Incident tracker

Recent cyber attacks and data breaches

This view includes companies named on ransomware leak sites. Those are the gangs’ claims, not verified breaches.

DisclosedCompanyWhat happenedTypeRecordsSource
2026-09-04Bimbo Bakeries USA (Oracle)Bimbo Bakeries USA (Oracle): a data breach

Bimbo Bakeries USA (Oracle) notified the Washington State Attorney General on September 4, 2026 of a data breach that occurred on August 9, 2025, affecting 786 Washington residents. Information involved: Name, Social Security Number, Financial & Banking Information.

Data breach
Not disclosedWashington State Attorney General
2026-09-04Catalyst Brands LLCCatalyst Brands LLC: a data breach

Catalyst Brands LLC notified the Washington State Attorney General on September 4, 2026 of a data breach that occurred on May 20, 2026, affecting 4,015 Washington residents. Information involved: Name, Social Security Number, Driver's License or Washington ID Card Number, Financial & Banking Information, Full Date of Birth, Military ID Number, Passport Number, Email Address and Password/Security Question Answers, Other.

Data breach
Not disclosedCalifornia Attorney General

+1 more

2026-09-04LHC Group, Inc.LHC Group, Inc.: a data breach

LHC Group, Inc. notified the Washington State Attorney General on September 4, 2026 of a data breach that occurred on April 7, 2026, affecting 6,602 Washington residents. Information involved: Name, Social Security Number, Financial & Banking Information, Full Date of Birth, Health Insurance Policy or ID Number, Medical Information, Protected Health Information owned or licensed by a HIPAA covered entity.

Data breach
Not disclosedWashington State Attorney General
2026-09-04Beaver County Behavioral Health

Healthcare

Beaver County Behavioral Health: a health data breach

Beaver County Behavioral Health, a healthcare provider in PA, reported a breach of health information affecting 501 people to the US Department of Health and Human Services on September 4, 2026. HHS records the breach type as hacking/it incident, involving network server.

Data breach
501HHS Office for Civil Rights
2026-09-03Virta Health Corp. and Virta Medical, PC (Department of Health And Human Services)Virta Health Corp. and Virta Medical, PC (Department of Health And Human Services): a data breach

Virta Health Corp. and Virta Medical, PC (Department of Health And Human Services) notified the Washington State Attorney General on September 3, 2026 of a data breach that occurred on March 19, 2026, affecting 134 Washington residents. Information involved: Name, Social Security Number, Full Date of Birth, Health Insurance Policy or ID Number, Medical Information, Protected Health Information owned or licensed by a HIPAA covered entity.

Data breach
Not disclosedWashington State Attorney General
2026-09-02Manchester Airports GroupManchester Airports Group: a data breach

In August 2026, Manchester Airports Group (MAG) disclosed a data breach impacting their services . The incident was later claimed by the FulcrumSec hacking group , who subsequently published email addresses and phone numbers relating to 8.8M customers of Manchester, Stansted and East Midlands airports. The data contained personal information relating to airport services, including vehicle registrations and parking history, Fast Track purchases and lounge bookings. In their disclosure notice , MAG advised that "at no point has passenger safety or aviation security been compromised".

Data breach
8,849,657Have I Been Pwned
2026-09-02Fishbrain ABFishbrain AB: a data breach

Fishbrain AB notified the California Attorney General of a data breach on September 2, 2026, with the breach dated July 30, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-09-02Knowledge Research CenterKnowledge Research Center: a data breach

Knowledge Research Center notified the California Attorney General of a data breach on September 2, 2026, with the breach dated July 8, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-09-02YouLend US LLCYouLend US LLC: a data breach

YouLend US LLC notified the California Attorney General of a data breach on September 2, 2026, with the breach dated June 5, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General

+1 more

2026-09-02HumanEdge, Inc.HumanEdge, Inc.: a data breach

HumanEdge, Inc. notified the California Attorney General of a data breach on September 2, 2026, with the breach dated March 17, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General

About this tracker

442
Incidents
320
Ransomware gang claims
762
Last 30 days
425
Companies tracked
2,742,606,708
Records disclosed