Incident tracker

Recent cyber attacks and data breaches

This view includes companies named on ransomware leak sites. Those are the gangs’ claims, not verified breaches.

DisclosedCompanyWhat happenedTypeRecordsSource
2026-09-14AlicotransAlicotrans named on qilin's leak site

Freight & Logistics Services

Ransomware claimClaimed by qilin · not verified
Not disclosedRansomLook
2026-09-14Accela, Inc.Accela, Inc.: a data breach

Accela, Inc. notified the California Attorney General of a data breach on September 14, 2026, with the breach dated December 11, 2025. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-09-14CENTERPOINT ENERGY INCCNP

Electric Services

CENTERPOINT ENERGY INC disclosed a cybersecurity incident

In September 2026, CenterPoint Energy, Inc. (the "Company") became aware of an online post by a third party claiming to have obtained a data set containing certain of the Company's customer information. Upon becoming aware of the post, the Company promptly took action and activated its cybersecurity incident response protocols, initiated an investigation with the assistance of third-party cybersecurity experts, and took steps to further protect the Company's systems. The Company's delivery of electric and gas services has not been impacted and remains operational and undisrupted. As of the date of this filing, the Company does not believe it is reasonably likely that there will be a material impact on the Company's financial condition or results of operations. While the investigation remains ongoing, the Company has determined that an unauthorized third party obtained personal information relating to a portion of the Company's customers through one of the Company's external facing systems (the "Incident"). The Company is continuing to work with third-party experts to determine the scope of customers and personal information affected by the Incident and intends to notify affected customers and regulatory authorities as required by applicable law. The Company reported the matter to law enforcement authorities and has notified certain regulatory authorities of the issue. The Company has incurred, and expects to continue to incur, certain expenses related to the Incident and its response to the Incident. The Company maintains customary cybersecurity insurance coverage and believes this insurance will offset related costs. Forward-Looking Statements This Current Report on Form 8-K (the "Current Report") may contain "forward-looking statements" within the meaning of Section 27A of the Securities Act and Section 21E of the Exchange Act. All statements other than statements of historical fact included in this Current Report are forward-looking statements made in good faith by us and are intended to qualify for the safe harbor from liability established by the Private Securities Litigation Reform Act of 1995. When used in this Current Report, the words "continue," "may," "potential," "will" or other similar words are intended to identify forward-looking statements. These forward-looking statements are based upon assumptions of management which are believed to be reasonable at the time made and are subject to significant risks and uncertainties. Actual events and results may differ materially from those expressed or implied by these forward-looking statements. The Company assumes no obligation and does not intend to update or revise these forward-looking statements, whether as a result of new information, future events or otherwise, except as required by securities and other applicable laws. Forward-looking statements include, but are not limited to, our expectations regarding any impact on the Company's financial condition or results of operations, the timing and nature of expenses in connection with the Incident, availability of insurance and potential impact on customers and the Company. Each forward-looking statement contained in this Current Report speaks only as of the date of this report. Important factors that could cause actual results to differ materially from those indicated by the provided forward-looking information include risks and uncertainties relating to (1) the timing and nature of any remediation expenses incurred in connection with the Incident, (2) the availability of cybersecurity insurance proceeds, (3) the extent of regulatory compliance obligations, (4) the risk that the scope of the Incident is greater than initially expected and (5) other factors discussed in the Company's Annual Report on Form 10-K for the fiscal year ended December 31, 2025, the Company's Quarterly Reports on Form 10-Q for the quarters ended March 31, 2026 and June 30, 2026 and other reports the Company may file from time to time with

Regulatory filing
Not disclosedSEC EDGAR
2026-09-13Gilco ScaffoldingGilco Scaffolding named on qilin's leak site

Construction

Ransomware claimClaimed by qilin · not verified
Not disclosedRansomLook
2026-09-13Kimberly-ClarkKimberly-Clark named on shinyhunters's leak site

This is a final warning to reach out by 16 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.

Ransomware claimClaimed by shinyhunters · not verified
Not disclosedRansomLook
2026-09-13CARIDRO VAL DE LOIRECARIDRO VAL DE LOIRE named on qilin's leak site

Business Services

Ransomware claimClaimed by qilin · not verified
Not disclosedRansomLook
2026-09-13www.kashkha.comwww.kashkha.com named on krybit's leak site

Kashkha is a multinational modest fashion brand founded three decades ago in Dubai, UAE, specializing in designing, manu...

Ransomware claimClaimed by krybit · not verified
Not disclosedRansomLook
2026-09-13Chess.com (2026)Chess.com (2026): a data breach

In August 2026, millions of records allegedly sourced from Chess.com were posted online . The data contained 7.3M rows with 4.6M unique email addresses, along with usernames, names, countries and data relating to users' Chess.com accounts. Analysis of the data suggested it had been obtained by scraping. When loaded into HIBP, 99% of the email addresses had already appeared in previous data breaches, further supporting the scraping theory. Read more about scrapes and data breaches.

Data breach
4,653,212Have I Been Pwned
2026-09-13Strad SolutionsStrad Solutions named on vexy's leak site

Strad Solutions provides cloud hosting, dedicated servers, managed IT, cybersecurity, and disaster recovery services for businesses worldwide.

Ransomware claimClaimed by vexy · not verified
Not disclosedRansomLook
2026-09-13NavitransNavitrans named on emperador's leak site

Navitrans is a leading Colombian distributor and service provider specializing in commercial trucks and heavy machinery, offering a comprehensive range of products and services including vehicle sales, spare parts distribution, and maintenance and repair services through a nationwide network of workshops. This post includes sensitive data about prices, financing, and other operational information. Publication scheduled: 2026-09-23 13:01:31 UTC Size: 223.2 MB Sectors: Manufacturing, Transportation

Ransomware claimClaimed by emperador · not verified
Not disclosedRansomLook

About this tracker

435
Incidents
298
Ransomware gang claims
733
Last 30 days
401
Companies tracked
2,742,501,669
Records disclosed