Incident tracker
Recent cyber attacks and data breaches
This view includes companies named on ransomware leak sites. Those are the gangs’ claims, not verified breaches.
| Disclosed | Company | What happened | Type | Records | Source |
|---|---|---|---|---|---|
| 2026-06-09 | Pearlman, Brown & Wax LLP | Pearlman, Brown & Wax LLP: a data breach Pearlman, Brown & Wax LLP notified the California Attorney General of a data breach on June 9, 2026. The notice covers more than 500 California residents; California does not publish the exact number. | Data breach | Not disclosed | California Attorney General ↗ |
| 2026-06-07 | Baker Distributing | Baker Distributing: a data breach In May 2026, the HVAC/R wholesale distributor Baker Distributing Company was added to the ShinyHunters data extortion group's "pay or leak" site . In early June, the group publicly published data they claimed had been obtained from Baker's SharePoint and Salesforce infrastructure including 103k unique email addresses along with names, physical addresses, phone numbers and tickets relating to the company's HVAC contractor customer base. The exposed data was largely corporate contact and support information with limited sensitivity. | Data breach | 102,935 | Have I Been Pwned ↗ |
| 2026-06-05 | BCD Travel | BCD Travel: a data breach In May 2026, the corporate travel management company BCD Travel was claimed as a victim of the ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from BCD was subsequently published publicly in early June and contained 396k unique email addresses. Other exposed data included names, addresses, phone numbers, job titles and employer names, spanning a variety of different data sets including leads, internal staff and support tickets. | Data breach | 396,313 | Have I Been Pwned ↗ |
| 2026-06-05 | Ultrahuman Healthcare Private Limited | Ultrahuman Healthcare Private Limited: a data breach Ultrahuman Healthcare Private Limited notified the California Attorney General of a data breach on June 5, 2026, with the breach dated March 27, 2026. The notice covers more than 500 California residents; California does not publish the exact number. | Data breach | Not disclosed | California Attorney General ↗ |
| 2026-06-05 | Towerpoint Wealth, LLC | Towerpoint Wealth, LLC: a data breach Towerpoint Wealth, LLC notified the California Attorney General of a data breach on June 5, 2026, with the breach dated April 24, 2026. The notice covers more than 500 California residents; California does not publish the exact number. | Data breach | Not disclosed | California Attorney General ↗ |
| 2026-06-05 | Lansing Community College | Lansing Community College: a data breach Lansing Community College notified the California Attorney General of a data breach on June 5, 2026, with the breach dated February 12, 2025. The notice covers more than 500 California residents; California does not publish the exact number. | Data breach | Not disclosed | California Attorney General ↗ |
| 2026-06-05 | Meta Platforms, Inc. | Meta Platforms, Inc.: a data breach Meta Platforms, Inc. notified the California Attorney General of a data breach on June 5, 2026, with the breach dated April 17, 2026. The notice covers more than 500 California residents; California does not publish the exact number. | Data breach | Not disclosed | California Attorney General ↗ |
| 2026-06-05 | Plaza Home Mortgage Inc. | Plaza Home Mortgage Inc.: a data breach Plaza Home Mortgage Inc. notified the Washington State Attorney General on June 5, 2026 of a data breach that occurred on February 17, 2026, affecting 9,598 Washington residents. Information involved: Name, Social Security Number, Driver's License or Washington ID Card Number, Full Date of Birth, Username and Password/Security Question Answers. | Data breach | Not disclosed | Washington State Attorney General ↗ +1 more |
| 2026-06-05 | Gay & Lesbian Community Services Center of Orange County Inc | Gay & Lesbian Community Services Center of Orange County Inc: a data breach Gay & Lesbian Community Services Center of Orange County Inc notified the Washington State Attorney General on June 5, 2026 of a data breach that occurred on December 25, 2025, affecting 1,249 Washington residents. Information involved: Name, Driver's License or Washington ID Card Number, Financial & Banking Information, Full Date of Birth. | Data breach | Not disclosed | California Attorney General ↗ +1 more |
| 2026-06-03 | DentaQuest Healthcare | DentaQuest: a data breach In May 2026, the dental benefits administrator DentaQuest was the target of a ShinyHunters "pay or leak" extortion campaign that resulted in the group publicly publishing hundreds of gigabytes of data allegedly obtained from the company. The data included 2.6M unique email addresses along with names, addresses and phone numbers. Much of the data appeared in healthcare enrollment files ( ASC X12 transaction sets ) with some containing Medicaid IDs, while additional data appeared in member records and related files. DentaQuest acknowledged "a cybersecurity incident involving unauthorized access to a limited portion of our network" , and advised they had contained the attack and mitigated the threat. | Data breach | 2,553,599 | Have I Been Pwned ↗ +3 more |
About this tracker
- 435
- Incidents
- 298
- Ransomware gang claims
- 733
- Last 30 days
- 401
- Companies tracked
- 2,742,501,669
- Records disclosed