Incident tracker

Recent cyber attacks and data breaches

This view includes companies named on ransomware leak sites. Those are the gangs’ claims, not verified breaches.

DisclosedCompanyWhat happenedTypeRecordsSource
2026-09-02Fiesta Insurance Franchise CorporationFiesta Insurance Franchise Corporation: a data breach

Fiesta Insurance Franchise Corporation notified the California Attorney General of a data breach on September 2, 2026, with the breach dated May 25, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General

+1 more

2026-09-02See’s Candies, Inc.See’s Candies, Inc.: a data breach

See’s Candies, Inc. notified the California Attorney General of a data breach on September 2, 2026, with the breach dated April 11, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General

+1 more

2026-09-01QuestelQuestel: a data breach

In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising corporate contact information associated with sales leads, support cases and marketing activities, with 1.2M unique email addresses. The data also included names, employers and job titles, along with physical addresses and phone numbers.

Data breach
1,226,209Have I Been Pwned
2026-09-01Kaniksu Community HealthKaniksu Community Health: a data breach

Kaniksu Community Health notified the California Attorney General of a data breach on September 1, 2026, with the breach dated December 18, 2025. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-09-01DeMera DeMera Cameron, LLPDeMera DeMera Cameron, LLP: a data breach

DeMera DeMera Cameron, LLP notified the California Attorney General of a data breach on September 1, 2026, with the breach dated March 27, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-09-01NovoCure LtdNVCR

Surgical & Medical Instruments & Apparatus

NovoCure Ltd disclosed a cybersecurity incident

In mid-August 2026, NovoCure Limited (the "Company," "we," or "us") through a subsidiary, became aware of unauthorized access to some of its information systems. Upon detecting the unauthorized access, the Company activated its cybersecurity response plan, implemented containment measures, and initiated an internal investigation of the event. The Company also engaged independent cybersecurity forensic experts to assist with the investigation, including reviewing the exposed data that was accessed. Based on the investigation to date, the Company determined that the exposed data included: internal Company patient ID numbers for over 1,400 U.S. patient records (these ID numbers are only used internally and no patient names or other identifying data for these was exposed); patient data for fewer than 50 other patients in the western U.S. that included additional identifying information; general contact information for healthcare providers we work with; and general contact information for Novocure employees, such as their job titles and phone numbers. No access to any of our medical treatment devices was obtained, our ability to operate has not been compromised and all of our systems are fully functional. The Company takes its obligation to safeguard privacy and security of its patients' data very seriously. The Company continues to evaluate applicable regulatory and legal notification requirements and will make all required notifications based on its findings, including to impacted patients. At this time, we do not believe that this cybersecurity incident will have a material impact or reasonably likely material impact on our financial condition and results of operations; however, at the time of this filing we are continuing to ascertain additional information regarding this incident. If additional information is obtained whereby we determine this cybersecurity incident will have a material impact or reasonably likely material impact on our financial condition and results of operations, we undertake to file an amendment to this Form 8-K filing under Item 1.05 containing such information within four business days after we, without unreasonable delay, determine such information, or within four business days after such information becomes available. Forward-Looking Statements In addition to historical facts or statements of current condition, this press release may contain forward-looking statements. Forward-looking statements provide Novocure's current expectations or forecasts of future events. These may include statements regarding anticipated scientific progress on its research programs, clinical study progress, development of potential products, interpretation of clinical results, prospects for regulatory approval, manufacturing development and capabilities, market prospects for its products, coverage, collections from third-party payers and other statements regarding matters that are not historical facts. You may identify some of these forward-looking statements by the use of words in the statements such as "anticipate," "estimate," "expect," "project," "intend," "plan," "believe" or other words and terms of similar meaning. Novocure's performance and financial results could differ materially from those reflected in these forward-looking statements due to general financial, economic, environmental, regulatory and political conditions and other more specific risks and uncertainties facing Novocure such as those set forth in its Annual Report on Form 10-K filed on February 26, 2026, and subsequent flings with the U.S. Securities and Exchange Commission. Given these risks and uncertainties, any or all of these forward-looking statements may prove to be incorrect. Therefore, you should not rely on any such factors or forward-looking statements. Furthermore, Novocure does not intend to update publicly any forward-looking statement, except as required by law. Any forward-looking statements herein speak only as of the date hereof. T

Regulatory filing
Not disclosedSEC EDGAR
2026-09-01Park Dental Partners, Inc.PARK

Services-Misc Health & Allied Services, NEC

Park Dental Partners, Inc. disclosed a material cybersecurity incident
Regulatory filing
Not disclosedSEC EDGAR
2026-08-31Virta Health Corp. and Virta Medical, PCVirta Health Corp. and Virta Medical, PC: a data breach

Virta Health Corp. and Virta Medical, PC notified the California Attorney General of a data breach on August 31, 2026, with the breach dated March 19, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-08-31Berkeley Research Group, LLCBerkeley Research Group, LLC: a data breach

Berkeley Research Group, LLC notified the California Attorney General of a data breach on August 31, 2026, with the breach dated February 28, 2025. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-08-31Nutex Health Inc.NUTX

Services-Business Services, NEC

Nutex Health Inc. disclosed a material cybersecurity incident
Regulatory filing
Not disclosedSEC EDGAR

About this tracker

442
Incidents
320
Ransomware gang claims
762
Last 30 days
425
Companies tracked
2,742,606,708
Records disclosed