Incident tracker

Recent cyber attacks and data breaches

DisclosedCompanyWhat happenedTypeRecordsSource
2026-09-14CENTERPOINT ENERGY INCCNP

Electric Services

CENTERPOINT ENERGY INC disclosed a cybersecurity incident

In September 2026, CenterPoint Energy, Inc. (the "Company") became aware of an online post by a third party claiming to have obtained a data set containing certain of the Company's customer information. Upon becoming aware of the post, the Company promptly took action and activated its cybersecurity incident response protocols, initiated an investigation with the assistance of third-party cybersecurity experts, and took steps to further protect the Company's systems. The Company's delivery of electric and gas services has not been impacted and remains operational and undisrupted. As of the date of this filing, the Company does not believe it is reasonably likely that there will be a material impact on the Company's financial condition or results of operations. While the investigation remains ongoing, the Company has determined that an unauthorized third party obtained personal information relating to a portion of the Company's customers through one of the Company's external facing systems (the "Incident"). The Company is continuing to work with third-party experts to determine the scope of customers and personal information affected by the Incident and intends to notify affected customers and regulatory authorities as required by applicable law. The Company reported the matter to law enforcement authorities and has notified certain regulatory authorities of the issue. The Company has incurred, and expects to continue to incur, certain expenses related to the Incident and its response to the Incident. The Company maintains customary cybersecurity insurance coverage and believes this insurance will offset related costs. Forward-Looking Statements This Current Report on Form 8-K (the "Current Report") may contain "forward-looking statements" within the meaning of Section 27A of the Securities Act and Section 21E of the Exchange Act. All statements other than statements of historical fact included in this Current Report are forward-looking statements made in good faith by us and are intended to qualify for the safe harbor from liability established by the Private Securities Litigation Reform Act of 1995. When used in this Current Report, the words "continue," "may," "potential," "will" or other similar words are intended to identify forward-looking statements. These forward-looking statements are based upon assumptions of management which are believed to be reasonable at the time made and are subject to significant risks and uncertainties. Actual events and results may differ materially from those expressed or implied by these forward-looking statements. The Company assumes no obligation and does not intend to update or revise these forward-looking statements, whether as a result of new information, future events or otherwise, except as required by securities and other applicable laws. Forward-looking statements include, but are not limited to, our expectations regarding any impact on the Company's financial condition or results of operations, the timing and nature of expenses in connection with the Incident, availability of insurance and potential impact on customers and the Company. Each forward-looking statement contained in this Current Report speaks only as of the date of this report. Important factors that could cause actual results to differ materially from those indicated by the provided forward-looking information include risks and uncertainties relating to (1) the timing and nature of any remediation expenses incurred in connection with the Incident, (2) the availability of cybersecurity insurance proceeds, (3) the extent of regulatory compliance obligations, (4) the risk that the scope of the Incident is greater than initially expected and (5) other factors discussed in the Company's Annual Report on Form 10-K for the fiscal year ended December 31, 2025, the Company's Quarterly Reports on Form 10-Q for the quarters ended March 31, 2026 and June 30, 2026 and other reports the Company may file from time to time with

Regulatory filing
Not disclosedSEC EDGAR
2026-09-13Chess.com (2026)Chess.com (2026): a data breach

In August 2026, millions of records allegedly sourced from Chess.com were posted online . The data contained 7.3M rows with 4.6M unique email addresses, along with usernames, names, countries and data relating to users' Chess.com accounts. Analysis of the data suggested it had been obtained by scraping. When loaded into HIBP, 99% of the email addresses had already appeared in previous data breaches, further supporting the scraping theory. Read more about scrapes and data breaches.

Data breach
4,653,212Have I Been Pwned
2026-09-10McKessonMcKesson: a data breach

In August 2026, healthcare and pharmaceutical company McKesson was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published a substantial corpus of data they alleged was sourced from the company, which included 6.4M unique email addresses among other personal and corporate data attributes. The impacted data related to a range of individuals and roles, including marketing campaign recipients, patients, staff and healthcare provider contacts. In McKesson's disclosure notice , the company advised it had identified unauthorised access to "certain third-party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units", but had "reasonable assurance of no ongoing unauthorized activity".

