Incident tracker
Recent cyber attacks and data breaches
This view includes companies named on ransomware leak sites. Those are the gangs’ claims, not verified breaches.
| Disclosed | Company | What happened | Type | Records | Source |
|---|---|---|---|---|---|
| 2026-09-08 | Veradigm Inc. Services-Computer Integrated Systems Design | Veradigm Inc. disclosed a cybersecurity incident Veradigm Inc. (the "Company") recently learned that one of its third-party vendors experienced a cybersecurity incident that impacted certain data associated with a small number of the Company's customers. Based on the Company's investigation to date, an unauthorized party obtained credentials from the vendor's environment to a Company application programming interface used by the vendor to provide services on behalf of the Company's customers. The unauthorized party used these credentials to download copies of certain personal data of patients, including, in some instances, Social Security numbers; no clinical or medical data was involved. The vendor's compromised credentials provided access only through that limited interface and did not provide access to any other part of the Company's environment, including the Company's broader network, servers, databases, or other systems. The incident did not result in any operational disruptions. The Company promptly initiated its cybersecurity incident response protocols upon learning of the incident and has notified law enforcement. The Company's investigation is ongoing. The Company is reviewing the affected data, and affected customers and individuals are being notified, with credit monitoring services being offered where applicable. The Company has not yet determined the extent of any potential liabilities associated with this matter. However, based on the information currently available, the Company does not believe that this incident is reasonably likely to have a material impact on the Company's business, operations, financial condition, or results of operations. This Current Report on Form 8-K contains forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995. These forward-looking statements are based on the current beliefs and expectations of the Company with respect to the cybersecurity incident and its impact on the Company's business, operations and financial results, only speak as of the date that they are made, and are subject to significant risks and uncertainties. Such statements can be identified by the use of words such as "future," "anticipates," "believes," "estimates," "expects," "intends," "plans," "predicts," "will," "would," "could," "continue," "can," "may," "look forward," "aims," "hopes," and "seeks" and similar terms, although not all forward-looking statements contain such words or expressions. Actual results could differ significantly from those set forth in the forward-looking statements. Important factors that may cause actual results to differ materially from those in the forward-looking statements include, but are not limited to, legal, reputational, and financial risks resulting from the cybersecurity incident, including any related regulatory inquiries, litigation, or remediation costs, and other factors contained in "Part 1, Item 1A. "Risk Factors" in the Company's Annual Report on Form 10-K for each of the fiscal years ended December 31, 2024 and December 31, 2023, and the Company's other filings with the SEC from time to time. The Company does not undertake to update any forward-looking statements to reflect changed assumptions, the impact of circumstances or events that may arise after the date of the forward-looking statements, or other changes over time, except as required by law. | Regulatory filing | Not disclosed | SEC EDGAR ↗ |
| 2026-09-08 | BOSTON SCIENTIFIC CORPBSX Surgical & Medical Instruments & Apparatus | BOSTON SCIENTIFIC CORP disclosed a material cybersecurity incident On August 25, 2026, Boston Scientific Corporation (the " Company ") identified a cybersecurity incident affecting certain of its information technology systems that has resulted in a global disruption to the Company's operations. Upon detection, the Company activated its incident response protocols and began an investigation with the assistance of third-party cybersecurity experts to assess and to contain the threat. The incident has caused, and is expected to continue to cause, disruptions and limitations of access to certain of the Company's information systems and business applications that support aspects of the Company's operations, including the ability to process and ship customer orders. While the Company is working diligently to restore affected functions and systems access, the timeline for a full restoration is not yet known. The Company's investigation of the cybersecurity incident is ongoing, and the full scope, nature and impacts, including operational and financial impacts, of the incident are not yet known. Accordingly, the Company has not yet determined whether the incident is reasonably likely to have a material impact on the Company. Cautionary Statement Regarding Forward-Looking Statements Certain statements that we may make from time to time, including statements contained in this Current Report on Form 8-K and information incorporated by reference herein, constitute "forward-looking statements" within the meaning of Section 27A of the Securities Act of 1933 and Section 21E of the Securities Exchange Act of 1934. Forward-looking statements may be identified by words like "anticipate," "expect," "project," "believe," "plan," "estimate," "intend," "aim," "goal," "target," "continue," "hope," "may" and similar words. These forward-looking statements are based on our beliefs, assumptions