Unfortunately, techniques to break Monero's anonymity have been known since 2018, and these techniques are effective at breaking essentially any partial-mixing based cryptocurrency. (Monero, Lelantus, CoinJoin, Wasabi, etc).
Initial attacks (famously The Flashlight Attack) were capable of breaking the anonymity of targeted individuals, but this attack was later generalized (by me) to break everyone.
These attacks never got a lot of coverage but they are highly effective. The only way to get strong on-chain privacy is to use a full-anonymity cryptocurrency like Zcash.
https://slideslive.com/38911785/satoshi-has-no-clothes-failu...
https://gist.github.com/DavidVorick/0dbd4906bfa50b7d8dba23f7...
The general idea behind each of these is that you can identify people by doing math that essentially asks "what is the likelihood that these N outputs are this close together in the transaction history graph" - and the answer ends up being "cryptographically unlikely" after just a handful of transactions from the same party. The privacy decays unexpectedly quickly. I never formalized the math but iirc you can get enough evidence to be convinced that two different transactions were by the same person after they spend something like 3 outputs total. The math is really nasty.
The only fix we know of is to switch to full anonymity systems. The privacy break is exponential in strength, and therefore even systems like Lelantus that use mixin sizes of >50,000 outputs fail to provide meaningful anonymity.