Data breach
6,404,340Have I Been Pwned
2026-09-09Quatrro Business Support Services, Inc.Quatrro Business Support Services, Inc.: a data breach

Quatrro Business Support Services, Inc. notified the Washington State Attorney General on September 9, 2026 of a data breach that occurred on November 11, 2025, affecting 10,008 Washington residents. Information involved: Name, Social Security Number, Driver's License or Washington ID Card Number, Financial & Banking Information, Passport Number, Health Insurance Policy or ID Number, Medical Information.

Data breach
Not disclosedWashington State Attorney General
2026-09-08Hibbett Retail, Inc.Hibbett Retail, Inc.: a data breach

Hibbett Retail, Inc. notified the Washington State Attorney General on September 8, 2026 of a data breach that occurred on April 22, 2026, affecting 510 Washington residents. Information involved: Name, Social Security Number, Driver's License or Washington ID Card Number, Financial & Banking Information, Full Date of Birth, Student ID Number, Military ID Number, Passport Number, Health Insurance Policy or ID Number, Medical Information.

Data breach
Not disclosedWashington State Attorney General
2026-09-08Veradigm Inc.

Services-Computer Integrated Systems Design

Veradigm Inc. disclosed a cybersecurity incident

Veradigm Inc. (the "Company") recently learned that one of its third-party vendors experienced a cybersecurity incident that impacted certain data associated with a small number of the Company's customers. Based on the Company's investigation to date, an unauthorized party obtained credentials from the vendor's environment to a Company application programming interface used by the vendor to provide services on behalf of the Company's customers. The unauthorized party used these credentials to download copies of certain personal data of patients, including, in some instances, Social Security numbers; no clinical or medical data was involved. The vendor's compromised credentials provided access only through that limited interface and did not provide access to any other part of the Company's environment, including the Company's broader network, servers, databases, or other systems. The incident did not result in any operational disruptions. The Company promptly initiated its cybersecurity incident response protocols upon learning of the incident and has notified law enforcement. The Company's investigation is ongoing. The Company is reviewing the affected data, and affected customers and individuals are being notified, with credit monitoring services being offered where applicable. The Company has not yet determined the extent of any potential liabilities associated with this matter. However, based on the information currently available, the Company does not believe that this incident is reasonably likely to have a material impact on the Company's business, operations, financial condition, or results of operations. This Current Report on Form 8-K contains forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995. These forward-looking statements are based on the current beliefs and expectations of the Company with respect to the cybersecurity incident and its impact on the Company's business, operations and financial results, only speak as of the date that they are made, and are subject to significant risks and uncertainties. Such statements can be identified by the use of words such as "future," "anticipates," "believes," "estimates," "expects," "intends," "plans," "predicts," "will," "would," "could," "continue," "can," "may," "look forward," "aims," "hopes," and "seeks" and similar terms, although not all forward-looking statements contain such words or expressions. Actual results could differ significantly from those set forth in the forward-looking statements. Important factors that may cause actual results to differ materially from those in the forward-looking statements include, but are not limited to, legal, reputational, and financial risks resulting from the cybersecurity incident, including any related regulatory inquiries, litigation, or remediation costs, and other factors contained in "Part 1, Item 1A. "Risk Factors" in the Company's Annual Report on Form 10-K for each of the fiscal years ended December 31, 2024 and December 31, 2023, and the Company's other filings with the SEC from time to time. The Company does not undertake to update any forward-looking statements to reflect changed assumptions, the impact of circumstances or events that may arise after the date of the forward-looking statements, or other changes over time, except as required by law.

