U.S. Ransomware Breaches Expose Personal Data
Coverage from Class Action U, KREM, and others

Organizations across the United States are disclosing ransomware and other unauthorized-access incidents involving Social Security numbers, financial information, medical records, government identifiers, and other personal data.
Beacon Mutual is the largest and most heavily reported case, with an estimated 162,000 affected people and alleged links to INC Ransom, while other incidents involve groups including Akira, The Gentlemen, and SafePay. The disclosures are driving credit-monitoring offers, regulatory reporting, public warnings, and litigation over data security and notification timing.
The story broadens from a collection of U.S. organizational breaches into a wider ecosystem involving third-party data custodians, online platforms, leak indexing, and potentially tens of millions of accounts. The updated framing also emphasizes delayed disclosure and continuing accountability after forensic reviews.
The update broadens the story from Beacon Mutual and a few related breaches into a wider U.S. ransomware trend spanning multiple sectors and threat actors. It also reframes Beacon Mutual as part of a larger set of disclosures rather than the sole focal point.
The story has narrowed from a broader roundup of multiple breach incidents to a Beacon Mutual-centered account, adding specific timing, the reported leak-site claim, and the ensuing class-action litigation. It also now clarifies the notification timeline and identity-protection response, making the Beacon incident the clear focal point.
- Unauthorized access occurred between January 7 and January 14, 2026.
- INC RANSOM allegedly advertised 275 gigabytes of Beacon Mutual data.
- Beacon Mutual began mailing notifications in May 2026.
- A Rhode Island class-action complaint was filed over the breach.
- The current version reframes Beacon Mutual as the central incident.
The story now centers less on broad, partly unverified ransomware exposure claims and more on a specific set of newly detailed incidents involving major insurers, property firms, and municipalities, with clearer reporting on affected populations and service disruption. It also adds new named actors and a stronger emphasis on legal and notification consequences.
- Beacon Mutual now reported roughly 162,000 affected people.
- JRK Property Holdings disclosed possible exposure of renter and employee data.
- Middletown, Ohio linked its breach to municipal service disruption.
- SafePay appears as a new ransomware-group actor.
- Follow-on litigation is now explicitly part of the story.
The story now emphasizes larger-scale platform and third-party exposure cases, especially Paidwork, Suno, and Mercadien, alongside a clearer pattern of delayed forensic review and standardized remediation responses. It also adds uncertainty around some threat-actor data-release claims, making the overall picture broader and more operationally active than before.
- Paidwork exposure reportedly includes more than 23 million email addresses.
- Suno exposure reportedly includes more than 55 million email addresses.
- Mercadien systems exposed client and bank customer records.
- Kootenai County also reported a small number of fingerprints.
- Several data-release claims remain partly unverified.
The story now adds a distinct Suno angle, shifting part of the coverage from conventional ransomware/privacy breaches to a platform dispute involving exposed user records and alleged music-data scraping. It also introduces new scale details, including Beacon Mutual’s roughly 162,000 potentially affected people and Medtronic’s Vermont notice.
The story has shifted from a mixed set of breach disclosures to a more specific pattern of ransomware-driven incidents, with clearer attribution to named extortion groups and a stronger emphasis on delayed notice and litigation risk. The breadth of affected sectors and states also widened, especially with public-sector and property-related victims now prominent.
- Tor-posted extortion claims now accompany several ransomware intrusions.
- Driver license and biometric data are among the newly emphasized exposed records.
- Delayed discovery and public notice are now a recurring story element.
- At least one incident has progressed into class-action litigation.
- Public-sector and property firms are newly prominent breach victims.
The update sharpens the story around multiple breaches by adding new organizations and clarifying that some reported exposures are still partly unverified. It also distinguishes confirmed user-account exposure at Suno from separate, unconfirmed claims about source-code theft.
The story broadens beyond ransomware-linked insurer and contractor breaches to include major healthcare, HR, and consumer-platform incidents, with Suno’s reportedly massive account exposure now a standout element. The current version also emphasizes delayed investigation timelines and restoration support, while adding more specific organizations and data types.
- Suno incident reportedly affected more than 55 million user accounts.
- Medtronic disclosed potential exposure of 8,668 Vermont residents' data.
- Cardinal Services and Alcott HR are new employer-services breach disclosures.
- Have I Been Pwned reportedly ingested data from the Suno incident.
- Current reporting includes investigations into whether reasonable safeguards were in place.
The story has broadened from repeated ransomware-linked insurer and contractor breaches to include a new cluster of very large-scale credential and payment exposures from digital platforms. The reporting also more clearly emphasizes long-delayed disclosure and downstream litigation as recurring consequences.
The story has broadened from a general pattern of ransomware-linked data breaches into a more specific 2026 wave concentrated in insurers, contractors, and health-related entities, with delayed notices, state filings, and at least one lawsuit now central to the narrative. The new reporting also introduces additional threat actors and a clearer legal/regulatory follow-on risk.
- New ransomware actors include Akira, Interlock, DragonForce, and The Gentlemen.
- Delays between intrusion and notice often stretched from late 2025 or early 2026 into mid-2026.
- State filings now span many jurisdictions, including Massachusetts, Iowa, Nebraska, and Connecticut.
- A class-action lawsuit has been filed over inadequate safeguards and delayed notice.
- Health-related and property/contractor entities are now more prominent targets.
The story remains materially stable: ransomware incidents continue to be framed primarily as data-exposure events creating identity-theft and fraud risks. The current version broadens the named sector examples to include lending and architecture while giving less emphasis to litigation and delayed disclosure.
The story broadens beyond insurance, contractors, and property firms to include manufacturers and infrastructure-related organizations, while litigation appears more widespread than previously indicated.
The story broadened from a general cluster of ransomware-linked breaches into a more specific, more actionable pattern: delayed disclosures, multi-state regulatory reporting, and repeated remediation responses across insurance, construction, retail, and property services. Beacon Mutual remains the anchor, but the current version adds more named actors and frames the incidents as a stable wave of privacy harm rather than just isolated breaches.
- Several new named companies appear: Mullinax Ford, JRK Property Holdings, Alliance Roofing, and Carlson Building Maintenance.
- Disclosures are described as often arriving months after the initial intrusion.
- Notices now explicitly involve multiple state attorneys general and consumer agencies.
- Beacon Mutual is newly characterized as the largest case with follow-on litigation.
- The incident pattern is framed as direct privacy harm from ransomware-driven data theft.
This topic centers on a wave of ransomware-linked and unauthorized-access data breaches that exposed Social Security numbers, financial details, and other sensitive personal information. Beacon Mutual is the anchor case, with a large insurer reporting a compromise that may affect about 162,000 people, while related incidents show similar attack patterns across insurance, HR, real estate, automotive, and benefits-administration firms. The material is consistent in emphasizing notification efforts, forensic review, law-enforcement involvement, and identity protection offers, but the attacker identities and full scope often remain uncertain.
