Healthcare Data Breaches And Vendor…Healthcare Data Breaches And Vendor ExposureCoverage from SecurityWeek, BleepingComputer, and others
00/00/0000
DailyWeekly
Healthcare, telecom, and government-linked service providers are disclosing large breaches that expose Social Security numbers, medical records, contact data, and government IDs, with regulators increasingly examining notification timing and vendor accountability.
The strongest signal is repeated exposure through third-party systems and contractor-managed platforms.
Looking Back
566 Day Timeline
Articles published over time. Hover any bar for the period and its article count.
Jan '25
Apr '25
Jul '25
Oct '25
Jan '26
Apr '26
Jul '26
History
07/21/2026
The story has narrowed from a broad pattern of healthcare breaches to a specific TriWest incident affecting Tricare beneficiaries, with a clearer account of what data was accessed and how many people were notified. It also adds concrete remediation and investigation steps, including credit monitoring, forensic review, and tighter access controls.
07/21/2026
The story has shifted from a single Texas license-vendor breach to a broader pattern of repeated healthcare and public-sector data disclosures involving vendors, business associates, and mixed sensitive records. The new framing emphasizes systemic exposure across multiple geographies and the special severity of biometric and medical data theft.
Oracle issued an out-of-band advisory in 2026 for CVE-2026-35273 in PeopleSoft PeopleTools, as ShinyHunters-linked reporting described targeting hundreds of PeopleSoft instances.
6/12/2026 • Cybersecurity (Privacy-Relevant) • Cybersecurity Tech (Privacy-Relevant): Data Breaches & Mass Exposures
Texas Parks and Wildlife Department disclosed a vendor breach affecting about 3 million hunting and fishing license holders after Texas Cyber Command notification.
6/22/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Medtronic notified 3.8 million Indiana-area affected individuals after ShinyHunters accessed corporate IT in April 2026 and obtained personal and medical data.
7/4/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Centers Laboratory notified US officials in connection with a late-discovered August 2025 breach affecting 542,377 people, after WorldLeaks posted leak and extortion claims.
7/13/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
London Hydro investigated in London, Ontario a suspected breach that may have exposed customer personal and account data, while reporting no payment information impact.
6/20/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Estée Lauder notified individuals in 2026 after unauthorized access to Oracle E-Business Suite identified in August 2025, aligning with CVE-2025-61882 exploitation.
7/20/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks and Wildlife Department disclosed a vendor-related breach in a license system impacting over 3 million customers, while Texas Cyber Command investigated intrusion scope and advised credit monitoring.
6/19/2026 • Data Breaches & Exposure Events • third-party/vendor Breaches
NAIC said ShinyHunters gained access to NAIC systems using an Oracle PeopleSoft zero-day, and NAIC reported no evidence of PII exposure after June 11 investigation.
6/29/2026 • Data Breaches & Exposure Events • Corporate Data Leaks
Mount Royal University reported a June 17 cyberattack in Calgary involving stolen and deleted H drive data, with exposure uncertainty and response actions including notifications and credit monitoring.
7/8/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
On June 2, DentaQuest disclosed an unauthorized access incident after ShinyHunters posted a claimed 234 GB leak affecting 2.6 million account records in the United States.
6/4/2026 • Cybersecurity (Privacy-Relevant) • Cybersecurity Tech (Privacy-Relevant): Data Breaches & Mass Exposures
ShinyHunters claimed responsibility for data theft and extortion demands against Oracle PeopleSoft instances affecting more than 100 organizations, including Nottingham University.
6/10/2026 • Cybersecurity Tech (Privacy-Relevant) • Cybersecurity Tech (Privacy-Relevant): Data Breaches & Mass Exposures
Oracle warned about CVE-2026-35273 in PeopleSoft PeopleTools, which enables unauthenticated remote code execution and was reportedly exploited by ShinyHunters in data theft attacks.
6/11/2026 • Data Breaches & Exposure Events • Corporate Data Leaks
Xsolis detected targeted phishing-based unauthorized access on January 22, 2026, after an attack on January 20, and notified 1,396,519 impacted individuals.
6/23/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
On January 27, 2026, Erie Family Health Centers in Chicago confirmed suspected unauthorized access between December 10, 2025 and January 27, 2026 affecting about 570,000 individuals.
5/21/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Wolf Haldenstein Adler Freeman & Herz LLP investigated claims tied to a February 2026 Strategic Education, Inc. data breach affecting New York and Chicago residents.
6/4/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Xsolis reported a phishing-led intrusion in January 2026 that exposed patient data for up to two days, with potential identity theft risk and possible court remedies.
6/24/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Schubert Jonckheer & Kolbe LLP is investigating an alleged ShinyHunters breach of Inter-Con in Pasadena, California, affecting about 2.7 million records.
7/13/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
NYC Health and Hospitals disclosed a months-long vendor-mediated cyberattack detected February 2, 2026, exposing medical, identity, geolocation, and fingerprint data for at least 1.8 million people in New York.
5/18/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Zara and Inditex reported an Anodot-linked breach affecting about 200,000 customers, with leaked data analysis identifying 197,400 unique email addresses.
5/11/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
NYC Health + Hospitals confirmed a November 2025 to February 2026 cyberattack exposing about 1.8 million patients' biometrics, health records, IDs, and precise geolocation.
5/19/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
NAIC confirmed a PeopleSoft zero-day cyberattack with dark-web data leakage on June 17, after detecting the intrusion on June 11 and citing Oracle emergency patching.
6/26/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Cyber Command reported a vendor data breach impacting over 3 million hunting and fishing license customers, with potential exposure of identity data fields.
6/22/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks and Wildlife reported a vendor data breach affecting more than 3 million Texas hunting and fishing license holders; Texas Cyber Command investigates.
6/22/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Craneware notified the FBI and the UK Information Commissioner's Office after a contained network intrusion copied employee and customer partner data in the USA and UK.
7/20/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Middletown, Ohio, notified residents on June 3 after a late-2025 breach exposed Social Security numbers and medical information, with TransUnion providing credit monitoring.
6/4/2026 • Data Breaches & Exposure Events • Government Data Exposure
Texas Parks and Wildlife Department disclosed that a license vendor data breach, notified on May 13, 2026 by Texas Cyber Command, may have exposed personal IDs for over 3 million people.
6/22/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Inditex disclosed April 2026 unauthorized database access for Zara after ShinyHunters used compromised Anodot tokens, exposing customer emails, locations, purchases, and support tickets.
