Incident tracker
Recent cyber attacks and data breaches
This view includes companies named on ransomware leak sites. Those are the gangs’ claims, not verified breaches.
| Disclosed | Company | What happened | Type | Records | Source |
|---|---|---|---|---|---|
| 2026-08-03 | CTS Journey Holdings, LLC, a Delaware limited liability comp | CTS Journey Holdings, LLC, a Delaware limited liability comp: a data breach CTS Journey Holdings, LLC, a Delaware limited liability comp notified the Washington State Attorney General on August 3, 2026 of a data breach that occurred on December 3, 2025, affecting 2,226 Washington residents. Information involved: Name, Social Security Number, Driver's License or Washington ID Card Number, Financial & Banking Information, Full Date of Birth, Passport Number, Medical Information. | Data breach | Not disclosed | Washington State Attorney General ↗ |
| 2026-08-03 | PAMCAH-UA Local 675 Health and Welfare Fund Healthcare | PAMCAH-UA Local 675 Health and Welfare Fund: a health data breach PAMCAH-UA Local 675 Health and Welfare Fund, a health plan in HI, reported a breach of health information affecting 8,319 people to the US Department of Health and Human Services on August 3, 2026. HHS records the breach type as hacking/it incident, involving email. | Data breach | 8,319 | HHS Office for Civil Rights ↗ |
| 2026-08-01 | SplitVPN | SplitVPN: a data breach In July 2026, the Russian VPN service SplitVPN (previously known as NotVPN) suffered a data breach . The incident exposed millions of customer records, including 865k unique email addresses. Other impacted data included IP addresses, the user's country, and partial payment card data (first 6 and last 4 digits plus expiry date). | Data breach | 865,336 | Have I Been Pwned ↗ |
| 2026-07-31 | Everside Health | Everside Health: a data breach Everside Health notified the California Attorney General of a data breach on July 31, 2026, with the breach dated December 2, 2025. The notice covers more than 500 California residents; California does not publish the exact number. | Data breach | Not disclosed | California Attorney General ↗ |
| 2026-07-31 | Stanislaus County Health Services Agency | Stanislaus County Health Services Agency: a data breach Stanislaus County Health Services Agency notified the California Attorney General of a data breach on July 31, 2026, with the breach dated December 2, 2025. The notice covers more than 500 California residents; California does not publish the exact number. | Data breach | Not disclosed | California Attorney General ↗ |
| 2026-07-31 | Everside Health (Aesto, LLC) | Everside Health (Aesto, LLC): a data breach Everside Health (Aesto, LLC) notified the Washington State Attorney General on July 31, 2026 of a data breach that occurred on December 2, 2025, affecting 21,308 Washington residents. Information involved: Name, Social Security Number, Full Date of Birth, Medical Information. | Data breach | Not disclosed | Washington State Attorney General ↗ |
| 2026-07-31 | Asheville Beaverdam NC Opco LLC d/b/a Bear Mountain Health and Rehabilitation Healthcare | Asheville Beaverdam NC Opco LLC d/b/a Bear Mountain Health and Rehabilitation: a health data breach Asheville Beaverdam NC Opco LLC d/b/a Bear Mountain Health and Rehabilitation, a healthcare provider in NC, reported a breach of health information affecting 1,397 people to the US Department of Health and Human Services on July 31, 2026. HHS records the breach type as hacking/it incident, involving electronic medical record, network server. | Data breach | 1,397 | HHS Office for Civil Rights ↗ |
| 2026-07-31 | Asheville Victoria NC Opco LLC d/b/a Elevate Health & Rehabilitation Healthcare | Asheville Victoria NC Opco LLC d/b/a Elevate Health & Rehabilitation: a health data breach Asheville Victoria NC Opco LLC d/b/a Elevate Health & Rehabilitation, a healthcare provider in NC, reported a breach of health information affecting 1,551 people to the US Department of Health and Human Services on July 31, 2026. HHS records the breach type as hacking/it incident, involving desktop computer, network server. | Data breach | 1,551 | HHS Office for Civil Rights ↗ |
| 2026-07-31 | Asheville US Seventy NC Opco LLC d/b/a Swannanoa Valley Health and Rehabilitation Healthcare | Asheville US Seventy NC Opco LLC d/b/a Swannanoa Valley Health and Rehabilitation: a health data breach Asheville US Seventy NC Opco LLC d/b/a Swannanoa Valley Health and Rehabilitation, a healthcare provider in NC, reported a breach of health information affecting 1,045 people to the US Department of Health and Human Services on July 31, 2026. HHS records the breach type as hacking/it incident, involving desktop computer, network server. | Data breach | 1,045 | HHS Office for Civil Rights ↗ |
| 2026-07-31 | Monongalia County General Hospital Company Healthcare | Monongalia County General Hospital Company: a health data breach Monongalia County General Hospital Company, a healthcare provider in WV, reported a breach of health information affecting 2,173 people to the US Department of Health and Human Services on July 31, 2026. HHS records the breach type as hacking/it incident, involving email. | Data breach | 2,173 | HHS Office for Civil Rights ↗ |
About this tracker
- 442
- Incidents
- 314
- Ransomware gang claims
- 756
- Last 30 days
- 414
- Companies tracked
- 2,742,606,708
- Records disclosed