Incident tracker

Recent cyber attacks and data breaches

This view includes companies named on ransomware leak sites. Those are the gangs’ claims, not verified breaches.

DisclosedCompanyWhat happenedTypeRecordsSource
2026-08-03CTS Journey Holdings, LLC, a Delaware limited liability compCTS Journey Holdings, LLC, a Delaware limited liability comp: a data breach

CTS Journey Holdings, LLC, a Delaware limited liability comp notified the Washington State Attorney General on August 3, 2026 of a data breach that occurred on December 3, 2025, affecting 2,226 Washington residents. Information involved: Name, Social Security Number, Driver's License or Washington ID Card Number, Financial & Banking Information, Full Date of Birth, Passport Number, Medical Information.

Data breach
Not disclosedWashington State Attorney General
2026-08-03PAMCAH-UA Local 675 Health and Welfare Fund

Healthcare

PAMCAH-UA Local 675 Health and Welfare Fund: a health data breach

PAMCAH-UA Local 675 Health and Welfare Fund, a health plan in HI, reported a breach of health information affecting 8,319 people to the US Department of Health and Human Services on August 3, 2026. HHS records the breach type as hacking/it incident, involving email.

Data breach
8,319HHS Office for Civil Rights
2026-08-01SplitVPNSplitVPN: a data breach

In July 2026, the Russian VPN service SplitVPN (previously known as NotVPN) suffered a data breach . The incident exposed millions of customer records, including 865k unique email addresses. Other impacted data included IP addresses, the user's country, and partial payment card data (first 6 and last 4 digits plus expiry date).

Data breach
865,336Have I Been Pwned
2026-07-31Everside HealthEverside Health: a data breach

Everside Health notified the California Attorney General of a data breach on July 31, 2026, with the breach dated December 2, 2025. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-07-31Stanislaus County Health Services AgencyStanislaus County Health Services Agency: a data breach

Stanislaus County Health Services Agency notified the California Attorney General of a data breach on July 31, 2026, with the breach dated December 2, 2025. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-07-31Everside Health (Aesto, LLC)Everside Health (Aesto, LLC): a data breach

Everside Health (Aesto, LLC) notified the Washington State Attorney General on July 31, 2026 of a data breach that occurred on December 2, 2025, affecting 21,308 Washington residents. Information involved: Name, Social Security Number, Full Date of Birth, Medical Information.

Data breach
Not disclosedWashington State Attorney General
2026-07-31Asheville Beaverdam NC Opco LLC d/b/a Bear Mountain Health and Rehabilitation

Healthcare

Asheville Beaverdam NC Opco LLC d/b/a Bear Mountain Health and Rehabilitation: a health data breach

Asheville Beaverdam NC Opco LLC d/b/a Bear Mountain Health and Rehabilitation, a healthcare provider in NC, reported a breach of health information affecting 1,397 people to the US Department of Health and Human Services on July 31, 2026. HHS records the breach type as hacking/it incident, involving electronic medical record, network server.

Data breach
1,397HHS Office for Civil Rights
2026-07-31Asheville Victoria NC Opco LLC d/b/a Elevate Health & Rehabilitation

Healthcare

Asheville Victoria NC Opco LLC d/b/a Elevate Health & Rehabilitation: a health data breach

Asheville Victoria NC Opco LLC d/b/a Elevate Health & Rehabilitation, a healthcare provider in NC, reported a breach of health information affecting 1,551 people to the US Department of Health and Human Services on July 31, 2026. HHS records the breach type as hacking/it incident, involving desktop computer, network server.

Data breach
1,551HHS Office for Civil Rights
2026-07-31Asheville US Seventy NC Opco LLC d/b/a Swannanoa Valley Health and Rehabilitation

Healthcare

Asheville US Seventy NC Opco LLC d/b/a Swannanoa Valley Health and Rehabilitation: a health data breach

Asheville US Seventy NC Opco LLC d/b/a Swannanoa Valley Health and Rehabilitation, a healthcare provider in NC, reported a breach of health information affecting 1,045 people to the US Department of Health and Human Services on July 31, 2026. HHS records the breach type as hacking/it incident, involving desktop computer, network server.

Data breach
1,045HHS Office for Civil Rights
2026-07-31Monongalia County General Hospital Company

Healthcare

Monongalia County General Hospital Company: a health data breach

Monongalia County General Hospital Company, a healthcare provider in WV, reported a breach of health information affecting 2,173 people to the US Department of Health and Human Services on July 31, 2026. HHS records the breach type as hacking/it incident, involving email.

Data breach
2,173HHS Office for Civil Rights

About this tracker

442
Incidents
314
Ransomware gang claims
756
Last 30 days
414
Companies tracked
2,742,606,708
Records disclosed