5/10/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks and Wildlife Department disclosed a vendor breach involving 3,087,721 license customers after Texas Cyber Command investigated unauthorized access in Texas.
6/21/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Xsolis disclosed a January phishing-driven breach later reported in early June, impacting 1.4 million people with exposed personal and protected health information.
6/23/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Medtronic notified customers in 2026 after unauthorized access to corporate IT systems may have exposed Social Security numbers and health-related data, per ShinyHunters extortion claims.
7/2/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Colorado Health Network disclosed a data breach to regulators on June 22, 2026 after alleged Tor data posting by threat actor Cephalus on Aug. 28, 2025.
6/22/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
ShinyHunters claimed Council of Europe data theft in connection with Oracle PeopleSoft CVE-2026-35273, while Google reported related exploitation affecting 100+ organizations.
6/15/2026 • Data Breaches & Exposure Events • Corporate Data Leaks
Estée Lauder disclosed July 20, 2026, a breach of Oracle E-Business Suite HR systems after access starting on or around August 9, 2025, exposed Social Security and financial data.
7/21/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks and Wildlife Department reported a vendor cybersecurity incident affecting more than 3 million Texans, with potential exposure of passport numbers and residential addresses.
6/22/2026 • Cybersecurity Tech (Privacy-Relevant) • Cybersecurity Tech (Privacy-Relevant): Data Breaches & Mass Exposures
Shenandoah Borough, led by Mike Cadau, reported a 2024 payroll-record exposure after discarded documents with Social Security numbers were found near Bicentennial Park and in a borough garage.
7/13/2026 • Data Breaches & Exposure Events • Government Data Exposure
TriWest Healthcare Alliance notified 11,844 TRICARE West beneficiaries after unauthorized access discovered April 16 may have exposed protected health information, including DoD Benefits Numbers and some SSNs.
7/13/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks and Wildlife Department disclosed in June 2026 that a third-party vendor breach exposed driver license and passport identifiers for 3.1 million Texans.
6/21/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Eversource Energy disclosed April phishing and social engineering attacks that compromised two employees and exposed personal data of 3,049 customers in Connecticut, Massachusetts, and New Hampshire.
6/3/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Xsolis disclosed unauthorized access from a targeted phishing attack on Jan. 20, 2026, exposing sensitive data for 1,396,519 individuals in the United States.
6/24/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Cyber Command confirmed a Texas Parks and Wildlife Department license system incident in Texas may have exposed sensitive personal data for more than 3 million customers.
6/30/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Singapore Land Authority reported unauthorized access in an IBM-managed cloud testing environment involving STARS and eLodgment systems, exposing data for about 70,000 people.
7/3/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Xsolis disclosed a June 5 phishing-related breach after Jan. 20 unauthorized IT access affected 1.4 million patients across multiple health systems, with HHS posting results on June 22.
7/2/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
CMD Organization ransomware stole and deleted files from Mount Royal University shared drives in Calgary, after passport-scan proof and a 30 Bitcoin demand.
7/9/2026 • Cybersecurity (Privacy-Relevant) • Cybersecurity Tech (Privacy-Relevant): Data Breaches & Mass Exposures
TriWest Healthcare Alliance notified 11,844 beneficiaries in July after an April 16 incident may have exposed protected health information, with Experian credit monitoring offered.
7/13/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Melissa King filed a June 4 class action in Massachusetts alleging DentaQuest cybersecurity failures after a ShinyHunters ransomware-linked attack exposed Social Security and health data.
6/29/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Delaware North reported a January 2026 breach tied to a compromised Microsoft account, with possible ID and Social Security exposure, notifying in New Hampshire and Texas.
6/9/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Unlimited Technology Systems LLC disclosed to the Iowa Attorney General on July 1, 2026 that unauthorized activity in an October 2025 datacenter may have exposed PII and limited PHI, and offered Kroll identity monitoring.
7/20/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Excelas disclosed a May 12, 2026 data breach to Massachusetts and New Hampshire after 2025 unauthorized access may have exposed PII and protected health information.
5/15/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Eversource Energy disclosed a phishing-related data breach affecting about 3,049 people, reported May 21, 2026 to the Maine Attorney General and notified consumers starting May 27, 2026.
5/22/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Manager on Call LLC disclosed a May 2026 phishing breach after display name spoofing exposed W-2 data and Social Security numbers for five employees in New Hampshire and South Carolina.
6/4/2026 • Data Breaches & Exposure Events • Corporate Data Leaks
C2N Diagnostics LLC disclosed an April 27, 2026 breach notice after unauthorized access to employee email communications exposed patient PII and protected health information affecting about 2,027 people in the United States.
6/5/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Manzil Investment Advisors LLC disclosed an early-April 2026 data breach exposing Social Security numbers, with New Hampshire Attorney General notification on June 5, 2026.
6/9/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Stanley Pearlman Enterprises disclosed a 2026 data breach to Massachusetts and Nebraska regulators and affected individuals, exposing PII and PHI including biometric data.
6/18/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
AgelessRx disclosed help-desk ticket access in April 2026 that exposed patient health and identity data, with consumer notifications starting June 23 and state reporting on June 24.
6/25/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Optalis Management Solutions disclosed unauthorized network access from April 2025, affecting financial and health data, and notified Massachusetts regulators in June 2026.
6/30/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
First National Holdings LLC disclosed a July 2026 data breach affecting 34,507 Texas residents and one Vermont resident after notices to state attorneys general.
7/12/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Firstsource disclosed a healthcare platform programming-error data breach affecting potentially exposed Social Security numbers, reported to Massachusetts on July 15, 2026.
7/15/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Locus Technologies disclosed a Social Security number data breach and notified affected individuals in July 2026, with Massachusetts reporting on July 15 and TransUnion credit monitoring offered.
7/16/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Alamo Heights Independent School District reported a March cyberattack in Texas that exposed personal data of more than 26,000 people, triggering attorney general reporting and mailed notifications.
6/25/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Cyber Command detected a vendor breach in the Texas hunting and fishing license sales system used by Texas Parks and Wildlife Department, exposing identity and contact data for over 3 million customers.
6/25/2026 • Data Breaches & Exposure Events • third-party/vendor Breaches
Oak Hill confirmed May 13, 2026 that an October 6, 2025 security incident involved unauthorized access to files containing PII and protected health information, with notifications mailed June 30, 2026 in Connecticut.
