SecurityWeek / Ionut Arghire06-20-2026London Hydro investigated in London, Ontario a suspected breach that may have exposed customer personal and account data, while reporting no payment information impact.
Morningstar07-13-2026Schubert Jonckheer & Kolbe LLP is investigating an alleged ShinyHunters breach of Inter-Con in Pasadena, California, affecting about 2.7 million records.
Cincinnati Enquirer06-04-2026Middletown, Ohio, notified residents on June 3 after a late-2025 breach exposed Social Security numbers and medical information, with TransUnion providing credit monitoring.
ClassAction.org06-23-2026Campbell University disclosed a cloud data breach discovered April 1, 2026, exposing personal and medical records and reporting to HHS on May 29.
Claim Depot05-11-2026Healthcare In Action reported a January 2026 credential compromise that exposed PII and protected health information for 1,143 people, with breach notification to HHS in March 2026.
Claim Depot05-15-2026Pivot Health disclosed a March 2026 AWS data breach affecting 1,172 people in Texas and 27 in Nebraska after unauthorized access between Feb. 26 and March 13.
Claim Depot05-27-2026Ermi LLC reported a 2025 employee email breach to California and Vermont regulators after investigation found possible exposure of health records.
Claim Depot05-27-2026Aimbridge Hospitality disclosed a hotel systems data breach to Maine and Vermont authorities after unauthorized access may have occurred in November 2025.
Claim Depot05-27-2026Easy Dynamics Corp. disclosed an employee data breach to Massachusetts regulators on May 19, 2026, exposing Social Security numbers and benefits data.
Claim Depot05-27-2026Interstate Management Company, LLC disclosed unauthorized hotel-system access from Nov. 19 to Nov. 22, 2025, potentially affecting 22,743 U.S. people, with notices sent May 26, 2026.
Claim Depot05-27-2026United Medical Systems disclosed a data breach impacting 485 people, including Massachusetts and Maine residents, with notifications beginning May 20, 2026.
Claim Depot05-29-2026University of Dallas disclosed a data breach on undisclosed date affecting Texas and Vermont residents, potentially exposing sensitive identity, financial, and health information.
Claim Depot05-29-2026Nursa disclosed unauthorized access to clinician profiles on its Murray, Utah platform, exposing names and full dates of birth for 13,168 Washington residents.
Claim Depot06-02-2026ViaQuest Psychiatric & Behavioral Solutions disclosed to HHS on May 8, 2026 a data breach affecting at least 6,420 people with exposure of PII and protected health information.
Claim Depot06-05-2026Gainwell Technologies notified about 22,500 affected individuals in Connecticut after a March 2026 HUSKY provider portal breach using compromised Hartford HealthCare employee credentials.
Claim Depot06-08-2026MasTec notified Maine and South Carolina authorities on June 5, 2026 about a breach affecting 25,220 US residents linked to an August 2025 network intrusion.
Claim Depot06-08-2026DTG Consulting Solutions Inc. disclosed May 2026 breach notice to Massachusetts regulators and Vermont Attorney General and notified affected people May 29, 2026.
Claim Depot06-08-2026CenterWell disclosed a U.S. data breach in notifications to Massachusetts and Texas attorneys general and HHS, affecting 9,651 people including 4,618 Texans.
Claim Depot06-11-2026Liberty Solutions Inc. reported a PHI-related data breach affecting 7,329 U.S. individuals, with HHS filing details but no public specifics on exposed data types or attack dates.
Claim Depot06-11-2026Beusa Energy LLC disclosed a data breach affecting 7,174 U.S. residents, with notifications starting June 10, 2026 from The Woodlands, Texas.
Claim Depot06-17-2026Lifepoint Health disclosed a 2026 vendor-related data breach after compromised account access exposed U.S. vendor employees' personally identifiable information.
Claim Depot06-20-2026One Medical Seniors disclosed a June 13, 2026 ransomware breach of a third-party file-storage archive, after unauthorized access lasting about three days.
