Incident tracker

Recent cyber attacks and data breaches

This view includes companies named on ransomware leak sites. Those are the gangs’ claims, not verified breaches.

DisclosedCompanyWhat happenedTypeRecordsSource
2026-06-24Madison Square Garden SportsMadison Square Garden Sports: a data breach

In June 2026, the sports and entertainment company Madison Square Garden Sports was the target of a ShinyHunters "pay or leak" extortion campaign . The group later published the alleged data, which included almost 10M unique email addresses spanning staff and customers, along with extensive personal, employment and customer relationship information.

Data breach
9,796,738Have I Been Pwned
2026-06-24AgelessRxAgelessRx: a data breach

AgelessRx notified the California Attorney General of a data breach on June 24, 2026, with the breach dated April 17, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-06-24Eisen, Inc.Eisen, Inc.: a data breach

Eisen, Inc. notified the California Attorney General of a data breach on June 24, 2026, with the breach dated December 12, 2025. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-06-23First Advantage CorporationFirst Advantage Corporation: a data breach

First Advantage Corporation notified the California Attorney General of a data breach on June 23, 2026, with the breach dated November 13, 2025. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-06-23Schmiidt & Battaglino Tax & Accounitng Inc.Schmiidt & Battaglino Tax & Accounitng Inc.: a data breach

Schmiidt & Battaglino Tax & Accounitng Inc. notified the Washington State Attorney General on June 23, 2026 of a data breach that occurred on May 28, 2026. Information involved: Name, Social Security Number, Financial & Banking Information, Full Date of Birth.

Data breach
Not disclosedWashington State Attorney General
2026-06-238X8 INC /DE/EGHT

Services-Computer Processing & Data Preparation

8X8 INC /DE/ disclosed a material cybersecurity incident
Regulatory filing
Not disclosedSEC EDGAR
2026-06-20JCPenneyJCPenney: a data breach

In June 2026, retailer JCPenney and associated brands were targeted in a ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from JCPenney through the exploitation of a critical zero-day vulnerability in Oracle PeopleSoft was later published publicly. The exposed records indicated they primarily related to internal HR systems and impacted current and former employees. The data included 368k corporate and personal email addresses, names, dates of birth, Social Security numbers, phone numbers and home addresses.

Data breach
368,418Have I Been Pwned
2026-06-19Xsolis, Inc. (Alexian Brothers Health System, Banner Health, Hendrick Medical Center dba Hendrick Health, Infirmary Health, Legacy Health, Mayo Clinic, Rochester Regional Health, UW Medicine, Virginia Hospital Center)Xsolis, Inc. (Alexian Brothers Health System, Banner Health, Hendrick Medical Center dba Hendrick Health, Infirmary Health, Legacy Health, Mayo Clinic, Rochester Regional Health, UW Medicine, Virginia Hospital Center): a data breach

Xsolis, Inc. (Alexian Brothers Health System, Banner Health, Hendrick Medical Center dba Hendrick Health, Infirmary Health, Legacy Health, Mayo Clinic, Rochester Regional Health, UW Medicine, Virginia Hospital Center) notified the Washington State Attorney General on June 19, 2026 of a data breach that occurred on January 20, 2026, affecting 26,203 Washington residents. Information involved: Name, Social Security Number, Full Date of Birth, Health Insurance Policy or ID Number, Medical Information, Protected Health Information owned or licensed by a HIPAA covered entity.

Data breach
Not disclosedWashington State Attorney General
2026-06-18Ralph LaurenRalph Lauren: a data breach

In June 2026, fashion retailer Ralph Lauren was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published hundreds of gigabytes of data they claimed was obtained from the organisation's Salesforce instance, including 140k unique email addresses along with names, phone numbers, genders and age groups.

Data breach
139,903Have I Been Pwned
2026-06-18Operation Endgame 4.0Operation Endgame 4.0: data obtained by malware

On 18 June 2026, the latest phase of Operation Endgame targeted the SocGholish malware operation , a prolific malware distribution network used to compromise systems and facilitate further cybercrime. Coordinated by international law enforcement agencies with support from Europol and Eurojust, the operation remediated almost 15,000 compromised websites and disrupted more than 100 servers and domains used to distribute malware. Authorities initially provided HIBP with 154k impacted email addresses and more than half a million previously unseen passwords. The following week, a further 4M email addresses and 9M passwords relating to the StealC malware operation also targeted by Operation Endgame were provided, followed by another 131k email addresses the following month, bringing the total to more than 4.3M unique email addresses.

Data breach
4,348,526Have I Been Pwned

About this tracker

435
Incidents
298
Ransomware gang claims
733
Last 30 days
402
Companies tracked
2,742,501,669
Records disclosed