7/20/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Columbia University disclosed a past data breach involving Social Security numbers and delayed notification details affecting unaffiliated individuals, with a proposed class action following.
6/4/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Universal Pure LLC disclosed a 2024 unauthorized-access data breach affecting Maine, Massachusetts, New Hampshire, and Texas residents, with identity protection via Cyberscout.
4/24/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Healthcare In Action reported a January 2026 credential compromise that exposed PII and protected health information for 1,143 people, with breach notification to HHS in March 2026.
5/11/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Fluke Corp. reported a 2025-2026 data breach affecting 18,517 US residents, including Texas, Vermont, and Maine residents, with notifications beginning May 15, 2026.
5/14/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Pivot Health disclosed a March 2026 AWS data breach affecting 1,172 people in Texas and 27 in Nebraska after unauthorized access between Feb. 26 and March 13.
5/15/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Hemic disclosed a 2026 data breach discovered Feb. 2026, with potential exposure of Social Security numbers and health records for affected people in multiple states.
5/15/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
FRCC disclosed an unauthorized file-copying data breach in March-April 2026, potentially exposing names and Social Security numbers for Texas and New Hampshire residents.
5/15/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Global Consulting Services & Software Development notified Maine, Massachusetts, and Vermont attorneys general on May 18, 2026 after unauthorized access exposed names and Social Security numbers for 1,320 U.S. individuals.
5/20/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Southern California University of Health Sciences disclosed a 2026 data breach affecting about 2,206 people after file viewing and copying occurred March 23 to March 24, 2026.
5/20/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Global Consulting Services & Software Development reported a January 2026 data breach to the Maine and Vermont attorney generals in May 2026, affecting 1,320 U.S. individuals.
5/20/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
NCCER notified affected individuals in 2026 after a March 2025 breach involving Quilin file exfiltration, with Maine residents receiving mailed notices on May 1, May 15, and May 21.
5/26/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Aimbridge Hospitality disclosed a hotel systems data breach to Maine and Vermont authorities after unauthorized access may have occurred in November 2025.
5/27/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Interstate Management Company, LLC disclosed unauthorized hotel-system access from Nov. 19 to Nov. 22, 2025, potentially affecting 22,743 U.S. people, with notices sent May 26, 2026.
5/27/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
United Medical Systems disclosed a data breach impacting 485 people, including Massachusetts and Maine residents, with notifications beginning May 20, 2026.
5/27/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
NetLine Corp. reported a webserver data breach in Newton, Massachusetts, in which exposed data may include Social Security numbers or ITINs, after notifying Maine and Vermont attorneys general.
5/28/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Everest Ito Group, LLP reported a May 20, 2026 data breach to Massachusetts regulators involving names and Social Security numbers for three affected residents.
5/28/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
University of Dallas disclosed a data breach on undisclosed date affecting Texas and Vermont residents, potentially exposing sensitive identity, financial, and health information.
5/29/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Nursa disclosed unauthorized access to clinician profiles on its Murray, Utah platform, exposing names and full dates of birth for 13,168 Washington residents.
5/29/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
ViaQuest Psychiatric & Behavioral Solutions disclosed to HHS on May 8, 2026 a data breach affecting at least 6,420 people with exposure of PII and protected health information.
6/2/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Capital Bank notified California and Texas regulators in May 2026 after a breach on April 26-27 exposed Social Security numbers for 86,067 Texas residents.
6/3/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Bridle Trails Family Dentistry disclosed in 2026 an unauthorized employee email account access in 2024 affecting about 20,976 individuals in Kirkland, Washington.
6/3/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
D.B. Root & Co. LLC disclosed a 2025 network intrusion affecting 2,806 people across the U.S., with possible exposure of Social Security and financial data.
6/5/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Gainwell Technologies notified about 22,500 affected individuals in Connecticut after a March 2026 HUSKY provider portal breach using compromised Hartford HealthCare employee credentials.
6/5/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
MasTec notified Maine and South Carolina authorities on June 5, 2026 about a breach affecting 25,220 US residents linked to an August 2025 network intrusion.
6/8/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
DTG Consulting Solutions Inc. disclosed May 2026 breach notice to Massachusetts regulators and Vermont Attorney General and notified affected people May 29, 2026.
6/8/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Delaware North disclosed a Jan.-May 2026 breach after an employee Microsoft account compromise exposed names and driver ID numbers for affected New Hampshire and Maine residents.
6/8/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
CenterWell disclosed a U.S. data breach in notifications to Massachusetts and Texas attorneys general and HHS, affecting 9,651 people including 4,618 Texans.
6/8/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Xsolis disclosed a Jan. 20, 2026 phishing breach affecting personal and health data provided by healthcare clients, offering credit monitoring for eligible individuals.
6/8/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Liberty Solutions Inc. reported a PHI-related data breach affecting 7,329 U.S. individuals, with HHS filing details but no public specifics on exposed data types or attack dates.
6/11/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Lifepoint Health disclosed a 2026 vendor-related data breach after compromised account access exposed U.S. vendor employees' personally identifiable information.
6/17/2026 • Data Breaches & Exposure Events • third-party/vendor Breaches
Texas Parks and Wildlife Department disclosed a data breach affecting 3,087,721 Texas residents, with limited publicly released details about timeline and access method.
6/18/2026 • Data Breaches & Exposure Events • Government Data Exposure
One Medical Seniors disclosed a June 13, 2026 ransomware breach of a third-party file-storage archive, after unauthorized access lasting about three days.
6/20/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Fedcap Group disclosed a breach potentially exposing Social Security and driver license numbers, with filings to Massachusetts regulators and the Vermont Attorney General in June 2026.
6/26/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
MCBS LLC reported a privacy incident involving unauthorized network access between Sept. 22 and Sept. 26, 2025, to the California Attorney General on June 26, 2026.
6/29/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
FoxTrot LLC disclosed an April 2026 breach to Caldwell Sutter Capital Inc., exposing consumer identifiers including Social Security numbers and triggering Experian IdentityWorks services.
6/29/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Cross Resource Group disclosed to Massachusetts officials on June 26, 2026 a May 19, 2026 employee data breach involving Social Security numbers and payroll data.
6/30/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Yorozu Automotive Tennessee Inc. reported a Oct. 9, 2024 data breach affecting 20,627 U.S. individuals, including exposure of PII and protected health information, with notifications starting June 2, 2026.
7/2/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
T.A. Solberg Co. Inc. disclosed an unauthorized access incident impacting consumers in 2026 regulator notices, involving Social Security, identity, and health data exposure.
