Incident tracker

Recent cyber attacks and data breaches

This view includes companies named on ransomware leak sites. Those are the gangs’ claims, not verified breaches.

DisclosedCompanyWhat happenedTypeRecordsSource
2026-08-10Westchester Institute for Human Development, Inc.

Healthcare

Westchester Institute for Human Development, Inc.: a health data breach

Westchester Institute for Human Development, Inc., a healthcare provider in NY, reported a breach of health information affecting 938 people to the US Department of Health and Human Services on August 10, 2026. HHS records the breach type as hacking/it incident, involving email.

Data breach
938HHS Office for Civil Rights
2026-08-10Boston Healthcare for the Homeless Program

Healthcare

Boston Healthcare for the Homeless Program: a health data breach

Boston Healthcare for the Homeless Program, a healthcare provider in MA, reported a breach of health information affecting 201,260 people to the US Department of Health and Human Services on August 10, 2026. HHS records the breach type as hacking/it incident, involving network server.

Data breach
201,260California Attorney General

+1 more

2026-08-09AlconAlcon: a data breach

In August 2026, the Alcon eye care company was named in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data allegedly sourced from Alcon containing 218k unique email addresses along with other largely corporate B2B contact fields, including name, phone number and physical address.

Data breach
218,395Have I Been Pwned
2026-08-08Brinks HomeBrinks Home: a data breach

In July 2026, Brinks Home was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data they alleged was taken from the company, including 732k unique email addresses and other personal information relating to leads, customers and Brinks staff such as name, phone numbers and physical addresses. The data also included purchases from Brinks along with partial credit card data (last 4 digits, card type and expiry). In Brinks' disclosure notice , they acknowledged the incident and risk of disclosure, and advised that they would notify impacted parties "consistent with applicable law".

Data breach
732,162Have I Been Pwned
2026-08-07Exact SciencesExact Sciences: a data breach

In July 2026, Exact Sciences (now owned by Abbott Laboratories) was the target of a ShinyHunters "pay or leak" extortion campaign . The group claimed to have obtained data from the company's cancer diagnostics business, which they later published publicly. The breach contained 10.9M unique email addresses belonging to customers, patients and healthcare providers, along with names, addresses, phone numbers and health records. Abbott subsequently published a public notice advising that "some of the impacted files contain personal information and/or personal health information" and that more specific information would follow once their review of the incident was complete. For context, Exact Sciences is the maker of the Cologuard at-home colorectal cancer screening test.

Data breach
10,869,543Have I Been Pwned
2026-08-07Oklahoma Health Care Authority Employees Group Insurance Division

Healthcare

Oklahoma Health Care Authority Employees Group Insurance Division: a health data breach

Oklahoma Health Care Authority Employees Group Insurance Division, a health plan in OK, reported a breach of health information affecting 5,690 people to the US Department of Health and Human Services on August 7, 2026. HHS records the breach type as hacking/it incident, involving network server.

Data breach
5,690HHS Office for Civil Rights
2026-08-07American Addiction CentersAmerican Addiction Centers: a data breach

American Addiction Centers notified the Washington State Attorney General on August 7, 2026 of a data breach that occurred on May 12, 2026, affecting 1,155 Washington residents. Information involved: Name, Social Security Number, Health Insurance Policy or ID Number, Medical Information.

Data breach
Not disclosedWashington State Attorney General

+1 more

2026-08-07Golden Opportunities And Local Support, LLCGolden Opportunities And Local Support, LLC: a data breach

Golden Opportunities And Local Support, LLC notified the Washington State Attorney General on August 7, 2026 of a data breach. Information involved: Name, Full Date of Birth, Other, Protected Health Information owned or licensed by a HIPAA covered entity.

Data breach
Not disclosedWashington State Attorney General
2026-08-07Horizon Eye Care Laser & Eye Surgery Center

Healthcare

Horizon Eye Care Laser & Eye Surgery Center: a health data breach

Horizon Eye Care Laser & Eye Surgery Center, a healthcare provider in NJ, reported a breach of health information affecting 501 people to the US Department of Health and Human Services on August 7, 2026. HHS records the breach type as hacking/it incident, involving network server.

Data breach
501HHS Office for Civil Rights
2026-08-07Indico Data Solutions, Inc.

Healthcare

Indico Data Solutions, Inc.: a health data breach

Indico Data Solutions, Inc., a business associate in MA, reported a breach of health information affecting 4,840 people to the US Department of Health and Human Services on August 7, 2026. HHS records the breach type as hacking/it incident, involving network server.

Data breach
4,840HHS Office for Civil Rights

+1 more

About this tracker

442
Incidents
318
Ransomware gang claims
760
Last 30 days
420
Companies tracked
2,742,606,708
Records disclosed