Regulatory filing
Not disclosedSEC EDGAR
2026-09-08BOSTON SCIENTIFIC CORPBSX

Surgical & Medical Instruments & Apparatus

BOSTON SCIENTIFIC CORP disclosed a material cybersecurity incident

On August 25, 2026, Boston Scientific Corporation (the " Company ") identified a cybersecurity incident affecting certain of its information technology systems that has resulted in a global disruption to the Company's operations. Upon detection, the Company activated its incident response protocols and began an investigation with the assistance of third-party cybersecurity experts to assess and to contain the threat. The incident has caused, and is expected to continue to cause, disruptions and limitations of access to certain of the Company's information systems and business applications that support aspects of the Company's operations, including the ability to process and ship customer orders. While the Company is working diligently to restore affected functions and systems access, the timeline for a full restoration is not yet known. The Company's investigation of the cybersecurity incident is ongoing, and the full scope, nature and impacts, including operational and financial impacts, of the incident are not yet known. Accordingly, the Company has not yet determined whether the incident is reasonably likely to have a material impact on the Company. Cautionary Statement Regarding Forward-Looking Statements Certain statements that we may make from time to time, including statements contained in this Current Report on Form 8-K and information incorporated by reference herein, constitute "forward-looking statements" within the meaning of Section 27A of the Securities Act of 1933 and Section 21E of the Securities Exchange Act of 1934. Forward-looking statements may be identified by words like "anticipate," "expect," "project," "believe," "plan," "estimate," "intend," "aim," "goal," "target," "continue," "hope," "may" and similar words. These forward-looking statements are based on our beliefs, assumptions and estimates using information available to us at the time and are not intended to be guarantees of future events or performance. These forward-looking statements include, among other things, statements regarding the Company's current understanding regarding the extent of the cybersecurity incident and the results or findings of the Company's investigation thereof; the Company's ability to contain and/or mitigate the incident, and the timing thereof; the potential impact or disruption to the Company's business or operations; and the potential impact on the Company's reputation, financial condition and results of operations. If our underlying assumptions turn out to be incorrect, or if certain risks or uncertainties materialize, actual results could vary materially from the expectations and projections expressed or implied by our forward-looking statements. These factors, in some cases, have affected and in the future (together with other factors) could affect our ability to implement our business strategy and may cause actual results to differ materially from those contemplated by the statements expressed in this Current Report on Form 8-K. As a result, readers are cautioned not to place undue reliance on any of our forward-looking statements. Factors that may cause such differences include, among other things: economic conditions, including the impact of foreign currency fluctuations; future U.S. and global political, competitive, reimbursement and regulatory conditions, including changing trade and tariff policies; geopolitical conflicts and tensions; manufacturing, distribution and supply chain disruptions and cost increases; disruptions caused by cybersecurity events, including the results of the Company's investigation into the cybersecurity incident, any impairment to the Company's systems or data, delays or difficulties in restoring the Company's systems and data, the adequacy of processes during the period of disruption of the Company's systems, or the Company's ability to use alternatives to its systems to the extent needed; the unauthorized release of any confidential data or information of the Company, includi

Regulatory filing
Not disclosedSEC EDGAR

+1 more

2026-09-04Bimbo Bakeries USA (Oracle)Bimbo Bakeries USA (Oracle): a data breach

Bimbo Bakeries USA (Oracle) notified the Washington State Attorney General on September 4, 2026 of a data breach that occurred on August 9, 2025, affecting 786 Washington residents. Information involved: Name, Social Security Number, Financial & Banking Information.

Data breach
Not disclosedWashington State Attorney General
2026-09-04Catalyst Brands LLCCatalyst Brands LLC: a data breach

Catalyst Brands LLC notified the Washington State Attorney General on September 4, 2026 of a data breach that occurred on May 20, 2026, affecting 4,015 Washington residents. Information involved: Name, Social Security Number, Driver's License or Washington ID Card Number, Financial & Banking Information, Full Date of Birth, Military ID Number, Passport Number, Email Address and Password/Security Question Answers, Other.

Data breach
Not disclosedWashington State Attorney General
2026-09-04LHC Group, Inc.LHC Group, Inc.: a data breach

LHC Group, Inc. notified the Washington State Attorney General on September 4, 2026 of a data breach that occurred on April 7, 2026, affecting 6,602 Washington residents. Information involved: Name, Social Security Number, Financial & Banking Information, Full Date of Birth, Health Insurance Policy or ID Number, Medical Information, Protected Health Information owned or licensed by a HIPAA covered entity.

Data breach
Not disclosedWashington State Attorney General

About this tracker

307
Incidents
270
Ransomware gang claims
577
Last 30 days
383
Companies tracked
2,742,501,669
Records disclosed