7/6/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
TriWest Healthcare Alliance disclosed a July 7, 2026 breach to the Texas Attorney General exposing PII and protected health information for 2,408 Texas residents.
7/7/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Signature Healthcare disclosed a nationwide data breach to the U.S. Department of Health and Human Services on June 5, 2026, while exposed data types remained undisclosed as of June 30, 2026.
7/9/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
YouLend US LLC disclosed a June 2026 data breach after unauthorized access exposed Social Security numbers, with reporting to California and Texas attorneys general in July 2026.
7/16/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Novo Nordisk, Kodak, Fortinet, Infinite Campus, and Texas government systems disclosed breaches that exposed sensitive personal data and credentials amid ransom demands.
6/19/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Ultrahuman notified some users on March 27, 2026 about a breach targeting an internal analytics system that may have exposed wellness-linked account details for about 1,000 users.
6/4/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks & Wildlife reported a vendor unauthorized access incident involving hunting and fishing license processing, exposing personal data for more than 3 million people.
6/18/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
TriWest Healthcare confirmed an April 16 breach affecting about 12,000 TRICARE beneficiaries after Ernst & Young detected anomalous activity on April 23.
7/17/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Senator Bill Cassidy asked NYC Health + Hospitals for details about a months-long hack that allegedly exposed medical records and fingerprint scans for over 1.8 million patients.
6/5/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Unlimited Technology Systems, LLC discovered unauthorized datacenter activity on October 19, 2025 and began patient notifications around July 20, 2026 after a potential data exposure.
7/20/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Murphy Law Firm reported a data breach exposing Social Security numbers, driver license numbers, financial data, and health records, enabling identity theft and fraud.
4/23/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Missouri officials investigated a Conduent breach occurring between fall 2024 and January 2025 after exposure of Social Security numbers and health data.
5/7/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
In 2024, healthcare breaches in the United States exposed over 289 million individuals, with Change Healthcare's cyberattack driving exposure for many Chicago-area providers.
6/8/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
ShinyHunters breached DentaQuest on a ransom timeline and publicly posted data for 2.6 million Medicaid and Medicare Advantage accounts after June 2 confirmation.
6/9/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
A Fluke Corp. employee filed a Seattle class action on June 5 alleging delayed breach notification and inadequate cybersecurity after a 2025 incident exposing employee personal data.
6/12/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Lehighton Area School District board members faced residents' backlash after Social Security numbers were exposed online following a Right-to-Know records request and posting by director David Bradley.
6/12/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Kentucky Management Services Organization reported a CRS medical records vendor breach affecting about 500 Kentucky Bariatric Institute patients, with exposure limited to names, medical record numbers, and service dates.
6/13/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Xsolis disclosed a January 20 phishing breach that Xsolis detected on January 22, exposing sensitive patient data for Mayo Clinic and other healthcare customers.
6/16/2026 • Data Breaches & Exposure Events • third-party/vendor Breaches
Texas Parks and Wildlife Department disclosed a vendor breach on license processing affecting over 3 million Texans and offered Kroll credit monitoring after exposure of multiple personal identifiers.
6/19/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks and Wildlife Department reported a vendor-linked breach detected by Texas Cyber Command exposing hunting and fishing license contact and driver license data for over 3 million Texans.
6/20/2026 • Data Breaches & Exposure Events • third-party/vendor Breaches
Texas Parks & Wildlife Department notified about 3 million hunting and fishing license holders in June 2026 after detecting suspicious activity in 2024 and exposing some Social Security numbers.
6/22/2026 • Data Breaches & Exposure Events • Government Data Exposure
Xsolis disclosed a Jan 22 2026 targeted phishing breach affecting 1.4 million people, reporting containment and no misuse, with downstream notices from major healthcare providers.
6/24/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Medtronic disclosed a April 2026 patient-data incident involving unauthorized access to corporate IT systems, reporting impacts across Texas, Massachusetts, and Vermont.
7/1/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Singapore Land Authority said unauthorized access in an IBM-managed cloud test environment may have exposed NRIC numbers and addresses for about 70,000 people.
7/6/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
X-Copper Professional Corporation reported a June 8, 2026 hack involving compromised credentials and malware in Canada, potentially exposing customers personal data.
7/10/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
TriWest Healthcare Alliance notified TRICARE West beneficiaries in July after an April 16 unauthorized access incident potentially exposed protected health information.
7/14/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Ultrahuman notified customers in an email sent Wednesday after an unauthorized party accessed an internal analytics system on March 27, exposing contact, account, and transaction-history data.
6/4/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
HaveIBeenPwned reported a ShinyHunters campaign tied to stolen Anodot tokens exposed Zara support ticket and Canvas user data across multiple countries in April 2026.
5/11/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Google Threat Intelligence Group and Mandiant reported a ShinyHunters compromise of Oracle PeopleSoft between May 27 and June 9, with Oracle issuing a June 10 security alert.
6/15/2026 • Data Breaches & Exposure Events • third-party/vendor Breaches
Texas Parks and Wildlife Department confirmed June 18, 2026 that a third-party licensing vendor breach exposed government ID-linked data for 3,087,721 permit holders.
6/21/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Estée Lauder confirmed in June 2026 a breach stemming from Oracle E-Business Suite BI Publisher CVE-2025-61882 exploitation, later reported to the Vermont Attorney General in July 2026.
7/21/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Xsolis, a Tennessee healthcare technology vendor, disclosed a Jan. 22 phishing-driven breach affecting client patient data in the United States, with VHC Health notifying Virginia patients.
6/15/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Edelson Lechtzin LLP offered free consultations in connection with Excelas after Excelas disclosed a 2025-2026 data breach and Massachusetts notification in 2026.
5/18/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks and Wildlife reported a vendor-linked cybersecurity incident detected by Texas Cyber Command that may have exposed personal data for over 3 million license customers.
6/23/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
DentaQuest reported a breach affecting up to 2.6 million people, after ShinyHunters posted claimed customer data in May and multiple class actions were filed in Massachusetts federal court.
6/8/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks and Wildlife Department reported a vendor data breach affecting hunting and fishing license customers, with credit monitoring offered by Kroll and a Sept. 14 enrollment deadline.
6/25/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Medtronic disclosed an April 2026 corporate IT breach that exposed SSNs and health-related data, with notifications starting in late June 2026 after ShinyHunters extortion claims.
