Incident tracker
Recent cyber attacks and data breaches
This view includes companies named on ransomware leak sites. Those are the gangs’ claims, not verified breaches.
| Disclosed | Company | What happened | Type | Records | Source |
|---|---|---|---|---|---|
| 2026-07-17 | CLOVER HEALTH INVESTMENTS, CORP. /DECLOV Hospital & Medical Service Plans | CLOVER HEALTH INVESTMENTS, CORP. /DE disclosed a cybersecurity incident On July 4, 2026, Clover Health Investments, Corp. (the "Company") became aware of anomalous login activity on certain of its information systems. The Company immediately activated its incident response procedures, initiated an investigation with assistance from leading third-party cybersecurity experts, and took steps to contain the activity. The Company also notified law enforcement. The investigation subsequently showed that a threat actor gained access to three non-managerial health plan employee accounts through social engineering. Based on preliminary findings from the Company's investigation, those accounts were assigned to employees who had member visit-scheduling and broker-facing sales functions. The employee accounts had access to certain personally identifiable information and protected health information, but had no access to corporate financial or claims systems. While the investigation is ongoing into the precise nature, scope, and extent of data that was subject to unauthorized access and acquisition, the Company believes that its rapid response successfully contained and terminated the unauthorized access. Based on information available as of the date of this filing, the Company does not believe that the incident has had, or is reasonably likely to have, a material impact on its business, financial condition or results of operations. The Company takes the privacy and security of its member data very seriously and has taken, and continues to take, steps to further harden its IT environment. The Company continues to evaluate applicable regulatory and legal notification requirements and will make all required notifications based on its findings, including to impacted members. Forward-Looking Statements This Current Report on Form 8-K (the "Form 8-K") contains forward-looking statements within the meaning of Section 27A of the Securities Act of 1933, as amended, and Section 21E of the Securities Exchange Act of 1934, as amended. Forward-looking statements include statements regarding future events and the Company's future results of operations, financial condition, market size and opportunity, business strategy and plans, and the factors affecting our performance and our objectives for future operations. Forward-looking statements are not guarantees of future performance and you are cautioned not to place undue reliance on such statements. In some cases, you can identify forward looking statements because they contain words such as "may," "will," "should," "expects," "plans," "anticipates," "going to," "can," "could," "should," "would," "intends," "target," "projects," "contemplates," "believes," "estimates," "predicts," "potential," "outlook," "forecast," "guidance," "objective," "plan," "seek," "grow," "if," "continue" or the negative of these words or other similar terms or expressions that concern the Company's expectations, strategy, priorities, plans or intentions. Forward-looking statements in the Form 8-K include, but are not limited to, the following: estimates regarding the potential impact of the cybersecurity incident, ongoing remediation efforts, future operational recovery and potential financial losses. These forward-looking statements are based on current expectations and are subject to inherent risks, uncertainties, and assumptions that are difficult to predict. Factors that could cause actual results to differ materially include, but are not limited to, the scope and duration of the incident, the nature of the compromised data, the outcome of any regulatory investigations or litigation, and our ability to successfully implement our remediation plans. Additional information concerning these and other risk factors is contained under Item 1A. "Risk Factors" in our most recent Annual Report on Form 10-K filed with the Securities and Exchange Commission (the "SEC") on February 27, 2026, as such risks may be updated in our subsequent filings with the SEC. The forward-looking statements included in t | Regulatory filing | Not disclosed | SEC EDGAR ↗ |
| 2026-07-16 | Questo | Questo: a data breach Questo notified the California Attorney General of a data breach on July 16, 2026, with the breach dated October 1, 2025. The notice covers more than 500 California residents; California does not publish the exact number. | Data breach | Not disclosed | California Attorney General ↗ |
| 2026-07-16 | Fox Rothschild LLP | Fox Rothschild LLP: a data breach Fox Rothschild LLP notified the Washington State Attorney General on July 16, 2026 of a data breach that occurred on May 21, 2026, affecting 1,891 Washington residents. Information involved: Name, Social Security Number, Full Date of Birth. | Data breach | Not disclosed | California Attorney General ↗ +1 more |
| 2026-07-16 | Lifespan Physician Group of Massachusetts, Inc. d/b/a Brown Health Medical Group-MA Healthcare | Lifespan Physician Group of Massachusetts, Inc. d/b/a Brown Health Medical Group-MA: a health data breach Lifespan Physician Group of Massachusetts, Inc. d/b/a Brown Health Medical Group-MA, a healthcare provider in MA, reported a breach of health information affecting 311,760 people to the US Department of Health and Human Services on July 16, 2026. HHS records the breach type as hacking/it incident, involving network server. | Data breach | 311,760 | HHS Office for Civil Rights ↗ |
| 2026-07-15 | Fluke | Fluke: a data breach In July 2026, electronic test and measurement equipment company Fluke was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published more than 100GB of data allegedly taken from the company. The corpus contained largely corporate contact information, including over 800k unique email addresses, names, phone numbers and physical addresses. A large collection of support cases was also present. | Data breach | 821,100 | Have I Been Pwned ↗ |
| 2026-07-15 | Goose Creek | Goose Creek: a data breach In June 2026, a party claiming to have access to data from Goose Creek Candle Company sent emails to a number of the company's customers , claiming the company had a security vulnerability and suffered a data breach. The data was subsequently sent to Have I Been Pwned and contained 6.6M unique email addresses along with names, phone numbers, physical addresses, order IDs and total spent. The data appears to have been obtained from the company's Shopify instance. Goose Creek is aware of the reports but was unable to provide Have I Been Pwned with any further information at the time of publication. | Data breach | 6,574,121 | Have I Been Pwned ↗ |
| 2026-07-15 | Ernst & Young LLP | Ernst & Young LLP: a data breach Ernst & Young LLP notified the California Attorney General of a data breach on July 15, 2026, with the breach dated March 28, 2026. The notice covers more than 500 California residents; California does not publish the exact number. | Data breach | Not disclosed | California Attorney General ↗ |
| 2026-07-15 | North Coast Opportunities, Inc. / Redwood Caregiver Resource Center | North Coast Opportunities, Inc. / Redwood Caregiver Resource Center: a data breach North Coast Opportunities, Inc. / Redwood Caregiver Resource Center notified the California Attorney General of a data breach on July 15, 2026, with the breach dated June 30, 2026. The notice covers more than 500 California residents; California does not publish the exact number. | Data breach | Not disclosed | California Attorney General ↗ |
| 2026-07-15 | Wilmer Cutler Pickering Hale and Dorr LLP | Wilmer Cutler Pickering Hale and Dorr LLP: a data breach Wilmer Cutler Pickering Hale and Dorr LLP notified the Washington State Attorney General on July 15, 2026 of a data breach that occurred on May 8, 2026, affecting 17,253 Washington residents. Information involved: Name, Social Security Number, Full Date of Birth, Student ID Number. | Data breach | Not disclosed | California Attorney General ↗ +1 more |
| 2026-07-15 | Resource Center of Dallas, Inc. Healthcare | Resource Center of Dallas, Inc.: a health data breach Resource Center of Dallas, Inc., a healthcare provider in TX, reported a breach of health information affecting 12,490 people to the US Department of Health and Human Services on July 15, 2026. HHS records the breach type as hacking/it incident, involving network server. | Data breach | 12,490 | HHS Office for Civil Rights ↗ |
About this tracker
- 437
- Incidents
- 300
- Ransomware gang claims
- 737
- Last 30 days
- 408
- Companies tracked
- 2,742,606,708
- Records disclosed