Incident tracker

Recent cyber attacks and data breaches

This view includes companies named on ransomware leak sites. Those are the gangs’ claims, not verified breaches.

DisclosedCompanyWhat happenedTypeRecordsSource
2026-07-22Kootenai County, IdahoKootenai County, Idaho: a data breach

Kootenai County, Idaho notified the Washington State Attorney General on July 22, 2026 of a data breach, affecting 746 Washington residents. Information involved: Name, Social Security Number, Driver's License or Washington ID Card Number, Full Date of Birth, Health Insurance Policy or ID Number, Medical Information, Biometric Data.

Data breach
Not disclosedWashington State Attorney General
2026-07-22FIVE BELOW, INCFIVE

Retail-Variety Stores

FIVE BELOW, INC disclosed a cybersecurity incident

On July 15, 2026, Five Below, Inc. (the "Company") identified anomalous activity on a Company-issued computer belonging to an employee. Upon detection, the Company promptly activated its cybersecurity incident response plan, initiated a forensic investigation, with assistance from third-party cybersecurity experts, and took immediate steps to contain the activity. The investigation determined that on July 14, 2026, a threat actor used social engineering techniques that enabled unauthorized access to that employee's Company-issued computer. The threat actor exfiltrated a number of files from the affected computer. As of the date of this filing, the Company believes that its rapid response efforts successfully contained and terminated the unauthorized access, that the incident was limited to the affected employee's environment, that no personally identifiable information was accessed or exfiltrated, and that the incident did not affect the Company's other systems, platforms, data, or environments. Based on information available as of the date of this filing, the Company does not believe the incident has had, or is reasonably likely to have, a material impact on the Company's business strategy, operations, financial condition, or results of operations. Certain statements contained in this Current Report on Form 8-K constitute forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995, including, without limitation, statements regarding the scope, impact, and anticipated consequences of the cybersecurity incident described herein. These forward-looking statements are based on the Company's current expectations, estimates, and assumptions and are subject to risks and uncertainties that could cause actual results to differ materially, including the risks that the Company may identify additional affected systems or data, that the exfiltrated information may be used in ways harmful to the Company's competitive position or financial condition, that regulatory authorities may reach conclusions different from those of the Company, or that litigation may result from the incident. The Company undertakes no obligation to update or revise any forward-looking statements, whether as a result of new information, future events, or otherwise, except as required by law.

Regulatory filing
Not disclosedSEC EDGAR
2026-07-21Boundary Regional Community Health Center dba Kaniksu Community Health

Healthcare

Boundary Regional Community Health Center dba Kaniksu Community Health: a health data breach

Boundary Regional Community Health Center dba Kaniksu Community Health, a healthcare provider in ID, reported a breach of health information affecting 88,000 people to the US Department of Health and Human Services on July 21, 2026. HHS records the breach type as hacking/it incident, involving network server.

Data breach
88,000HHS Office for Civil Rights
2026-07-21Xsolis, Inc.Xsolis, Inc.: a data breach

Xsolis, Inc. notified the California Attorney General of a data breach on July 21, 2026, with the breach dated January 20, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General

+1 more

2026-07-21Unlimited Technology Systems, LLC

Healthcare

Unlimited Technology Systems, LLC: a health data breach

Unlimited Technology Systems, LLC, a business associate in OH, reported a breach of health information affecting 3,803,750 people to the US Department of Health and Human Services on July 21, 2026. HHS records the breach type as hacking/it incident, involving network server.

Data breach
3,803,750HHS Office for Civil Rights

+2 more

2026-07-20SunoSuno: a data breach

In November 2025, AI music generation tool Suno suffered a data breach that later came to light in July the following year . The data contained over 55M unique email addresses. Phone numbers were also present where they had been used as the sign-up method. Although representing a small portion of the corpus, the breach also included tens of thousands of Stripe records relating to purchases, containing names, physical addresses, purchase amounts and partial credit card data including the card type, expiry date and last 4 digits. The company advised that "Suno does not have access to customers' full credit card numbers in Stripe".

Data breach
55,282,226Have I Been Pwned
2026-07-20TransGlobal Insurance Agency, Inc.TransGlobal Insurance Agency, Inc.: a data breach

TransGlobal Insurance Agency, Inc. notified the California Attorney General of a data breach on July 20, 2026, with the breach dated February 18, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-07-20Beltrami County Health and Human Services

Healthcare

Beltrami County Health and Human Services: a health data breach

Beltrami County Health and Human Services, a healthcare provider in MN, reported a breach of health information affecting 1,491 people to the US Department of Health and Human Services on July 20, 2026. HHS records the breach type as hacking/it incident, involving email.

Data breach
1,491HHS Office for Civil Rights
2026-07-19PaidworkPaidwork: a data breach

In March 2026, hackers claimed they had obtained data from the gig economy platform Paidwork which they then listed for sale . Almost 11GB of data allegedly obtained from the platform was subsequently posted publicly in July and contained over 23M unique email addresses. The breach also included a broad range of other data relating to the operation of the platform including user profile data, banking information, payout history for workers and passwords stored as bcrypt hashes.

Data breach
23,272,765Have I Been Pwned
2026-07-19Minnesota Health Insurance Network

Healthcare

Minnesota Health Insurance Network: a health data breach

Minnesota Health Insurance Network, a business associate in MN, reported a breach of health information affecting 3,656 people to the US Department of Health and Human Services on July 19, 2026. HHS records the breach type as hacking/it incident, involving network server.

Data breach
3,656HHS Office for Civil Rights

About this tracker

437
Incidents
300
Ransomware gang claims
737
Last 30 days
408
Companies tracked
2,742,606,708
Records disclosed