7/5/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
NYC Health + Hospitals disclosed a March 24, 2026 report of a vendor-based breach detected February 2, 2026 that exposed medical and biometric data for at least 1.8 million people in New York City.
5/19/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks and Wildlife Department disclosed a vendor-linked breach affecting 3,087,721 Texans, with notifications filed in Texas amid identity theft risks.
6/23/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
In Rhode Island, a community services center began June 2026 notices after a late-December 2025 incident left files potentially containing health and identity information.
6/8/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
In New York, a district reported to state agencies and the FBI after an outside actor accessed backup files for a lunch processing system and exposed student data.
6/11/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Cyber Command detected a Texas Parks and Wildlife vendor breach affecting 3 million-plus hunters and anglers, exposing identifiers while excluding Social Security numbers and financial data.
6/19/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks and Wildlife Department reported a vendor-related cybersecurity incident affecting more than 3 million license holders, with Kroll credit monitoring offered and safeguards planned.
6/19/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks and Wildlife said Texas Cyber Command detected a vendor data breach on hunting and fishing license sales, exposing driver license and passport data.
6/22/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks and Wildlife Department disclosed a vendor-related breach affecting more than 3 million hunting and fishing license customers, with credit monitoring offered via Kroll.
6/22/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Edelson Lechtzin LLP began investigating potential class action claims after Xsolis discovered unauthorized activity from a January 2026 phishing attack affecting at least 1.4 million individuals.
6/22/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Schubert Jonckheer & Kolbe LLP is investigating a ShinyHunters claim that Inter-Con Security Systems had unauthorized access to data tied to about 2.7 million individuals, with notification not yet confirmed, as of July 13, 2026 in Pasadena, California.
7/13/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
TriWest Healthcare Alliance notified 11,844 TRICARE beneficiaries after an April incident enabled unauthorized access and download of limited personal and protected health information.
7/17/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
ShinyHunters published 234 GB of stolen DentaQuest files, and DentaQuest confirmed June 2 unauthorized access affecting 2.6 million Medicaid and Medicare Advantage beneficiaries.
6/8/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks and Wildlife Department disclosed a vendor system breach affecting 3.09 million license customers after Texas Cyber Command confirmed unauthorized access.
6/22/2026 • Data Breaches & Exposure Events • third-party/vendor Breaches
Texas Cyber Command investigated a Texas Parks and Wildlife license system vendor incident discovered in 2026, affecting over three million customers' identity contact data.
6/23/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
CMS deferred more than 1.3 billion dollars in California Medicaid payments as a Congressional Medical Office breach exposed lawmakers' prescription and medical record data via RXNT.
5/14/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Estée Lauder notified employees in 2026 that Oracle E-Business Suite HR compromise dating to August 9, 2025 led to exfiltration of personal data linked to Clop ransomware activity.
7/20/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Mount Royal University in Calgary reported a June 17, 2026 data breach after attackers copied shared-drive files, deleted originals, and CMD Organization posted sample data.
7/9/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
NYC Health + Hospitals disclosed a Solventum business associate breach in 2026 exposing protected health information for 58,778 patients after dark-web posting.
7/15/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
A roundup reports breach concealment pressure, a GitHub AI agent flaw enabling private repository leaks, and major U.S. consumer data exposure events in 2025.
7/9/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
NYC Health + Hospitals notified nearly 2 million patients in 2024 after a third-party vendor hacking incident led to potential exposure of health, identity, payment, and biometric data in New York City.
5/19/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Medtronic notified potentially affected people more than two months after disclosure of an unauthorized cyberattack disclosed earlier, offering credit and dark-web monitoring while reporting no evidence of public internet exposure.
7/2/2026 • Data Breaches & Exposure Events • Corporate Data Leaks
ShinyHunters claimed responsibility for a Zara breach disclosed in April, using compromised Anodot authentication tokens to exfiltrate 197,400 BigQuery customer records from a former provider.
5/20/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks and Wildlife Department disclosed a cybersecurity incident impacting more than three million residents after unauthorized access to hunting and fishing license records in Texas.
6/19/2026 • Data Breaches & Exposure Events • Government Data Exposure
Texas Parks and Wildlife Department reported a vendor cyberattack detected by Texas Cyber Command, potentially exposing driver license and contact data for 3.1 million Texans.
6/19/2026 • Cybersecurity (Privacy-Relevant) • Cybersecurity Tech (Privacy-Relevant): Data Breaches & Mass Exposures
VHC Health notified patients on June 5 about a Jan. 22 Xsolis, Inc. phishing-related vendor breach that may have exposed Social Security numbers, medical diagnoses, and account numbers.
6/11/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
NYC Health + Hospitals disclosed March 24, 2026 that a vendor-linked breach exposed medical records and biometric fingerprints for at least 1.8 million patients and employees.
5/19/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks and Wildlife Department reported a third-party vendor breach in which exposed PII affected about 3.08 million hunting and fishing license holders.
6/19/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Xsolis reported a healthcare AI vendor breach in June 2026 after phishing access on January 20 exposed at least 1.4 million patient records across eight U.S. health systems.
7/2/2026 • Data Breaches & Exposure Events • third-party/vendor Breaches
Lawmakers were notified after an RXNT-targeted data breach affecting the congressional medical office potentially exposed prescription history on March 1 and 3.
5/13/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
OpenLoop Health disclosed in 2026 that hackers accessed systems between January 7 and 8 and exposed telehealth patient personal data of 716,000 people.
5/13/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
On May 20, 2026, Kroll notified The Oncology Institute about vendor-detected unauthorized access tied to patient data after a November 2025 breach disclosure.
5/26/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks and Wildlife Department disclosed a vendor breach identified by Texas Cyber Command affecting about 3 million hunting and fishing license customers.
6/22/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Xsolis disclosed a January 2026 phishing-driven data breach in Tennessee affecting 1,396,519 people by exposing personal and protected health information.
6/23/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
NYC Health + Hospitals disclosed a Solventum business-associate breach affecting 58,778 patients after unauthorized protected health information access on or around March 29, 2026.
7/14/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
NYC Health and Hospitals disclosed on 2026 that hackers accessed systems from 25 November 2025, stealing health records, biometric identifiers, and geolocation data affecting at least 1.8 million people.
5/18/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks and Wildlife Department reported a license database breach in Texas involving possible personal information exposure for more than 3 million customers.
6/23/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Cindi Carter and Check Point Software advise identity-protection steps after a ransomware attack exposed personal data of up to 26,000 people in Alamo Heights ISD, Texas.
