Last Update: 08/01/2026 at 12:00 PM EST

Large-Scale Personal Data Breaches

Coverage from SecurityWeek, BleepingComputer, and others

Articles

157

Active Days

560

The Topic

Large-Scale Personal Data Breaches topic image

Organizations across the energy, healthcare, medical technology, utility, and education sectors are reporting breaches involving the theft or potential exposure of sensitive personal and account data. Several incidents involve extortion groups, ransom demands, or threats to publish stolen information, while affected organizations investigate scope, notify regulators and individuals, and provide identity-protection services. The incidents show that data compromise can affect large populations even when core operations remain functional, although some attacks also cause service disruption or data loss.

First Article: 01/15/25

Latest Article: 07/28/26

Summary

  • Origin Energy reported unauthorized access affecting about 900,000 current and former customers, while an alleged attacker claimed a larger victim count.
  • Medtronic notified more than 3.8 million people that personal and medical information had been compromised after a ShinyHunters intrusion.
  • Healthcare and education breaches included Social Security, identity, health, passport, and student or employee data.
  • Extortion groups including ShinyHunters, WorldLeaks, and CMD Organization claimed or were linked to several incidents.
  • Attack impacts vary from data theft without reported operational effects to significant service disruption, system wiping, and prolonged recovery.
  • Organizations are relying on external investigators, law-enforcement coordination, regulatory notifications, and credit or identity monitoring for affected individuals.
  • Exact exposure remains uncertain in several cases because investigations, data recovery, and victim identification are incomplete.

History

This topic is new, but as new articles are added to it this area will summarize shifts, changes and expansions of the issues.

