ Air France & KLM customer data takes off

What happened: A breach in a third-party customer service platform exposed names, emails, contact details, and frequent flyer data for 6 million Air France and KLM passengers. No passwords or credit card info, but still a heavy hit to customer trust.

The cause: A vulnerable vendor. Third-party integration without proper segmentation or risk modeling.

Your move:

- Treat third-party platforms as external — because they are.
- Use layered security: private access, device posture checks, and identity-based policies.
- Don’t assume your vendors are doing it right.

### 🎥 Venice Film Festival gets hacked — stars (and staff) affected

What happened: Participant and journalist data from the Venice Film Festival was leaked. Not the worst breach on this list, but still: red carpet, meet red flags.

The cause: No official details, but the takeaway is clear — any organization handling personal data is a target.

Your move:

- Build privacy-first processes, even if you’re not a traditional “tech company.”
- Publish a breach response plan before you need it.
- Segment access to personal data with context-aware rules.

## 🧩 What these breaches have in common

- Over-trusted systems and platforms
- Lack of visibility into third-party risks
- Weak or missing segmentation and access controls

Sound familiar? These are the exact problems Zero Trust was built to solve — and the kind of thing OpenVPN users can actively guard against using our tools.

## 🛡️ How OpenVPN helps you avoid being on this list

- Secure remote access that keeps sensitive systems off the public internet.
- CloudConnexa® can enforce identity, location, and device-based access controls.
- Private routing and segmentation so even if one app gets hit, the rest don’t go down with it.
- Easy integrations with the platforms you already use — but with the security those platforms sometimes forget to include.

## TL;DR

You don’t need a massive budget or an AI-driven threat detection machine to avoid ending up in a breach roundup. You just need:

 

- Strong access controls
- Isolation of critical systems
- A healthy suspicion of your vendors
- And ideally, a VPN solution that knows how to evolve with the threat landscape

 

We happen to know a good one.

[![Get Started](https://no-cache.hubspot.com/cta/default/43411546/86be8315-bc8b-41cd-8936-66cf4d6bf0e7.png)](https://cta-redirect.hubspot.com/cta/redirect/43411546/86be8315-bc8b-41cd-8936-66cf4d6bf0e7)

[Heather Walters](https://blog.openvpn.net/author/heather-walters)

Heather is a writer for OpenVPN.

## Related posts from OpenVPN

### [![LastPass Vulnerability](https://blog.openvpn.net/hubfs/social-suggested-images/simon-abrams-k_T9Zj3SE8k-unsplash%20(1).jpg) Cybersecurity Nov 8, 2019 LastPass Vulnerability](https://blog.openvpn.net/lastpass-vulnerability/)

### [![Secure Your OpenClaw AI Gateway with Access Server](https://blog.openvpn.net/hubfs/social-suggested-images/4%20(2)-2.png) Cybersecurity Mar 26, 2026 Secure Your OpenClaw AI Gateway with Access Server](https://blog.openvpn.net/secure-your-openclaw-ai-gateway-with-access-server)

### [![This Week in Cybersecurity: AI Hacks AI](https://blog.openvpn.net/hubfs/social-suggested-images/3%20(4).png) Cybersecurity Nov 21, 2025 This Week in Cybersecurity: AI Hacks AI](https://blog.openvpn.net/this-week-in-cybersecurity-ai-hacks-ai)

### Subscribe for Blog Updates

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Heather Walters",
    "url" : "https://blog.openvpn.net/author/heather-walters"
  },
  "dateModified" : "2025-08-29T07:24:37.036Z",
  "datePublished" : "2025-08-25T18:51:13.000Z",
  "headline" : "This Month in Data Leaks | August 2025 OpenVPN",
  "image" : [ "https://blog.openvpn.net/hubfs/Blog%20Single%20Large%20copy.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.openvpn.net/data-leaks-august-2025",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.openvpn.net/hubfs/Dark=True%20Medium.png"
    },
    "name" : "OpenVPN"
  }
}
```