6/26/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
J. Arthur Trudeau Memorial Center reported suspicious network activity on Jan. 29 that led to unauthorized access to PHI and PII between Jan. 22 and Jan. 28 in Rhode Island.
7/16/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
J. Arthur Trudeau Memorial Center reported Jan. 22 to Jan. 28 data exfiltration after suspicious activity detection on Jan. 29, exposing PII and protected health information.
7/16/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
One Medical reported June 13 unauthorized access to a third-party file storage system holding archived health records for limited legacy Iora Health patients.
6/18/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Check Point Research reported 22 June 2026 privacy-relevant breaches affecting a Texas licensing vendor, iRhythm health data, and Salesforce-connected OAuth tokens.
6/22/2026 • Cybersecurity (Privacy-Relevant) • Cybersecurity Tech (Privacy-Relevant): Data Breaches & Mass Exposures
Texas Parks and Wildlife Department disclosed a vendor-related cyberattack impacting more than 3 million hunting and fishing license customers after Texas Cyber Command identification.
6/22/2026 • Data Breaches & Exposure Events • third-party/vendor Breaches
ViaQuest disclosed in Ohio a network server hacking incident in which 6,420 patients and staff had PII and PHI exposed, with HIPAA risk and a 2026 lawsuit investigation.
6/4/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Strategic Education disclosed a February 2026 data breach affecting 100,000-plus people in Texas, Massachusetts, and Maine after exposure of Social Security, driver’s license, and passport numbers.
6/4/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks and Wildlife Department disclosed a third-party vendor cyberattack affecting more than 3 million Texas residents in the hunting and fishing license system context.
6/22/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Missouri regulators investigated the Conduent breach in 2024-2025 data access and exfiltration, demanding better disclosure for consumer impact assessment, while Texas also pursued related inquiries in 2026.
5/12/2026 • Cybersecurity (Privacy-Relevant) • Cybersecurity Tech (Privacy-Relevant): Data Breaches & Mass Exposures
ShinyHunters issued an extortion threat against One Medical in 2023, while One Medical confirmed a limited third-party storage access affecting archived Iora Health records.
6/18/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Xsolis reported a phishing-driven unauthorized-access incident on January 20 affecting 1.4 million individuals, with HHS posting the figure on June 22.
6/23/2026 • Data Breaches & Exposure Events • third-party/vendor Breaches
NYC Health + Hospitals disclosed May 19, 2026 that a third-party vendor vulnerability in November 2025 enabled unauthorized access affecting about 1.8 million individuals.
5/20/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Cyber Command detected a vendor breach in TPWD licensing systems, potentially exposing personal information for more than 3 million hunting and fishing customers.
6/22/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks and Wildlife Department reported a vendor breach involving the licensing system, potentially exposing data for more than 3.1 million customers during an ongoing investigation.
6/23/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Connecticut DSS and Gainwell disclosed March 2026 unauthorized access to the HUSKY provider portal that used compromised Hartford HealthCare credentials and impacted about 22,500 people.
6/9/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Fundamental Administrative Services reported a data security incident impacting 13,302 people, disclosed in a Texas Attorney General breach report on August 19, 2025.
7/18/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks and Wildlife Department announced a vendor data breach detected by Texas Cyber Command, exposing personal identifiers for 3,087,721 customers.
6/19/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Federman & Sherwood investigates INTEGRIS Health after Cerner detected unauthorized third-party access to legacy electronic health record systems affecting Oklahoma patients.
6/29/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
University of Nottingham and Novo Nordisk reported privacy-impacting breaches in mid-June as attackers exploited vulnerabilities including CVE-2026-35273 and CVE-2026-50751.
6/15/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Federman & Sherwood is investigating YouLend US LLC after unauthorized network access from June 5 to June 9, 2026 potentially exposed Social Security numbers.
7/20/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Senate HELP chair Bill Cassidy demanded breach details from NYC Health + Hospitals after a March 24 notification tied to unauthorized access between Nov 25 and Feb 11.
6/8/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
HHS OCR reported that 2026 healthcare breach reports have impacted more than 19 million individuals, with hacking/IT incidents the leading breach type as of June 9, 2026.
6/16/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks and Wildlife alerted more than 3 million license purchasers in Texas after a vendor-linked cybersecurity incident exposed customer profile data, according to state officials.
6/22/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
DentaQuest reported a cybersecurity breach involving unauthorized access on a limited network portion, with about 2.6 million accounts exposed and notifications planned.
7/4/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Medtronic confirmed a breach discovered on April 15, 2026, after unauthorized access to corporate IT systems potentially exposed sensitive health and identity data.
7/12/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks & Wildlife notified the public in 2024 after a cybersecurity unit detected a vendor-related intrusion exposing drivers license information and passport numbers for more than 3 million people in Texas.
6/18/2026 • Data Breaches & Exposure Events • Government Data Exposure
TriWest Healthcare Alliance notified 11,844 beneficiaries in the Tricare West Region after an April 16 security incident potentially exposed protected health information.
7/13/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
ShinyHunters claimed responsibility for a May 2026 DentaQuest breach affecting about 2.6 million records, with DentaQuest confirming unauthorized access on June 2, 2026.
6/5/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
ShinyHunters claimed a June 2026 breach of Inter-Con Security Systems in Pasadena, California, allegedly exposing 2.7 million records with unconfirmed notification status.
7/13/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Cyber Command reported a Texas Parks and Wildlife Department vendor breach affecting over 3 million hunting and fishing license customers last Thursday.
6/23/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks and Wildlife Department reported a vendor-managed license-system breach detected by Texas Cyber Command, potentially exposing personal data for over 3 million customers.
6/22/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
On March 4, compromised Hartford HealthCare credentials enabled a hacker to access the Connecticut Medicaid provider portal, affecting about 22,500 patients, with notifications mailed starting May 22.
5/22/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Connecticut DSS announced May 22 postal notifications after a March 4 HUSKY provider-portal breach exposed personal information for about 22,500 enrollees.
5/22/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Colorado Health Network, Inc. disclosed an unauthorized-access cybersecurity incident and began breach notifications on June 18, 2026, after exposure of patients medical and financial data.
6/19/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks and Wildlife Department disclosed a Texas Cyber Command-detected vendor breach on the hunting and fishing license system affecting over three million customers.
6/26/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Strategic Education Inc. reported a 2026 breach to the Maine Attorney General after 87 days of undetected server access exposed sensitive identification data for 2,673 Maine residents.