Claim Depot06-29-2026MCBS LLC reported a privacy incident involving unauthorized network access between Sept. 22 and Sept. 26, 2025, to the California Attorney General on June 26, 2026.
Claim Depot06-30-2026Cross Resource Group disclosed to Massachusetts officials on June 26, 2026 a May 19, 2026 employee data breach involving Social Security numbers and payroll data.
Claim Depot07-02-2026Yorozu Automotive Tennessee Inc. reported a Oct. 9, 2024 data breach affecting 20,627 U.S. individuals, including exposure of PII and protected health information, with notifications starting June 2, 2026.
Claim Depot07-09-2026Signature Healthcare disclosed a nationwide data breach to the U.S. Department of Health and Human Services on June 5, 2026, while exposed data types remained undisclosed as of June 30, 2026.
Claim Depot07-20-2026Oak Hill confirmed May 13, 2026 that an October 6, 2025 security incident involved unauthorized access to files containing PII and protected health information, with notifications mailed June 30, 2026 in Connecticut.
Claim Depot07-27-2026OnTrac disclosed in July 2026 that unauthorized access to company files exposed personal information of more than 40,000 individuals.
Privacy Guides / Nate Bartram06-19-2026Novo Nordisk, Kodak, Fortinet, Infinite Campus, and Texas government systems disclosed breaches that exposed sensitive personal data and credentials amid ransom demands.
Privacy Guides / Nate Bartram07-24-2026From July 17-23, 2026, multiple organizations disclosed data breaches involving third-party access, privilege escalation, legacy systems, credential-stuffing, and exposed customer and employee data.
SC Media07-27-2026OnTrac reported a March 23 breach after unauthorized access between March 20 and 22 potentially exposed customer personal information in the United States.
MedTech Dive07-02-2026Medtronic notified potentially affected people more than two months after disclosure of an unauthorized cyberattack disclosed earlier, offering credit and dark-web monitoring while reporting no evidence of public internet exposure.
CyberArts07-28-2026Organizations in Turkey, Sweden, and Puerto Rico reported personal-data breaches from July to October 2025, alongside governance updates on ISO 27701.
92.7 WOBM / Shawn Michaels04-17-2026IPPC Inc. reported a September 18 to 19 network intrusion that potentially exposed medical and Social Security data for up to 133,862 people across New Jersey and neighboring states.
LGBTQ Center OC06-08-2026In Rhode Island, a community services center began June 2026 notices after a late-December 2025 incident left files potentially containing health and identity information.
ITCPE Academy07-24-2026Origin Energy confirmed in Australia that stolen customer data followed a hacker claim, with federal authorities and cyber experts investigating while impact counts remain under review.
BenefitsPro / Alan Goforth06-22-2026On June 13, One Medical Senior Health disclosed limited unauthorized access to archived patient records stored in a third-party file system.
Safestate07-09-2026Mount Royal University in Calgary reported a June 17, 2026 data breach after attackers copied shared-drive files, deleted originals, and CMD Organization posted sample data.
GovInfoSecurity07-09-2026A roundup reports breach concealment pressure, a GitHub AI agent flaw enabling private repository leaks, and major U.S. consumer data exposure events in 2025.
Becker's ASC Review / Cameron Cortigiano07-28-2026Multiple U.S. physician practices disclosed data breaches over roughly 100 days, leading to breach notices and class-action settlement exposure.
HookPhish05-27-2026In April 2026, ShinyHunters released data from a Mytheresa extortion attempt after a ransom deadline, exposing 84,000 customers.
Tech Jacks Solutions06-29-2026London Hydro reported a June 20, 2026 data breach in Ontario that exposed customer names, contact details, and billing account numbers.
Tech Jacks Solutions Security Command Center06-04-2026ViaQuest disclosed in Ohio a network server hacking incident in which 6,420 patients and staff had PII and PHI exposed, with HIPAA risk and a 2026 lawsuit investigation.
