Last Update: 08/01/2026 at 1:00 PM EST

Data Breaches Expose Sensitive Records

Coverage from Morningstar, SecurityWeek, and others

Articles

27

Active Days

94

The Topic

Data Breaches Expose Sensitive Records topic image

Organizations across financial services, education, healthcare, and professional services are disclosing cyber incidents in which attackers accessed or encrypted systems and obtained sensitive personal information. The incidents commonly involve Social Security numbers, financial account data, identity documents, health information, or tax-related records, with some breaches originating in third-party platforms. The disclosures are driving credit-monitoring offers, regulatory notifications, investigations, and legal claims, while the full scope of several incidents remains unresolved.

First Article: 04/18/26

Latest Article: 07/20/26

Summary

  • Reported incidents span credit unions, a community college, a healthcare network, and Ernst & Young, indicating exposure across varied organizational environments.
  • Compromised data frequently includes Social Security numbers, financial account details, payment information, government IDs, and, in some cases, health or tax records.
  • Several incidents involved unauthorized access to third-party or affiliated systems rather than the directly affected organization’s own network.
  • Ransomware and malware were used to encrypt or lock systems in some cases, while other incidents centered on the theft or downloading of files.
  • Organizations are offering one- or two-year credit monitoring and identity-restoration services, while affected individuals face potential fraud and identity-theft risks.
  • Legal responses include a proposed $750,000 AOD Federal Credit Union settlement and investigations into potential claims tied to the Georgia Heritage breach.
  • Affected population counts and the precise information accessed remain incomplete or under investigation for several incidents.

History

07/21/2026

The story is now framed more broadly across financial, education, healthcare, and professional-services breaches, with a clearer emphasis on unresolved scope and the downstream legal/remediation burden. It also adds a proposed settlement and a new law-firm investigation tied to specific incidents.

07/21/2026

The story is now more explicitly centered on vendor- and shared-platform-driven breaches, rather than a looser set of financial-institution disclosures. It also adds a clearer downstream legal outcome, including a settlement in the AOD Federal Credit Union case.

Full History

Featured

Timeline: 94 Days

Apr 18May 9May 23Jun 13Jun 27Jul 18

Additional Articles

⭐⭐⭐⭐⭐

Claim Depot06-23-2026
KH Credit Union disclosed a 2025 Kettering Health network breach after unauthorized access potentially exposed member PII and PHI, reported to Massachusetts in June 2026.
Claim Depot07-18-2026
Ernst & Young reported a 2026 data breach to California and Massachusetts on July 15, to Vermont on July 16, and to Texas on July 17 after unauthorized access to a third-party support platform exposed customer data.
Claim Depot07-20-2026
Community College of Beaver County disclosed on March 9, 2026 a breach tied to unauthorized access from January 16 to March 9 that exposed Social Security and financial account data.
Credit Union Times / Peter Strozniak04-21-2026
Georgia Heritage Federal Credit Union and Alaska Air Group Federal Credit Union notified consumers of ransomware and third-party IT breaches exposing personal and banking information for 53,000+ people.
Credit Union Times / Peter Strozniak05-22-2026
SafePay-linked intrusion at Houston, Texas-based MemberSource Credit Union in June 2025 exposed unencrypted identity and financial data; Texas notified members in May 2026.
Emery Reddy07-17-2026
Ernst & Young filed California and Vermont notices in July 2026 after exposure of Social Security numbers and financial account data during March 28 to April 23, 2026.

⭐⭐⭐

Claim Depot04-18-2026
Georgia Heritage Federal Credit Union disclosed a January 2025 ransomware incident affecting about 43,077 people, with Maine Attorney General filing in April 2026 and consumer notifications starting January 2026.
Claim Depot04-18-2026
Alaska Air Group Federal Credit Union disclosed a March 2026 third-party IT breach, notifying the California and Maine Attorneys General in April 2026.
Claim Depot04-28-2026
Connected Credit Union disclosed a data breach filed with the Vermont Attorney General that exposed Social Security numbers and financial account codes, with timeline details not publicly released.
Claim Depot05-20-2026
Equal Vision Records reported a 2026 unauthorized network breach to Massachusetts regulators and began notifying affected consumers with Cyberscout credit monitoring.
Claim Depot06-03-2026
Educational Employees Credit Union reported to state attorneys general that a limited employee email account compromise on Dec. 15, 2025 may have exposed personal and payment identifiers.
Claim Depot06-05-2026
Corient Services LLC disclosed a March 30, 2026 insider email breach exposing employee data, affecting Texas, Massachusetts, and New Hampshire residents, with notifications dated May 28, 2026.
Claim Depot06-09-2026
OEConnection LLC disclosed a March 2026 server intrusion and state notifications beginning June 8, 2026, after potential exposure of Social Security numbers and financial data.
The CU Daily / Frank Diekmann04-21-2026
Georgia Heritage Financial Credit Union disclosed a ransomware-linked data breach on or around Jan. 25, 2025, affecting 43,077 individuals in Savannah-area operations.
CUToday.info05-25-2026
MemberSource Credit Union notified state attorneys general after unauthorized access exposed unencrypted personal and financial data tied to 22,308 Texas residents, with a June 3, 2025 breach date.
The CUDaily / Frank Diekmann06-24-2026
KH Credit Union reported a vendor network breach affecting member data stored on Kettering Health systems, reported to Massachusetts regulators on June 16, 2026.
Class Action U07-17-2026
Apologia Educational Ministries reported a March 30, 2026 data security incident affecting about 902 people in North Carolina on May 11, 2026, with exposed data categories unknown.
The Business Journal / Gabriel Dillard06-11-2026
EECU discovered December 15, 2025 unauthorized access to an employee email account and notified California members starting May 29, 2026 after identifying exposure of identity and financial data.
PR Newswire06-12-2026
Strategic Education, Inc. reported a 2026 network intrusion between Feb. 23 and Feb. 25 that may have exposed Social Security and passport numbers, leading Edelson Lechtzin LLP to investigate potential class action claims.
Cision PR Newswire06-03-2026
Educational Employees Credit Union investigated an employee email account breach in December 2025 involving sensitive identifiers and financial information, prompting class-action review by Edelson Lechtzin LLP.
ClassAction.org04-20-2026
Georgia Heritage Financial Credit Union disclosed a ransomware-related breach on or around January 25, 2025, affecting 43,077 people in Georgia.
Almeida Law Group06-18-2026
In Dallas, Texas, Ed Bell Investments reported a 2026 breach discovered May 11 and notified June 10, exposing Social Security, financial, and medical data.
Dapeer Law / Valeria Linares06-04-2026
Educational Employees Credit Union disclosed a December 2025 employee email account compromise, with May 2026 notification filings, prompting a potential California class action investigation.
Emery Reddy06-03-2026
Educational Employees Credit Union notified members in May 2026 after an employee email account compromise on December 15, 2025, and offered Kroll identity monitoring services.