Incident tracker
Recent cyber attacks and data breaches
This view includes companies named on ransomware leak sites. Those are the gangs’ claims, not verified breaches.
| Disclosed | Company | What happened | Type | Records | Source |
|---|---|---|---|---|---|
| 2026-05-24 | 7-Eleven | 7-Eleven: a data breach In April 2026, 7-Eleven was the victim of a "pay or leak" extortion campaign by ShinyHunters , with the data later published that month. The incident exposed 185k unique email addresses, along with names, physical addresses, dates of birth and phone numbers. A small number of records also contained additional exposed data fields. The company later advised the breach was limited to "certain 7-Eleven systems used to store franchisee documents", a statement consistent with the exposed data. | Data breach | 185,256 | Have I Been Pwned ↗ |
| 2026-05-22 | Sacramento County | Sacramento County: a data breach Sacramento County notified the California Attorney General of a data breach on May 22, 2026, with the breach dated October 29, 2025. The notice covers more than 500 California residents; California does not publish the exact number. | Data breach | Not disclosed | California Attorney General ↗ |
| 2026-05-22 | Gastro Health | Gastro Health: a data breach Gastro Health notified the Washington State Attorney General on May 22, 2026 of a data breach that occurred on February 24, 2026, affecting 1,813 Washington residents. Information involved: Name, Social Security Number, Driver's License or Washington ID Card Number, Full Date of Birth, Health Insurance Policy or ID Number, Medical Information, Protected Health Information owned or licensed by a HIPAA covered entity. | Data breach | Not disclosed | Washington State Attorney General ↗ |
| 2026-05-22 | Oncology Institute, Inc.STLN Services-Offices & Clinics of Doctors of Medicine | Oncology Institute, Inc. disclosed a material cybersecurity incident | Regulatory filing | Not disclosed | SEC EDGAR ↗ |
| 2026-05-21 | Dragonica Lunaris | Dragonica Lunaris: a data breach In December 2025, the European Dragonica private server Dragonica Lunaris suffered a data breach. The incident exposed 126k email addresses, usernames, dates of birth and bcrypt password hashes. The service operator confirmed the breach and advised it has since been fixed. | Data breach | 126,293 | Have I Been Pwned ↗ |
| 2026-05-21 | Windows93 / Myspace93 | Windows93 / Myspace93: a data breach In January 2021, the parody site Windows93 suffered a data breach of the Myspace93 sub-site after a beta application was exploited to download server files. The compromised data was later leaked in June and included 46k Myspace93 accounts containing email and IP addresses, usernames and passwords stored in plain text. | Data breach | 46,105 | Have I Been Pwned ↗ |
| 2026-05-21 | Barnhart Crane & Rigging Company, Inc. | Barnhart Crane & Rigging Company, Inc.: a data breach Barnhart Crane & Rigging Company, Inc. notified the Washington State Attorney General on May 21, 2026 of a data breach that occurred on April 23, 2025, affecting 1,068 Washington residents. Information involved: Name, Social Security Number, Driver's License or Washington ID Card Number, Financial & Banking Information, Full Date of Birth, Passport Number, Health Insurance Policy or ID Number, Medical Information. | Data breach | Not disclosed | Washington State Attorney General ↗ |
| 2026-05-20 | Frost Bank | Frost Bank: a data breach Frost Bank notified the California Attorney General of a data breach on May 20, 2026, with the breach dated December 6, 2025. The notice covers more than 500 California residents; California does not publish the exact number. | Data breach | Not disclosed | California Attorney General ↗ |
| 2026-05-20 | Cardinal Services, Inc, Cardinal Employer Organization, and Preferred Employer Solutions, collectively (“Cardinal”) | Cardinal Services, Inc, Cardinal Employer Organization, and Preferred Employer Solutions, collectively (“Cardinal”): a data breach Cardinal Services, Inc, Cardinal Employer Organization, and Preferred Employer Solutions, collectively (“Cardinal”) notified the California Attorney General of a data breach on May 20, 2026, with the breach dated June 25, 2025. The notice covers more than 500 California residents; California does not publish the exact number. | Data breach | Not disclosed | California Attorney General ↗ |
| 2026-05-20 | VacPartsWarehouse.com | VacPartsWarehouse.com: a data breach VacPartsWarehouse.com notified the California Attorney General of a data breach on May 20, 2026, with the breach dated October 31, 2025. The notice covers more than 500 California residents; California does not publish the exact number. | Data breach | Not disclosed | California Attorney General ↗ |
About this tracker
- 435
- Incidents
- 296
- Ransomware gang claims
- 731
- Last 30 days
- 401
- Companies tracked
- 2,742,501,669
- Records disclosed