6/3/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Open Arms Care Corporation notified potentially affected individuals starting June 9, 2026 after unauthorized access to its Tennessee email environment occurred between June and August 2025.
6/17/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Federman & Sherwood is investigating a Precipio, Inc. data breach reported to affect 4,952 Texas residents after a Texas Attorney General notification on April 28, 2026.
4/28/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Federman & Sherwood is investigating a Fluke Corporation data breach reported to the Maine Attorney General after third-party application exploitation possibly exposed Social Security numbers.
5/26/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Federman & Sherwood investigates the Wellpoint Washington data breach, described as an email-system hacking incident reported to HHS, affecting about 12,020 Washington residents.
6/19/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Federman & Sherwood is investigating the Ray Riding Motors data breach reported to the Attorney General of Texas after potential exposure of Social Security and medical information.
6/23/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Stanley Pearlman Enterprises reported a February 2026 network intrusion that exposed names and driver license numbers, with June 2026 notifications to affected individuals in Nebraska.
6/25/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Federman & Sherwood investigated the AgelessRx data breach reported to the Vermont Attorney General after potential health-record exposure for about five Vermont residents.
6/25/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Federman & Sherwood investigated a Brooks, Cook & Associates data breach reported to the Vermont Attorney General in connection with Social Security number exposure.
7/10/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Federman & Sherwood investigates an Averhealth Holdings data breach affecting about 858 Vermont residents after unauthorized access to protected health information was reported to the Vermont Attorney General.
7/15/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks and Wildlife Department announced a vendor-caused data breach affecting over 3 million license holders, with Texas Cyber Command reporting unauthorized access and offering Kroll credit monitoring.
6/22/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Cyber Command reported a vendor-related breach at Texas Parks and Wildlife Department affecting over 3 million hunting and fishing license customers, with credit monitoring offered via Kroll.
6/22/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
NYC Health and Hospitals reported a months-long network breach from November 2025 to February 2026 affecting at least 1.8 million people, exposing medical records, IDs, and fingerprint scans.
5/18/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks and Wildlife Department disclosed a breach on over 3 million hunting and fishing license accounts, potentially exposing contact and ID data, in Texas.
6/22/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
In April 2026, Medtronic reported a breach exposing Social Security numbers and medical data, triggering identity theft concerns and legal investigation by Murphy Law Firm.
6/30/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Murphy Law Firm is investigating a Passco Companies, LLC data breach after reports of unauthorized access to sensitive personal files impacting thousands.
6/18/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Mayo Clinic said an April 23 third-party vendor incident at Xsolis may have affected some patient information, with Xsolis notifying affected patients.
6/22/2026 • Data Breaches & Exposure Events • third-party/vendor Breaches
Former customer Lariesha Lincoln filed a proposed class action on July 6 in Florida alleging Futuredontics failed to protect patient data after Qili ransomware claimed theft from 1-800-Dentist.
7/9/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
IPPC Inc. reported a September 18 to 19 network intrusion that potentially exposed medical and Social Security data for up to 133,862 people across New Jersey and neighboring states.
4/17/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Texas Parks & Wildlife Department disclosed a vendor-related breach of hunting and fishing license systems in Texas, with possible exposure of identity and contact information.
6/19/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Unlimited Technology Systems disclosed a 2025 breach involving unauthorized access to patient files, with potential PII and PHI exposure and Iowa Attorney General notification submitted in 2026.
7/20/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
LexisNexis disclosed a data breach affecting over 364,000 consumers after an unknown hacker obtained sensitive personal data via a third-party software development platform.
5/28/2025 • Data Breaches & Exposure Events • Consumer Data Breaches
Cybernews researchers reported a temporarily misconfigured Elasticsearch database publicly exposed 24 billion records with plaintext passwords and login URLs.
6/19/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Medtronic confirmed a corporate IT breach in April 2026 after ShinyHunters claimed data compromise affecting nine million affiliated individuals, raising privacy and notification concerns.
5/7/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Edelson Lechtzin LLP says it is investigating a Xsolis, Inc. phishing-triggered data breach discovered on January 22, 2026, possibly affecting 1.4 million people.
6/22/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Xsolis reported a January 2026 phishing-driven breach affecting 1.4 million people, exposing patient records and leading to class-action efforts in Tennessee and nationwide.
6/24/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
ShinyHunters claimed a June 19, 2026 breach at Inter-Con Security Systems in Pasadena, California, alleging 2.7 million records stolen and delayed notification through July 13.
7/13/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Xsolis disclosed a January 2026 phishing-based intrusion that exposed patient records, potentially including Social Security numbers, for up to 1.4 million individuals.
6/24/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
HHS OCR listings show nearly 57 million individuals affected by healthcare data breaches in 2025, with major vendor and ransomware incidents reported across the United States.
1/2/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
Gaylord Specialty Healthcare and Gainwell Technologies report data breaches in December 2024 and July 2025 affecting patients in Connecticut and Medicaid recipients in Georgia due to unauthorized network access.
9/29/2025 • Data Breaches & Exposure Events • Consumer Data Breaches
Healthcare providers in Virginia, Massachusetts, California, New York, and Ohio reported protected health information exposure from ransomware and unauthorized access incidents during 2023 to 2024.
1/15/2025 • Data Breaches & Exposure Events • Consumer Data Breaches
Malwarebytes reported in February 2026 that a Conduent data breach first disclosed in October 2025 affected about 25 million people in the United States.
7/12/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
American Lending Center reported that a July 2025 ransomware attack exposed names, birthdates, and Social Security information for 123,158 people, with notifications sent April 28, 2026.
5/12/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Fluke Corporation disclosed a data breach in 2025 involving third-party application access and possible Social Security number, birth date, and disability indicator exposure, with analysis completed in 2026.
5/15/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Ermi reported an employee email account data breach in Texas, with potential exposure of Social Security numbers and medical information, and ongoing class-action assessment.
5/28/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Missouri regulators escalated a Conduent Business Services cybersecurity breach investigation after regulators said Conduent did not provide needed information for assessing consumer impact.
5/6/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Malwarebytes reported in February 2026 expanded scope of an October 2025 Conduent data breach affecting an estimated 25 million people in the United States.
7/12/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
TransUnion reported a late-July 2025 breach affecting 4.4 million consumers after exposure of Social Security numbers and contact data via a Salesforce-connected system.