Featured

Timeline: 560 Days

2025Jan 1Mar 5May 28Jul 30Oct 22Dec 242026Jan 1Mar 5May 28Jul 30Oct 22Dec 24

Additional Articles

⭐⭐⭐⭐⭐

SecurityWeek / Eduard Kovacs07-13-2026
Centers Laboratory notified US officials in connection with a late-discovered August 2025 breach affecting 542,377 people, after WorldLeaks posted leak and extortion claims.
BleepingComputer / Bill Toulas07-08-2026
Mount Royal University reported a June 17 cyberattack in Calgary involving stolen and deleted H drive data, with exposure uncertainty and response actions including notifications and credit monitoring.
BleepingComputer / Bill Toulas07-23-2026
Origin Energy confirmed a customer data breach in Australia in response to an external threat claim, coordinating with Australian law enforcement and regulators.
BleepingComputer / Bill Toulas07-24-2026
OnTrac disclosed on March 23 detection of a breach affecting files accessed March 20 to 22, and offered CyberScout identity protection to customers.
TechCrunch07-21-2026
Suno suffered a November 2025 cyberattack that exposed data for over 55.3 million people, including partial payment card numbers, without timely user notification.
The Record / Alexander Martin07-20-2026
Craneware notified the FBI and the UK Information Commissioner's Office after a contained network intrusion copied employee and customer partner data in the USA and UK.
The Record / James Reddick07-23-2026
Origin Energy announced a data breach affecting nearly five million customers in Australia, with investigation involving federal agencies after exposure of personal and partial payment data.
Security Boulevard / John Kevin Hao07-02-2026
Medtronic notified customers in 2026 after unauthorized access to corporate IT systems may have exposed Social Security numbers and health-related data, per ShinyHunters extortion claims.
Claim Depot06-22-2026
Colorado Health Network disclosed a data breach to regulators on June 22, 2026 after alleged Tor data posting by threat actor Cephalus on Aug. 28, 2025.
Malay Mail07-03-2026
Singapore Land Authority reported unauthorized access in an IBM-managed cloud testing environment involving STARS and eLodgment systems, exposing data for about 70,000 people.
Help Net Security / Sinisa Markovic07-20-2026
Have I Been Pwned added a reported Paidwork data breach on July 19, alleging exposure for 23.27 million users after a March 2026 intrusion.
OilPrice.com07-27-2026
Origin Energy disclosed in 2024 that about 900,000 Australian customers had personal information accessed after a July 22 incident update and notified regulators.
BleepingComputer / Bill Toulas02-26-2026
ManoMano disclosed in January 2026 a data breach caused by a third-party provider affecting 38 million customers
Claim Depot05-15-2026
Excelas disclosed a May 12, 2026 data breach to Massachusetts and New Hampshire after 2025 unauthorized access may have exposed PII and protected health information.
Claim Depot06-05-2026
C2N Diagnostics LLC disclosed an April 27, 2026 breach notice after unauthorized access to employee email communications exposed patient PII and protected health information affecting about 2,027 people in the United States.
Claim Depot06-25-2026
AgelessRx disclosed help-desk ticket access in April 2026 that exposed patient health and identity data, with consumer notifications starting June 23 and state reporting on June 24.
Claim Depot06-30-2026
Optalis Management Solutions disclosed unauthorized network access from April 2025, affecting financial and health data, and notified Massachusetts regulators in June 2026.
Claim Depot07-15-2026
Firstsource disclosed a healthcare platform programming-error data breach affecting potentially exposed Social Security numbers, reported to Massachusetts on July 15, 2026.
Claim Depot07-20-2026
Unlimited Technology Systems LLC disclosed to the Iowa Attorney General on July 1, 2026 that unauthorized activity in an October 2025 datacenter may have exposed PII and limited PHI, and offered Kroll identity monitoring.
WTVB / Sherin Sunny07-23-2026
Origin Energy disclosed in Australia that an unauthorized access incident exposed some customer identity and partial financial data, with notification and assessment ongoing.
Insurance Business / Roxanne Libatique07-24-2026
Origin Energy disclosed on July 23 a breach involving former employee credentials on a vendor platform, exposing partial payment details, while potential notification and enforcement timelines depend on Australian laws.
Tank Town Media05-18-2026
Edelson Lechtzin LLP offered free consultations in connection with Excelas after Excelas disclosed a 2025-2026 data breach and Massachusetts notification in 2026.
