The Identity Gap Beyond the Office Desk
13 July 2026A total of 29 breach events were found and analysed resulting in 10,816,710 exposed accounts containing a total of 56 different data types of personal datum. The breaches found publicly and freely available included Sysco Corporation, Moody Bible Institute, Glendale Community College, JCPenney and Fluke Corporation. Sign in to view the full
library of breach events which includes, where available, reference articles relating to
each breach.
Categories of Personal Data Discovered
Communication Logs, Contact, Technology, Geolocation, Sociodemographic, Academic, Career, Audio and Visual, Unstructured, National Identifiers, Relationships, Commerce, Finance, Digital Behaviour, Human Behaviour, Membership.
The signal this week
The 29 breach events analysed this week contained 10,816,710 exposed accounts and 56 distinct types of personal data. The selected organisations operate across campuses, retail stores, distribution networks and industrial environments. This brings attention to a part of identity security that can receive less attention than corporate office accounts: the people who work, study or provide services beyond a conventional desk.Distributed organisations may need to support permanent employees, shift workers, students, contractors, seasonal staff, technicians and external partners. The summary does not establish which of these populations appeared in the individual events, but it provides a useful reason to examine whether identity controls work consistently across every working environment.
What the selected breaches tell us
The selected breaches span food distribution, higher education, retail and industrial technology:- Sysco Corporation supplies food and related products to hospitality, catering and other food-service organisations.
- Moody Bible Institute provides biblical, theological, vocational and online education.
- Glendale Community College is a public higher-education institution serving students completing degrees, transfers, career training and occupational certificates.
- JCPenney operates a large network of physical retail stores alongside its online business.
- Fluke Corporation produces professional test, measurement and monitoring tools used across industrial and technical environments.
The BreachAware team has recorded and reviewed the provenance of this material. The descriptions shared here are intentionally limited, providing defenders with relevant context without publishing source locations, detailed contents or information that could encourage misuse.
What connects these examples is not a single industry. It is their relationship with people working or learning across many locations and roles.
Sysco’s operations support a broad food-service network. JCPenney serves customers through hundreds of stores as well as online. Fluke supplies technicians and engineers through international distribution and service channels. Educational institutions must manage changing populations of applicants, students, staff and alumni.
[Sysco describes its role in food-service distribution](https://www.sysco.co.uk/about-us). [Moody Bible Institute outlines its educational mission and programmes](https://www.moody.edu/about/educational-distinctives/). [Glendale Community College describes the students and communities it serves](https://www.gccaz.edu/about). [JCPenney operates more than 600 stores alongside its online channel](https://corporate.jcpenney.com/about/corporate-information/). [Fluke provides test and measurement products for industrial and technical professionals](https://www.fluke.com/en/support/about-us/corporate-profile).
Why non-desk identities require different thinking
Many identity programmes are designed around an employee with a company laptop, individual email account and regular access to a central office. Those assumptions may not fit every operational environment.People working in stores, warehouses, laboratories, workshops or other shared environments may use handheld devices, kiosks, point-of-sale systems, specialist applications or shared workstations. Students and temporary workers may need access for a defined period, while contractors and technicians may require limited access to particular locations or systems.
These conditions do not inherently make an organisation less secure. They create different design requirements.
For example, an authentication method that works well for an office employee may be impractical for someone wearing protective equipment, moving between customer-facing tasks or using a managed shared device. If the approved process creates too much friction, local workarounds may develop.
The breadth of this week’s material, 56 distinct data types, also shows why identity management cannot be reduced to usernames and passwords. Operational organisations may hold contact, employment, education, customer and service-related records across separate systems. The exact data found differed between events, but the variety makes classification and ownership important.
The problem with shared access
Shared equipment does not require shared identity. When several people use the same account, it becomes difficult to determine who completed an action, whether access should still exist or which credentials need to be revoked after a role change. Passwords may also be written down or passed between shifts because the account belongs to the location rather than an individual.Where shared devices are operationally necessary, each person should still authenticate with an individual identity wherever the technology allows it. Access can then follow the person’s current role, location and employment status.
The same principle applies to students, contractors and temporary staff. Access should have a named owner, a defined purpose and a planned end date. Waiting for a periodic review may leave dormant accounts active long after the relationship has changed.
Three defensive checks
1.Find the identities outside the corporate directory. Include retail, warehouse, campus, laboratory, contractor and specialist-system accounts in access reviews. Document who owns each system and how access is granted and removed.2.
Separate shared devices from shared accounts. Where multiple people use the same equipment, provide individual authentication and role-based permissions. Investigate generic or location-based accounts that prevent actions from being attributed to a person.3.
Test the complete joiner, mover and leaver process. Confirm that a change recorded by HR, student administration or a contractor manager reaches every relevant system. Pay particular attention to temporary access, seasonal roles and people moving between locations.Perspective
The selected examples do not demonstrate that education, retail, distribution or industrial organisations are being targeted more heavily than other sectors. They are not a representative sample from which to calculate an industry trend.The account total should not automatically be interpreted as 10,816,710 unique or currently active people. The material may include duplicate, historical or overlapping records. Similarly, the 56 data types describe the variety found across all 29 events and were not necessarily present in every event or account.
The presence of an organisation with a distributed workforce does not establish that employee records were involved. The exposed information may relate to another population or business process.
The useful conclusion is that identity controls must reflect how people actually work. An organisation should be able to identify, authenticate and remove access for people across every location and role—not only those with a permanent desk and company laptop.
BreachAware does not publish source locations, complete breach inventories or unnecessary operational details that could facilitate misuse.