4/13/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
DentaQuest disclosed a cybersecurity incident while ShinyHunters claimed extortion and publication of leaked data affecting about 2.6 million accounts.
6/9/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
NYC Health + Hospitals identified a February 2, 2026 breach traced to vendor access that exposed protected health and biometric data for at least 1.8 million people.
5/20/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Conduent Business Services notified over 25 million Americans after ransomware operators accessed sensitive benefit and HR records from October 2024 to January 2025.
5/2/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Ahdoot & Wolfson investigated a potential class action against Passco Companies LLC after a disclosed data security incident potentially exposed tenants and other connected individuals.
6/24/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
ShinyHunters claimed a May 2026 breach of DentaQuest cloud systems, exposing PII and PHI for about 2.6 million people and prompting notification compliance concerns.
6/7/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks & Wildlife Department disclosed a third-party vendor supply chain breach on June 18, 2026, exposing over 3 million records including driver's license and passport numbers.
6/21/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Centers Laboratory disclosed a 2025 breach affecting about 540,000 people in Cedar Knolls, New Jersey, after unauthorized access exposed health and identity records.
7/13/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
David Ludlow of NCC Group discusses cybersecurity measures and patient steps after a data breach at a major Australian healthcare provider affects patient information.
7/20/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
BlackFog reported ransomware-group claims against ViaQuest in Ohio during early 2026, potentially exposing health and disability data and implicating Ohio and HIPAA breach-notification timelines.
6/3/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Montana insurance regulator opened an investigation on Oct. 16 after Conduent's vendor breach exposed Social Security numbers and medical records for 462,000 Blue Cross Blue Shield Montana customers.
1/1/1900 • Data Breaches & Exposure Events • Consumer Data Breaches
ColorTokens threat advisory reports ransomware and healthcare data exposures tied to stolen credentials, identity vulnerabilities, and third-party application access in the 2020s.
7/1/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Xsolis disclosed a January 2026 phishing-based incident exposing personal and protected health information, with patient notices and identity monitoring offered to eligible individuals.
6/16/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
DeXpose reports 2025 incidents across Oracle Cloud, Oracle EBS, and Oracle Health after CloudSEK observed credentials sold online and CISA issued an active-threat advisory.
5/16/2026 • Data Breaches & Exposure Events • Corporate Data Leaks
Patients and health care providers affected by a data breach at TriZetto Provider Solutions between November 2024 and October 2 2025 in the United States.
2/17/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
DentaQuest reported a May 2026 unauthorized-access incident that may have exposed health insurance and Medicaid identifiers affecting about 2.6 million people in the USA.
6/10/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Firstsource notified individuals in response to a potential programming-error platform incident involving protected health information and standalone Social Security numbers.
7/16/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Conduent disclosed in 2026 that a breach dating back to late 2024 exposed personal and medical data of more than 25 million individuals across Texas and Oregon.
2/23/2026 • Data Breaches & Exposure Events • Consumer Data Breaches
WP Company LLC disclosed a July 10, 2025 breach with Vermont and Texas notices filed in July 2026, exposing Social Security, government ID, financial, and health insurance data.
7/15/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Charlie Condon Law Firm, LLC disclosed unauthorized access between October 4 and October 6, 2025, potentially exposing data for about 2,975 people and notifying affected individuals starting May 8, 2026.
5/11/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Perkins Coie LLP disclosed a January 26-27, 2026 unauthorized access incident involving a single account and possible exposure of personal, financial, and health-related data.
6/22/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Operation PAR, Boley Centers, and Eleos notified individuals in 2026 after discovering a June 2025 unauthorized network intrusion that may have involved patient and employee personal information.
7/2/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
American Lending Center notified U.S. residents in multiple states after ransomware activity raised concerns about unauthorized access to personal information, with a review completed April 8, 2026.
5/12/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
RXNT reported unauthorized access to personal data between March 1 and March 3, 2026, and started customer notifications in May 2026 while offering credit monitoring services.
6/4/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
MasTec, Inc. disclosed unauthorized third-party access to part of its network lasting several days in August 2025, with individual notifications starting May 2026.
6/8/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
UBEO Midco LLC disclosed a June 2025 unauthorized-access incident discovered May 13, 2026 in San Antonio, Texas, affecting 3,845 individuals with Social Security and medical data.
6/18/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Qilin ransomware posted 1-800-dentist to a data leak site on June 28, 2026, alleging exposure risks for millions of consumer callers and dental practice data.
6/29/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
DentaQuest disclosed an early-June 2026 unauthorized access incident after ShinyHunters leaked 234GB of stolen data exposing about 2.6 million accounts.
6/5/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Yahoo disclosed in 2016-2017 that 2013-2014 cyberattacks exposed up to three billion accounts, with DOJ indictments and SEC penalties for delayed disclosure.
7/18/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
NAIC disclosed unauthorized access to PeopleSoft systems on June 17, 2026, tied to ShinyHunters activity, with FBI involvement and online publication of alleged data by June 25.
6/29/2026 • Cybersecurity (Privacy-Relevant) • Cybersecurity Tech (Privacy-Relevant): Data Breaches & Mass Exposures
SafePay claimed responsibility in a months-long ransomware intrusion against Conduent Business Services, allegedly exposing Tennessee residents medical and identity data and prompting class actions.
5/21/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Texas Parks and Wildlife Department disclosed a vendor incident discovered by Texas Cyber Command that may have exposed PII of more than 3 million hunting and fishing license customers.
7/6/2026 • Data Breaches & Exposure Events • third-party/vendor Breaches
Project Consulting Services, Inc. disclosed a February 25-26, 2026 unauthorized-access incident on June 9, 2026 affecting three New Hampshire residents' Social Security numbers.
6/11/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Monmouth University notified individuals starting June 30, 2026, after a forensic review found unauthorized access to PII beginning around February 5, 2026.
7/7/2026 • Data Breaches & Exposure Events • Data Breaches & Exposure Events: Consumer Data Breaches
Capital One, NPD, Jerico Pictures, MGM Resorts, and Moody's illustrate that data breach harm can last years through litigation, contracting losses, credit impacts, and sustained regulatory oversight.
4/27/2026 • Cybersecurity (Privacy-Relevant) • Data Breaches & Mass Exposures
IBM and the Singapore Land Authority incident compromised personal information for about 70,000 people, with June discovery and legacy retention issues driving exposure.
7/4/2026 • Corporate Data Practices & Accountability • Corporate Data Practices & Accountability: Data Retention Policies