The National CIO Review / Emily Hill06-18-2026ShinyHunters issued an extortion threat against One Medical in 2023, while One Medical confirmed a limited third-party storage access affecting archived Iora Health records.
Check Point Research06-15-2026University of Nottingham and Novo Nordisk reported privacy-impacting breaches in mid-June as attackers exploited vulnerabilities including CVE-2026-35273 and CVE-2026-50751.
Class Action U06-19-2026Colorado Health Network, Inc. disclosed an unauthorized-access cybersecurity incident and began breach notifications on June 18, 2026, after exposure of patients medical and financial data.
Federman & Sherwood07-28-2026Bridgeway Benefit Technologies LLC investigated unauthorized access from March to May 2026 after a May 18 potential employee email compromise affecting personal information.
TechTarget / Jill Hughes06-16-2026HHS OCR reported that 2026 healthcare breach reports have impacted more than 19 million individuals, with hacking/IT incidents the leading breach type as of June 9, 2026.
Schubert Jonckheer & Kolbe / Matt Foti07-13-2026ShinyHunters claimed a June 2026 breach of Inter-Con Security Systems in Pasadena, California, allegedly exposing 2.7 million records with unconfirmed notification status.
Daily Hodl07-12-2026Medtronic confirmed a breach discovered on April 15, 2026, after unauthorized access to corporate IT systems potentially exposed sensitive health and identity data.
WHBL07-23-2026Origin Energy disclosed an Australian security incident involving unauthorized access and disclosure of customer personal data and partial financial digits, while notifying affected customers.
Federman & Sherwood / Caroline Chesher04-28-2026Federman & Sherwood is investigating a Precipio, Inc. data breach reported to affect 4,952 Texas residents after a Texas Attorney General notification on April 28, 2026.
Federman & Sherwood / Caroline Chesher06-25-2026Stanley Pearlman Enterprises reported a February 2026 network intrusion that exposed names and driver license numbers, with June 2026 notifications to affected individuals in Nebraska.
Federman & Sherwood / Caroline Chesher06-25-2026Federman & Sherwood investigated the AgelessRx data breach reported to the Vermont Attorney General after potential health-record exposure for about five Vermont residents.
Federman & Sherwood / Caroline Chesher07-15-2026Federman & Sherwood investigates an Averhealth Holdings data breach affecting about 858 Vermont residents after unauthorized access to protected health information was reported to the Vermont Attorney General.
Federman & Sherwood / Caroline Chesher07-24-2026Federman & Sherwood investigates a 11th Street Commons data breach reported to the Vermont Attorney General on July 24, 2026.
BeyondMachines06-17-2026Open Arms Care Corporation notified potentially affected individuals starting June 9, 2026 after unauthorized access to its Tennessee email environment occurred between June and August 2025.
Pluang06-30-2026In April 2026, Medtronic reported a breach exposing Social Security numbers and medical data, triggering identity theft concerns and legal investigation by Murphy Law Firm.
Cole & Van Note06-30-2026Cole & Van Note cites Kubota North America Corporation breach notifications on June 30, 2026 for a March 16, 2026 access incident affecting employees.
ABC 6 News / Paul Dunn06-22-2026Xsolis contained a healthcare data breach discovered on Jan. 22, prompting letters to some former Mayo Clinic patients.
McShane & Brady06-17-2026A cybercriminal accessed stored employee communications in a breach reported in notifications sent in letters to 2,027 individuals.
TechCrunch / Zack Whittaker05-28-2025LexisNexis disclosed a data breach affecting over 364,000 consumers after an unknown hacker obtained sensitive personal data via a third-party software development platform.
PR Newswire07-28-2026Edelson Lechtzin LLP investigated potential class action claims tied to a January 28, 2026 Penobscot Valley Hospital network intrusion in Lincoln, Maine.