Medical Daily06-08-2026
In 2024, healthcare breaches in the United States exposed over 289 million individuals, with Change Healthcare's cyberattack driving exposure for many Chicago-area providers.
News-Graphic06-13-2026
Kentucky Management Services Organization reported a CRS medical records vendor breach affecting about 500 Kentucky Bariatric Institute patients, with exposure limited to names, medical record numbers, and service dates.
Healthtech Security07-01-2026
Medtronic disclosed a April 2026 patient-data incident involving unauthorized access to corporate IT systems, reporting impacts across Texas, Massachusetts, and Vermont.
Must Share News / Asyiqin Nadzri07-06-2026
Singapore Land Authority said unauthorized access in an IBM-managed cloud test environment may have exposed NRIC numbers and addresses for about 70,000 people.
Seekr07-10-2026
X-Copper Professional Corporation reported a June 8, 2026 hack involving compromised credentials and malware in Canada, potentially exposing customers personal data.
Qrcodepress07-19-2026
Ohio Living detected suspicious network activity on April 17, 2026 and confirmed patient-data exfiltration between April 16-17 in Westerville, Ohio.
Astera Cancer Care07-20-2026
Unlimited Technology Systems, LLC discovered unauthorized datacenter activity on October 19, 2025 and began patient notifications around July 20, 2026 after a potential data exposure.
Napa Valley Register07-24-2026
Centers Laboratory detected suspicious activity in August 2025 and notified 542,377 affected patients around July 20, 2026, prompting privacy litigation claims.
Insurance Business Australia / Roxanne Libatique07-24-2026
Origin Energy addressed regulator engagement after alleged unauthorized access on a vendor platform using a fired former employee credential in Australia, affecting customer data.
Rescana07-05-2026
Medtronic disclosed an April 2026 corporate IT breach that exposed SSNs and health-related data, with notifications starting in late June 2026 after ShinyHunters extortion claims.
Safestate07-13-2026
Centers Lab NJ LLC confirmed a 2025 intrusion in New Jersey affecting 542,377 people after disclosure in July 2026.
WPRI07-16-2026
J. Arthur Trudeau Memorial Center reported Jan. 22 to Jan. 28 data exfiltration after suspicious activity detection on Jan. 29, exposing PII and protected health information.
TechRepublic / Joseph Ofonagoro07-27-2026
Origin Energy confirmed in 2020s reporting that hackers accessed customer data including PII and last-four payment-card identifiers, and began investigation after media notification in Australia.
Tech Jacks Solutions07-25-2026
OnTrac confirmed unauthorized access to its parcel delivery network in the western United States, potentially exposing customer personal information and prompting downstream breach-risk reviews.
Security Affairs / Pierluigi Paganini05-13-2026
OpenLoop Health disclosed in 2026 that hackers accessed systems between January 7 and 8 and exposed telehealth patient personal data of 716,000 people.
Security Affairs / Pierluigi Paganini05-26-2026
On May 20, 2026, Kroll notified The Oncology Institute about vendor-detected unauthorized access tied to patient data after a November 2025 breach disclosure.
Paubox / Mara Ellis06-01-2026
Western Orthopaedics, P.C. disclosed a 113,330-person healthcare data breach after unauthorized network access during September 2025.
Class Action U07-27-2026
AcademyHealth reported a data breach to the Vermont Attorney General on July 27, 2026, involving Social Security and financial account information for at least one Vermont resident.
MLex07-28-2026
Origin Energy reported a cyberattack affecting about 900,000 Australian customers in July, after access to personal information and partial payment details, with criminal investigation ongoing.
Check Point Research06-22-2026
Check Point Research reported 22 June 2026 privacy-relevant breaches affecting a Texas licensing vendor, iRhythm health data, and Salesforce-connected OAuth tokens.
Class Action U06-09-2026
Connecticut DSS and Gainwell disclosed March 2026 unauthorized access to the HUSKY provider portal that used compromised Hartford HealthCare credentials and impacted about 22,500 people.
Class Action U07-18-2026
Fundamental Administrative Services reported a data security incident impacting 13,302 people, disclosed in a Texas Attorney General breach report on August 19, 2025.
Eyewitness News 3 / Zoe Strothers05-22-2026
On March 4, compromised Hartford HealthCare credentials enabled a hacker to access the Connecticut Medicaid provider portal, affecting about 22,500 patients, with notifications mailed starting May 22.