and estimates using information available to us at the time and are not intended to be guarantees of future events or performance. These forward-looking statements include, among other things, statements regarding the Company's current understanding regarding the extent of the cybersecurity incident and the results or findings of the Company's investigation thereof; the Company's ability to contain and/or mitigate the incident, and the timing thereof; the potential impact or disruption to the Company's business or operations; and the potential impact on the Company's reputation, financial condition and results of operations. If our underlying assumptions turn out to be incorrect, or if certain risks or uncertainties materialize, actual results could vary materially from the expectations and projections expressed or implied by our forward-looking statements. These factors, in some cases, have affected and in the future (together with other factors) could affect our ability to implement our business strategy and may cause actual results to differ materially from those contemplated by the statements expressed in this Current Report on Form 8-K. As a result, readers are cautioned not to place undue reliance on any of our forward-looking statements. Factors that may cause such differences include, among other things: economic conditions, including the impact of foreign currency fluctuations; future U.S. and global political, competitive, reimbursement and regulatory conditions, including changing trade and tariff policies; geopolitical conflicts and tensions; manufacturing, distribution and supply chain disruptions and cost increases; disruptions caused by cybersecurity events, including the results of the Company's investigation into the cybersecurity incident, any impairment to the Company's systems or data, delays or difficulties in restoring the Company's systems and data, the adequacy of processes during the period of disruption of the Company's systems, or the Company's ability to use alternatives to its systems to the extent needed; the unauthorized release of any confidential data or information of the Company, includi | Regulatory filing | Not disclosed | SEC EDGAR ↗ +1 more |
| 2026-09-07 | Partners Group SK | Partners Group SK named on qilin's leak site Finance | Ransomware claimClaimed by qilin · not verified | Not disclosed | RansomLook ↗ |
| 2026-09-07 | State of Florida DMV | State of Florida DMV named on shinyhunters's leak site Contact us, you know how. or we will release the files. View download button below for proof (samples). Deadline : 9 11 2026 | Ransomware claimClaimed by shinyhunters · not verified | Not disclosed | RansomLook ↗ |
| 2026-09-07 | NorthShore Health Centers | NorthShore Health Centers named on insomnia's leak site NorthShore Health Centers offers comprehensive care in Indiana, including behavioral health, dental, pediatrics, and women’s health. It runs multiple health centers and mobile units across Porter, Lake, La Porte, and Jasper counties. | Ransomware claimClaimed by insomnia · not verified | Not disclosed | RansomLook ↗ |
| 2026-09-07 | Wellness Partners network(combined revenue) | Wellness Partners network(combined revenue) named on inc ransom's leak site | Ransomware claimClaimed by inc ransom · not verified | Not disclosed | RansomLook ↗ |
| 2026-09-07 | Alurwalls | Alurwalls named on dark project's leak site Alurwalls was attacked, resulting in the theft of approximately 17 GB of confidential data. The stolen information includes banking and other financial documents, client building plans, and other personal data belonging to the company and its partners. Currently, more than 16,000 files are no longer protected by Alurwalls. | Ransomware claimClaimed by dark project · not verified | Not disclosed | RansomLook ↗ |
| 2026-09-07 | Master Manufacturing Co., Inc. | Master Manufacturing Co., Inc. named on dark project's leak site Master Manufacturing Co specializing in custom metal stamping and production services has fallen victim to a significant cyberattack. Hackers reportedly exfiltrated 36 gigabytes of sensitive data from the company’s servers. The stolen information includes SQL databases containing personal data, as well as technical plans and schematics for custom metal parts. The breach raises serious concerns regarding intellectual property theft and potential privacy violations for employees and clients. | Ransomware claimClaimed by dark project · not verified | Not disclosed | RansomLook ↗ |
| 2026-09-07 | United Group | United Group named on vexy's leak site United Group is a diversified Indian business group delivering innovative products and services across multiple industries. Founded in 2003, the company began as a food and beverage consultancy and has since expanded into food ingredients, nutraceuticals, industrial machinery, infrastructure, fashion, digital branding, packaging, and automotive accessories. With a strong focus on quality, innovation, and customer satisfaction, United Group operates through a network of specialized businesses, serving clients across India and international markets. Backed by certified manufacturing facilities and experienced professionals, the group is committed to providing reliable, sustainable, and value-driven solutions that support business growth and long-term success. | Ransomware claimClaimed by vexy · not verified | Not disclosed | RansomLook ↗ |
| 2026-09-07 | TrainMe | TrainMe named on direwolf's leak site | Ransomware claimClaimed by direwolf · not verified | Not disclosed | RansomLook ↗ |
About this tracker
- 442
- Incidents
- 318
- Ransomware gang claims
- 760
- Last 30 days
- 420
- Companies tracked
- 2,742,606,708
- Records disclosed