PR Newswire07-13-2026ShinyHunters claimed a June 19, 2026 breach at Inter-Con Security Systems in Pasadena, California, alleging 2.7 million records stolen and delayed notification through July 13.
PR Newswire07-24-2026Centers Laboratory in New Jersey detected unauthorized access in August 2025 and reportedly began patient notification around July 20, 2026 after data exfiltration.
Kulr805-07-2026Medtronic confirmed a corporate IT breach in April 2026 after ShinyHunters claimed data compromise affecting nine million affiliated individuals, raising privacy and notification concerns.
The HIPAA Journal / Steve Alder09-29-2025Gaylord Specialty Healthcare and Gainwell Technologies report data breaches in December 2024 and July 2025 affecting patients in Connecticut and Medicaid recipients in Georgia due to unauthorized network access.
The HIPAA Journal / Steve Alder01-15-2025Healthcare providers in Virginia, Massachusetts, California, New York, and Ohio reported protected health information exposure from ransomware and unauthorized access incidents during 2023 to 2024.
The HIPAA Journal / Steve Alder10-20-2025Three healthcare entities in California and Massachusetts reported data breaches in 2024 and 2025.
ClassAction.org05-12-2026American Lending Center reported that a July 2025 ransomware attack exposed names, birthdates, and Social Security information for 123,158 people, with notifications sent April 28, 2026.
Privacy Guides06-26-2026Klue-linked supply-chain access, phishing, and internal leaks during 2026 exposed customer and user data for LastPass, Xsolis, Meta, and others.
Yahoo Finance / Ramish Cheema07-12-2026Malwarebytes reported in February 2026 expanded scope of an October 2025 Conduent data breach affecting an estimated 25 million people in the United States.
Fox-IT07-20-2026David Ludlow of NCC Group discusses cybersecurity measures and patient steps after a data breach at a major Australian healthcare provider affects patient information.
Kohl & Cook Law Firm LLC07-20-2026Ohio consumers can receive breach notifications and take protective actions after unauthorized access to personal information triggers notice requirements.
MacRumors07-22-2026Paidwork users faced a reported data breach in which personal and financial data were exposed for more than 23 million users, with an impact-check process provided in the associated report.
Almeida Law Group06-18-2026UBEO Midco LLC disclosed a June 2025 unauthorized-access incident discovered May 13, 2026 in San Antonio, Texas, affecting 3,845 individuals with Social Security and medical data.
Class Action U05-11-2026Charlie Condon Law Firm, LLC disclosed unauthorized access between October 4 and October 6, 2025, potentially exposing data for about 2,975 people and notifying affected individuals starting May 8, 2026.
Class Action U07-01-2026HHS OCR posted a June 16, 2026 breach-portal filing referencing Insight Optical, suggesting a potential HIPAA protected-health-information security incident.
Class Action U / Class Action U07-02-2026Operation PAR, Boley Centers, and Eleos notified individuals in 2026 after discovering a June 2025 unauthorized network intrusion that may have involved patient and employee personal information.
Emery Reddy05-12-2026American Lending Center notified U.S. residents in multiple states after ransomware activity raised concerns about unauthorized access to personal information, with a review completed April 8, 2026.
Emery Reddy / Emery Reddy06-04-2026RXNT reported unauthorized access to personal data between March 1 and March 3, 2026, and started customer notifications in May 2026 while offering credit monitoring services.
Emery Reddy06-08-2026MasTec, Inc. disclosed unauthorized third-party access to part of its network lasting several days in August 2025, with individual notifications starting May 2026.
Emery Reddy07-07-2026Monmouth University notified individuals starting June 30, 2026, after a forensic review found unauthorized access to PII beginning around February 5, 2026.
BlackFog / Rebecca Harpur04-27-2026Capital One, NPD, Jerico Pictures, MGM Resorts, and Moody's illustrate that data breach harm can last years through litigation, contracting losses, credit impacts, and sustained regulatory oversight.