CT News Junkie05-22-2026
Connecticut DSS announced May 22 postal notifications after a March 4 HUSKY provider-portal breach exposed personal information for about 22,500 enrollees.
Turnto10 / Amanda Bang07-16-2026
J. Arthur Trudeau Memorial Center reported suspicious network activity on Jan. 29 that led to unauthorized access to PHI and PII between Jan. 22 and Jan. 28 in Rhode Island.
WTAQ News Talk07-23-2026
Origin Energy reported July 23 unauthorized access and disclosure of some customer personal and partial financial data in Australia.
Federman & Sherwood / Caroline Chesher06-29-2026
Federman & Sherwood investigates INTEGRIS Health after Cerner detected unauthorized third-party access to legacy electronic health record systems affecting Oklahoma patients.
Federman & Sherwood / Caroline Chesher07-24-2026
Federman & Sherwood investigates a Unlimited Technology Systems, LLC data breach reported to the Vermont Attorney General involving unauthorized access to Vermont residents healthcare and identity data.
Rocketnews07-26-2026
Origin Energy disclosed a data breach affecting Australian customers, with Australian cyber and privacy authorities investigating after exposure of personal data and partial financial details.
TechCrunch / Zack Whittaker02-05-2026
Conduent disclosed a January 2025 data breach affecting millions across Texas, Oregon, and other states.
TechCrunch / Zack Whittaker02-24-2026
January 2025 breach at Conduent exposes millions of Americans' personal data nationwide.
AOL.com06-19-2026
Cybernews researchers reported a temporarily misconfigured Elasticsearch database publicly exposed 24 billion records with plaintext passwords and login URLs.
PR Newswire07-20-2026
Unlimited Technology Systems disclosed a 2025 breach involving unauthorized access to patient files, with potential PII and PHI exposure and Iowa Attorney General notification submitted in 2026.
The HIPAA Journal / Steve Alder01-02-2026
HHS OCR listings show nearly 57 million individuals affected by healthcare data breaches in 2025, with major vendor and ransomware incidents reported across the United States.
Hexnode / Sophia Hart07-28-2026
OnTrac disclosed on March 23, 2026 that unauthorized access occurred March 20 to March 22, with possible exposure of customer personal information and planned notifications.
AOL05-02-2026
Conduent Business Services notified over 25 million Americans after ransomware operators accessed sensitive benefit and HR records from October 2024 to January 2025.
Rescana07-28-2026
Origin Energy confirmed on 28 July 2026 that unauthorized access and exfiltration exposed personal data for about 900,000 customers, with Australian authorities investigating.
Rescana07-13-2026
Centers Laboratory disclosed a 2025 breach affecting about 540,000 people in Cedar Knolls, New Jersey, after unauthorized access exposed health and identity records.
Cybersecurity Insiders / Yair Cohen07-26-2026
OpenLoop Health confirmed a breach affecting over 716,000 patients across 120 healthcare organizations after an unauthorized session exposed regulated patient records.
Security Boulevard / Tanuj Mitra07-01-2026
ColorTokens threat advisory reports ransomware and healthcare data exposures tied to stolen credentials, identity vulnerabilities, and third-party application access in the 2020s.
Mass.gov07-16-2026
Firstsource notified individuals in response to a potential programming-error platform incident involving protected health information and standalone Social Security numbers.
Schubert Jonckheer & Kolbe / Nelida Almeida02-17-2026
Patients and health care providers affected by a data breach at TriZetto Provider Solutions between November 2024 and October 2 2025 in the United States.
Emery Reddy07-15-2026
WP Company LLC disclosed a July 10, 2025 breach with Vermont and Texas notices filed in July 2026, exposing Social Security, government ID, financial, and health insurance data.
Fox News02-22-2026
Conduent reports massive data breach in 2025 affecting tens of millions across multiple states.
Fox News10-24-2025
SimonMed Imaging data breach reveals exposure of patient data in the United States between January and February 2025.
Cory Watson Attorneys / Patrick Nolen05-21-2026
SafePay claimed responsibility in a months-long ransomware intrusion against Conduent Business Services, allegedly exposing Tennessee residents medical and identity data and prompting class actions.
Data Trust Cadence07-04-2026
IBM and the Singapore Land Authority incident compromised personal information for about 70,000 people, with June discovery and legacy retention issues driving exposure.

