Incident tracker

Recent cyber attacks and data breaches

This view includes companies named on ransomware leak sites. Those are the gangs’ claims, not verified breaches.

DisclosedCompanyWhat happenedTypeRecordsSource
2026-05-29RCI Internet ServicesRCI Internet Services: a data breach

RCI Internet Services notified the California Attorney General of a data breach on May 29, 2026, with the breach dated March 23, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-05-29Zalaznik & Associates, PLLCZalaznik & Associates, PLLC: a data breach

Zalaznik & Associates, PLLC notified the Washington State Attorney General on May 29, 2026 of a data breach that occurred on September 22, 2025, affecting 685 Washington residents. Information involved: Name, Social Security Number, Financial & Banking Information.

Data breach
Not disclosedWashington State Attorney General
2026-05-29IMA Diligence Services, LLCIMA Diligence Services, LLC: a data breach

IMA Diligence Services, LLC notified the Washington State Attorney General on May 29, 2026 of a data breach that occurred on December 8, 2025, affecting 1,977 Washington residents. Information involved: Name, Social Security Number, Driver's License or Washington ID Card Number, Financial & Banking Information, Full Date of Birth, Health Insurance Policy or ID Number, Medical Information.

Data breach
Not disclosedWashington State Attorney General

+1 more

2026-05-29Lakewood School DistrictLakewood School District: a data breach

Lakewood School District notified the Washington State Attorney General on May 29, 2026 of a data breach that occurred on March 19, 2026, affecting 1,006 Washington residents. Information involved: Name, Social Security Number, Driver's License or Washington ID Card Number, Financial & Banking Information.

Data breach
Not disclosedWashington State Attorney General
2026-05-29Fulcrum Real Estate Services, Inc.Fulcrum Real Estate Services, Inc.: a data breach

Fulcrum Real Estate Services, Inc. notified the Washington State Attorney General on May 29, 2026 of a data breach, affecting 1,360 Washington residents. Information involved: Name, Social Security Number, Driver's License or Washington ID Card Number, Financial & Banking Information, Health Insurance Policy or ID Number, Medical Information.

Data breach
Not disclosedWashington State Attorney General
2026-05-29Eastern Washington UniversityEastern Washington University: a data breach

Eastern Washington University notified the Washington State Attorney General on May 29, 2026 of a data breach that occurred on April 29, 2026. Information involved: Student ID Number.

Data breach
Not disclosedWashington State Attorney General
2026-05-29Networking Technology, INC. (RXNT)Networking Technology, INC. (RXNT): a data breach

Networking Technology, INC. (RXNT) notified the Washington State Attorney General on May 29, 2026 of a data breach that occurred on May 1, 2026, affecting 1,215 Washington residents. Information involved: Name, Social Security Number, Full Date of Birth, Medical Information, Protected Health Information owned or licensed by a HIPAA covered entity.

Data breach
Not disclosedWashington State Attorney General

+1 more

2026-05-28CharterCharter: a data breach

In May 2026, the telecommunications company Charter Communications (the parent company behind the consumer broadband and cable brand Spectrum) was named by the ShinyHunters group in a "pay or leak" extortion campaign . The group later published the data, which exposed 4.9M unique email addresses along with names, phone numbers and physical addresses. A subset of approximately 85k records originating from an internal employee directory also included job titles. Charter confirmed the incident, but stated that no sensitive personal information or customer proprietary network information (CPNI) was exfiltrated.

Data breach
4,851,517Have I Been Pwned
2026-05-28KemperKemper: a data breach

In April 2026, the American insurance holding company Kemper Corporation was named by the ShinyHunters ransomware group in a "pay or leak" extortion campaign . The attackers allegedly accessed Kemper's Salesforce environment via social engineering as part of a broader campaign targeting hundreds of organisations using the same method. The group later published tens of gigabytes of data they claimed included internal directory data, Salesforce records and Stripe payment logs. Among the 269k unique email addresses were names, phone numbers, physical addresses and partial payment card data including the last 4 digits, expiry dates and card brands. Kemper confirmed the incident and stated they had engaged third-party cybersecurity experts and notified law enforcement.

Data breach
269,299Have I Been Pwned
2026-05-28Johnson-Peltier Electric, Inc.Johnson-Peltier Electric, Inc.: a data breach

Johnson-Peltier Electric, Inc. notified the California Attorney General of a data breach on May 28, 2026, with the breach dated March 10, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General

About this tracker

435
Incidents
298
Ransomware gang claims
733
Last 30 days
401
Companies tracked
2,742,501,669
Records disclosed