Incident tracker

Recent cyber attacks and data breaches

This view includes companies named on ransomware leak sites. Those are the gangs’ claims, not verified breaches.

DisclosedCompanyWhat happenedTypeRecordsSource
2026-07-17CLOVER HEALTH INVESTMENTS, CORP. /DECLOV

Hospital & Medical Service Plans

CLOVER HEALTH INVESTMENTS, CORP. /DE disclosed a cybersecurity incident

On July 4, 2026, Clover Health Investments, Corp. (the "Company") became aware of anomalous login activity on certain of its information systems. The Company immediately activated its incident response procedures, initiated an investigation with assistance from leading third-party cybersecurity experts, and took steps to contain the activity. The Company also notified law enforcement. The investigation subsequently showed that a threat actor gained access to three non-managerial health plan employee accounts through social engineering. Based on preliminary findings from the Company's investigation, those accounts were assigned to employees who had member visit-scheduling and broker-facing sales functions. The employee accounts had access to certain personally identifiable information and protected health information, but had no access to corporate financial or claims systems. While the investigation is ongoing into the precise nature, scope, and extent of data that was subject to unauthorized access and acquisition, the Company believes that its rapid response successfully contained and terminated the unauthorized access. Based on information available as of the date of this filing, the Company does not believe that the incident has had, or is reasonably likely to have, a material impact on its business, financial condition or results of operations. The Company takes the privacy and security of its member data very seriously and has taken, and continues to take, steps to further harden its IT environment. The Company continues to evaluate applicable regulatory and legal notification requirements and will make all required notifications based on its findings, including to impacted members. Forward-Looking Statements This Current Report on Form 8-K (the "Form 8-K") contains forward-looking statements within the meaning of Section 27A of the Securities Act of 1933, as amended, and Section 21E of the Securities Exchange Act of 1934, as amended. Forward-looking statements include statements regarding future events and the Company's future results of operations, financial condition, market size and opportunity, business strategy and plans, and the factors affecting our performance and our objectives for future operations. Forward-looking statements are not guarantees of future performance and you are cautioned not to place undue reliance on such statements. In some cases, you can identify forward looking statements because they contain words such as "may," "will," "should," "expects," "plans," "anticipates," "going to," "can," "could," "should," "would," "intends," "target," "projects," "contemplates," "believes," "estimates," "predicts," "potential," "outlook," "forecast," "guidance," "objective," "plan," "seek," "grow," "if," "continue" or the negative of these words or other similar terms or expressions that concern the Company's expectations, strategy, priorities, plans or intentions. Forward-looking statements in the Form 8-K include, but are not limited to, the following: estimates regarding the potential impact of the cybersecurity incident, ongoing remediation efforts, future operational recovery and potential financial losses. These forward-looking statements are based on current expectations and are subject to inherent risks, uncertainties, and assumptions that are difficult to predict. Factors that could cause actual results to differ materially include, but are not limited to, the scope and duration of the incident, the nature of the compromised data, the outcome of any regulatory investigations or litigation, and our ability to successfully implement our remediation plans. Additional information concerning these and other risk factors is contained under Item 1A. "Risk Factors" in our most recent Annual Report on Form 10-K filed with the Securities and Exchange Commission (the "SEC") on February 27, 2026, as such risks may be updated in our subsequent filings with the SEC. The forward-looking statements included in t

Regulatory filing
Not disclosedSEC EDGAR
2026-07-16QuestoQuesto: a data breach

Questo notified the California Attorney General of a data breach on July 16, 2026, with the breach dated October 1, 2025. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-07-16Fox Rothschild LLPFox Rothschild LLP: a data breach

Fox Rothschild LLP notified the Washington State Attorney General on July 16, 2026 of a data breach that occurred on May 21, 2026, affecting 1,891 Washington residents. Information involved: Name, Social Security Number, Full Date of Birth.

Data breach
Not disclosedCalifornia Attorney General

+1 more

2026-07-16Lifespan Physician Group of Massachusetts, Inc. d/b/a Brown Health Medical Group-MA

Healthcare

Lifespan Physician Group of Massachusetts, Inc. d/b/a Brown Health Medical Group-MA: a health data breach

Lifespan Physician Group of Massachusetts, Inc. d/b/a Brown Health Medical Group-MA, a healthcare provider in MA, reported a breach of health information affecting 311,760 people to the US Department of Health and Human Services on July 16, 2026. HHS records the breach type as hacking/it incident, involving network server.

Data breach
311,760HHS Office for Civil Rights
2026-07-15FlukeFluke: a data breach

In July 2026, electronic test and measurement equipment company Fluke was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published more than 100GB of data allegedly taken from the company. The corpus contained largely corporate contact information, including over 800k unique email addresses, names, phone numbers and physical addresses. A large collection of support cases was also present.

Data breach
821,100Have I Been Pwned
2026-07-15Goose CreekGoose Creek: a data breach

In June 2026, a party claiming to have access to data from Goose Creek Candle Company sent emails to a number of the company's customers , claiming the company had a security vulnerability and suffered a data breach. The data was subsequently sent to Have I Been Pwned and contained 6.6M unique email addresses along with names, phone numbers, physical addresses, order IDs and total spent. The data appears to have been obtained from the company's Shopify instance. Goose Creek is aware of the reports but was unable to provide Have I Been Pwned with any further information at the time of publication.

Data breach
6,574,121Have I Been Pwned
2026-07-15Ernst & Young LLPErnst & Young LLP: a data breach

Ernst & Young LLP notified the California Attorney General of a data breach on July 15, 2026, with the breach dated March 28, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-07-15North Coast Opportunities, Inc. / Redwood Caregiver Resource CenterNorth Coast Opportunities, Inc. / Redwood Caregiver Resource Center: a data breach

North Coast Opportunities, Inc. / Redwood Caregiver Resource Center notified the California Attorney General of a data breach on July 15, 2026, with the breach dated June 30, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-07-15Wilmer Cutler Pickering Hale and Dorr LLPWilmer Cutler Pickering Hale and Dorr LLP: a data breach

Wilmer Cutler Pickering Hale and Dorr LLP notified the Washington State Attorney General on July 15, 2026 of a data breach that occurred on May 8, 2026, affecting 17,253 Washington residents. Information involved: Name, Social Security Number, Full Date of Birth, Student ID Number.

Data breach
Not disclosedCalifornia Attorney General

+1 more

2026-07-15Resource Center of Dallas, Inc.

Healthcare

Resource Center of Dallas, Inc.: a health data breach

Resource Center of Dallas, Inc., a healthcare provider in TX, reported a breach of health information affecting 12,490 people to the US Department of Health and Human Services on July 15, 2026. HHS records the breach type as hacking/it incident, involving network server.

Data breach
12,490HHS Office for Civil Rights

About this tracker

437
Incidents
300
Ransomware gang claims
737
Last 30 days
408
Companies tracked
2,742,606,708
Records disclosed