⭐⭐⭐

SecurityWeek / Ionut Arghire06-20-2026
London Hydro investigated in London, Ontario a suspected breach that may have exposed customer personal and account data, while reporting no payment information impact.
Morningstar07-13-2026
Schubert Jonckheer & Kolbe LLP is investigating an alleged ShinyHunters breach of Inter-Con in Pasadena, California, affecting about 2.7 million records.
Cincinnati Enquirer06-04-2026
Middletown, Ohio, notified residents on June 3 after a late-2025 breach exposed Social Security numbers and medical information, with TransUnion providing credit monitoring.
ClassAction.org06-23-2026
Campbell University disclosed a cloud data breach discovered April 1, 2026, exposing personal and medical records and reporting to HHS on May 29.
Claim Depot05-11-2026
Healthcare In Action reported a January 2026 credential compromise that exposed PII and protected health information for 1,143 people, with breach notification to HHS in March 2026.
Claim Depot05-15-2026
Pivot Health disclosed a March 2026 AWS data breach affecting 1,172 people in Texas and 27 in Nebraska after unauthorized access between Feb. 26 and March 13.
Claim Depot05-27-2026
Ermi LLC reported a 2025 employee email breach to California and Vermont regulators after investigation found possible exposure of health records.
Claim Depot05-27-2026
Aimbridge Hospitality disclosed a hotel systems data breach to Maine and Vermont authorities after unauthorized access may have occurred in November 2025.
Claim Depot05-27-2026
Easy Dynamics Corp. disclosed an employee data breach to Massachusetts regulators on May 19, 2026, exposing Social Security numbers and benefits data.
Claim Depot05-27-2026
Interstate Management Company, LLC disclosed unauthorized hotel-system access from Nov. 19 to Nov. 22, 2025, potentially affecting 22,743 U.S. people, with notices sent May 26, 2026.
Claim Depot05-27-2026
United Medical Systems disclosed a data breach impacting 485 people, including Massachusetts and Maine residents, with notifications beginning May 20, 2026.
Claim Depot05-29-2026
University of Dallas disclosed a data breach on undisclosed date affecting Texas and Vermont residents, potentially exposing sensitive identity, financial, and health information.
Claim Depot05-29-2026
Nursa disclosed unauthorized access to clinician profiles on its Murray, Utah platform, exposing names and full dates of birth for 13,168 Washington residents.
Claim Depot06-02-2026
ViaQuest Psychiatric & Behavioral Solutions disclosed to HHS on May 8, 2026 a data breach affecting at least 6,420 people with exposure of PII and protected health information.
Claim Depot06-05-2026
Gainwell Technologies notified about 22,500 affected individuals in Connecticut after a March 2026 HUSKY provider portal breach using compromised Hartford HealthCare employee credentials.
Claim Depot06-08-2026
MasTec notified Maine and South Carolina authorities on June 5, 2026 about a breach affecting 25,220 US residents linked to an August 2025 network intrusion.
Claim Depot06-08-2026
DTG Consulting Solutions Inc. disclosed May 2026 breach notice to Massachusetts regulators and Vermont Attorney General and notified affected people May 29, 2026.
Claim Depot06-08-2026
CenterWell disclosed a U.S. data breach in notifications to Massachusetts and Texas attorneys general and HHS, affecting 9,651 people including 4,618 Texans.
Claim Depot06-11-2026
Liberty Solutions Inc. reported a PHI-related data breach affecting 7,329 U.S. individuals, with HHS filing details but no public specifics on exposed data types or attack dates.
Claim Depot06-11-2026
Beusa Energy LLC disclosed a data breach affecting 7,174 U.S. residents, with notifications starting June 10, 2026 from The Woodlands, Texas.
Claim Depot06-17-2026
Lifepoint Health disclosed a 2026 vendor-related data breach after compromised account access exposed U.S. vendor employees' personally identifiable information.
Claim Depot06-20-2026
One Medical Seniors disclosed a June 13, 2026 ransomware breach of a third-party file-storage archive, after unauthorized access lasting about three days.
Claim Depot06-29-2026
MCBS LLC reported a privacy incident involving unauthorized network access between Sept. 22 and Sept. 26, 2025, to the California Attorney General on June 26, 2026.
Claim Depot06-30-2026
Cross Resource Group disclosed to Massachusetts officials on June 26, 2026 a May 19, 2026 employee data breach involving Social Security numbers and payroll data.
Claim Depot07-02-2026
Yorozu Automotive Tennessee Inc. reported a Oct. 9, 2024 data breach affecting 20,627 U.S. individuals, including exposure of PII and protected health information, with notifications starting June 2, 2026.
Claim Depot07-09-2026
Signature Healthcare disclosed a nationwide data breach to the U.S. Department of Health and Human Services on June 5, 2026, while exposed data types remained undisclosed as of June 30, 2026.
Claim Depot07-20-2026
Oak Hill confirmed May 13, 2026 that an October 6, 2025 security incident involved unauthorized access to files containing PII and protected health information, with notifications mailed June 30, 2026 in Connecticut.
Claim Depot07-27-2026
OnTrac disclosed in July 2026 that unauthorized access to company files exposed personal information of more than 40,000 individuals.
Privacy Guides / Nate Bartram06-19-2026
Novo Nordisk, Kodak, Fortinet, Infinite Campus, and Texas government systems disclosed breaches that exposed sensitive personal data and credentials amid ransom demands.
Privacy Guides / Nate Bartram07-24-2026
From July 17-23, 2026, multiple organizations disclosed data breaches involving third-party access, privilege escalation, legacy systems, credential-stuffing, and exposed customer and employee data.
SC Media07-27-2026
OnTrac reported a March 23 breach after unauthorized access between March 20 and 22 potentially exposed customer personal information in the United States.
MedTech Dive07-02-2026
Medtronic notified potentially affected people more than two months after disclosure of an unauthorized cyberattack disclosed earlier, offering credit and dark-web monitoring while reporting no evidence of public internet exposure.
CyberArts07-28-2026
Organizations in Turkey, Sweden, and Puerto Rico reported personal-data breaches from July to October 2025, alongside governance updates on ISO 27701.
92.7 WOBM / Shawn Michaels04-17-2026
IPPC Inc. reported a September 18 to 19 network intrusion that potentially exposed medical and Social Security data for up to 133,862 people across New Jersey and neighboring states.
LGBTQ Center OC06-08-2026
In Rhode Island, a community services center began June 2026 notices after a late-December 2025 incident left files potentially containing health and identity information.
ITCPE Academy07-24-2026
Origin Energy confirmed in Australia that stolen customer data followed a hacker claim, with federal authorities and cyber experts investigating while impact counts remain under review.
BenefitsPro / Alan Goforth06-22-2026
On June 13, One Medical Senior Health disclosed limited unauthorized access to archived patient records stored in a third-party file system.
Safestate07-09-2026
Mount Royal University in Calgary reported a June 17, 2026 data breach after attackers copied shared-drive files, deleted originals, and CMD Organization posted sample data.
GovInfoSecurity07-09-2026
A roundup reports breach concealment pressure, a GitHub AI agent flaw enabling private repository leaks, and major U.S. consumer data exposure events in 2025.
Becker's ASC Review / Cameron Cortigiano07-28-2026
Multiple U.S. physician practices disclosed data breaches over roughly 100 days, leading to breach notices and class-action settlement exposure.
HookPhish05-27-2026
In April 2026, ShinyHunters released data from a Mytheresa extortion attempt after a ransom deadline, exposing 84,000 customers.
Tech Jacks Solutions06-29-2026
London Hydro reported a June 20, 2026 data breach in Ontario that exposed customer names, contact details, and billing account numbers.
Tech Jacks Solutions Security Command Center06-04-2026
ViaQuest disclosed in Ohio a network server hacking incident in which 6,420 patients and staff had PII and PHI exposed, with HIPAA risk and a 2026 lawsuit investigation.
The National CIO Review / Emily Hill06-18-2026
ShinyHunters issued an extortion threat against One Medical in 2023, while One Medical confirmed a limited third-party storage access affecting archived Iora Health records.
Check Point Research06-15-2026
University of Nottingham and Novo Nordisk reported privacy-impacting breaches in mid-June as attackers exploited vulnerabilities including CVE-2026-35273 and CVE-2026-50751.
Class Action U06-19-2026
Colorado Health Network, Inc. disclosed an unauthorized-access cybersecurity incident and began breach notifications on June 18, 2026, after exposure of patients medical and financial data.
Federman & Sherwood07-28-2026
Bridgeway Benefit Technologies LLC investigated unauthorized access from March to May 2026 after a May 18 potential employee email compromise affecting personal information.
TechTarget / Jill Hughes06-16-2026
HHS OCR reported that 2026 healthcare breach reports have impacted more than 19 million individuals, with hacking/IT incidents the leading breach type as of June 9, 2026.
Schubert Jonckheer & Kolbe / Matt Foti07-13-2026
ShinyHunters claimed a June 2026 breach of Inter-Con Security Systems in Pasadena, California, allegedly exposing 2.7 million records with unconfirmed notification status.
Daily Hodl07-12-2026
Medtronic confirmed a breach discovered on April 15, 2026, after unauthorized access to corporate IT systems potentially exposed sensitive health and identity data.
WHBL07-23-2026
Origin Energy disclosed an Australian security incident involving unauthorized access and disclosure of customer personal data and partial financial digits, while notifying affected customers.
Federman & Sherwood / Caroline Chesher04-28-2026
Federman & Sherwood is investigating a Precipio, Inc. data breach reported to affect 4,952 Texas residents after a Texas Attorney General notification on April 28, 2026.
Federman & Sherwood / Caroline Chesher06-25-2026
Stanley Pearlman Enterprises reported a February 2026 network intrusion that exposed names and driver license numbers, with June 2026 notifications to affected individuals in Nebraska.
Federman & Sherwood / Caroline Chesher06-25-2026
Federman & Sherwood investigated the AgelessRx data breach reported to the Vermont Attorney General after potential health-record exposure for about five Vermont residents.
Federman & Sherwood / Caroline Chesher07-15-2026
Federman & Sherwood investigates an Averhealth Holdings data breach affecting about 858 Vermont residents after unauthorized access to protected health information was reported to the Vermont Attorney General.
Federman & Sherwood / Caroline Chesher07-24-2026
Federman & Sherwood investigates a 11th Street Commons data breach reported to the Vermont Attorney General on July 24, 2026.
BeyondMachines06-17-2026
Open Arms Care Corporation notified potentially affected individuals starting June 9, 2026 after unauthorized access to its Tennessee email environment occurred between June and August 2025.
Pluang06-30-2026
In April 2026, Medtronic reported a breach exposing Social Security numbers and medical data, triggering identity theft concerns and legal investigation by Murphy Law Firm.
Cole & Van Note06-30-2026
Cole & Van Note cites Kubota North America Corporation breach notifications on June 30, 2026 for a March 16, 2026 access incident affecting employees.
ABC 6 News / Paul Dunn06-22-2026
Xsolis contained a healthcare data breach discovered on Jan. 22, prompting letters to some former Mayo Clinic patients.
McShane & Brady06-17-2026
A cybercriminal accessed stored employee communications in a breach reported in notifications sent in letters to 2,027 individuals.
TechCrunch / Zack Whittaker05-28-2025
LexisNexis disclosed a data breach affecting over 364,000 consumers after an unknown hacker obtained sensitive personal data via a third-party software development platform.
PR Newswire07-28-2026
Edelson Lechtzin LLP investigated potential class action claims tied to a January 28, 2026 Penobscot Valley Hospital network intrusion in Lincoln, Maine.
PR Newswire07-13-2026
ShinyHunters claimed a June 19, 2026 breach at Inter-Con Security Systems in Pasadena, California, alleging 2.7 million records stolen and delayed notification through July 13.
PR Newswire07-24-2026
Centers Laboratory in New Jersey detected unauthorized access in August 2025 and reportedly began patient notification around July 20, 2026 after data exfiltration.
Kulr805-07-2026
Medtronic confirmed a corporate IT breach in April 2026 after ShinyHunters claimed data compromise affecting nine million affiliated individuals, raising privacy and notification concerns.
The HIPAA Journal / Steve Alder09-29-2025
Gaylord Specialty Healthcare and Gainwell Technologies report data breaches in December 2024 and July 2025 affecting patients in Connecticut and Medicaid recipients in Georgia due to unauthorized network access.
The HIPAA Journal / Steve Alder01-15-2025
Healthcare providers in Virginia, Massachusetts, California, New York, and Ohio reported protected health information exposure from ransomware and unauthorized access incidents during 2023 to 2024.
The HIPAA Journal / Steve Alder10-20-2025
Three healthcare entities in California and Massachusetts reported data breaches in 2024 and 2025.
ClassAction.org05-12-2026
American Lending Center reported that a July 2025 ransomware attack exposed names, birthdates, and Social Security information for 123,158 people, with notifications sent April 28, 2026.
Privacy Guides06-26-2026
Klue-linked supply-chain access, phishing, and internal leaks during 2026 exposed customer and user data for LastPass, Xsolis, Meta, and others.
Yahoo Finance / Ramish Cheema07-12-2026
Malwarebytes reported in February 2026 expanded scope of an October 2025 Conduent data breach affecting an estimated 25 million people in the United States.
Fox-IT07-20-2026
David Ludlow of NCC Group discusses cybersecurity measures and patient steps after a data breach at a major Australian healthcare provider affects patient information.
Kohl & Cook Law Firm LLC07-20-2026
Ohio consumers can receive breach notifications and take protective actions after unauthorized access to personal information triggers notice requirements.
MacRumors07-22-2026
Paidwork users faced a reported data breach in which personal and financial data were exposed for more than 23 million users, with an impact-check process provided in the associated report.
Almeida Law Group06-18-2026
UBEO Midco LLC disclosed a June 2025 unauthorized-access incident discovered May 13, 2026 in San Antonio, Texas, affecting 3,845 individuals with Social Security and medical data.
Class Action U05-11-2026
Charlie Condon Law Firm, LLC disclosed unauthorized access between October 4 and October 6, 2025, potentially exposing data for about 2,975 people and notifying affected individuals starting May 8, 2026.
Class Action U07-01-2026
HHS OCR posted a June 16, 2026 breach-portal filing referencing Insight Optical, suggesting a potential HIPAA protected-health-information security incident.
Class Action U / Class Action U07-02-2026
Operation PAR, Boley Centers, and Eleos notified individuals in 2026 after discovering a June 2025 unauthorized network intrusion that may have involved patient and employee personal information.
Emery Reddy05-12-2026
American Lending Center notified U.S. residents in multiple states after ransomware activity raised concerns about unauthorized access to personal information, with a review completed April 8, 2026.
Emery Reddy / Emery Reddy06-04-2026
RXNT reported unauthorized access to personal data between March 1 and March 3, 2026, and started customer notifications in May 2026 while offering credit monitoring services.
Emery Reddy06-08-2026
MasTec, Inc. disclosed unauthorized third-party access to part of its network lasting several days in August 2025, with individual notifications starting May 2026.
Emery Reddy07-07-2026
Monmouth University notified individuals starting June 30, 2026, after a forensic review found unauthorized access to PII beginning around February 5, 2026.
BlackFog / Rebecca Harpur04-27-2026
Capital One, NPD, Jerico Pictures, MGM Resorts, and Moody's illustrate that data breach harm can last years through litigation, contracting losses, credit impacts, and sustained regulatory oversight.

⭐️⭐️

ProCapitas / Dhruv Sharma02-23-2026
Conduent disclosed in 2026 that a breach dating back to late 2024 exposed personal and medical data of more than 25 million individuals across Texas and Oregon.