Incident tracker
Recent cyber attacks and data breaches
| Disclosed | Company | What happened | Type | Records | Source |
|---|---|---|---|---|---|
| 2026-08-08 | Brinks Home | Brinks Home: a data breach In July 2026, Brinks Home was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data they alleged was taken from the company, including 732k unique email addresses and other personal information relating to leads, customers and Brinks staff such as name, phone numbers and physical addresses. The data also included purchases from Brinks along with partial credit card data (last 4 digits, card type and expiry). In Brinks' disclosure notice , they acknowledged the incident and risk of disclosure, and advised that they would notify impacted parties "consistent with applicable law". | Data breach | 732,162 | Have I Been Pwned ↗ |
| 2026-08-07 | Exact Sciences | Exact Sciences: a data breach In July 2026, Exact Sciences (now owned by Abbott Laboratories) was the target of a ShinyHunters "pay or leak" extortion campaign . The group claimed to have obtained data from the company's cancer diagnostics business, which they later published publicly. The breach contained 10.9M unique email addresses belonging to customers, patients and healthcare providers, along with names, addresses, phone numbers and health records. Abbott subsequently published a public notice advising that "some of the impacted files contain personal information and/or personal health information" and that more specific information would follow once their review of the incident was complete. For context, Exact Sciences is the maker of the Cologuard at-home colorectal cancer screening test. | Data breach | 10,869,543 | Have I Been Pwned ↗ |
| 2026-08-07 | American Addiction Centers | American Addiction Centers: a data breach American Addiction Centers notified the Washington State Attorney General on August 7, 2026 of a data breach that occurred on May 12, 2026, affecting 1,155 Washington residents. Information involved: Name, Social Security Number, Health Insurance Policy or ID Number, Medical Information. | Data breach | Not disclosed | Washington State Attorney General ↗ +1 more |
| 2026-08-07 | Golden Opportunities And Local Support, LLC | Golden Opportunities And Local Support, LLC: a data breach Golden Opportunities And Local Support, LLC notified the Washington State Attorney General on August 7, 2026 of a data breach. Information involved: Name, Full Date of Birth, Other, Protected Health Information owned or licensed by a HIPAA covered entity. | Data breach | Not disclosed | Washington State Attorney General ↗ |
| 2026-08-07 | Horizon Eye Care Laser & Eye Surgery Center Healthcare | Horizon Eye Care Laser & Eye Surgery Center: a health data breach Horizon Eye Care Laser & Eye Surgery Center, a healthcare provider in NJ, reported a breach of health information affecting 501 people to the US Department of Health and Human Services on August 7, 2026. HHS records the breach type as hacking/it incident, involving network server. | Data breach | 501 | HHS Office for Civil Rights ↗ |
| 2026-08-07 | Indico Data Solutions, Inc. Healthcare | Indico Data Solutions, Inc.: a health data breach Indico Data Solutions, Inc., a business associate in MA, reported a breach of health information affecting 4,840 people to the US Department of Health and Human Services on August 7, 2026. HHS records the breach type as hacking/it incident, involving network server. | Data breach | 4,840 | HHS Office for Civil Rights ↗ +1 more |
| 2026-08-07 | Deseye, PLLC d/b/a Princeton Family Eye Care Healthcare | Deseye, PLLC d/b/a Princeton Family Eye Care: a health data breach Deseye, PLLC d/b/a Princeton Family Eye Care, a healthcare provider in TX, reported a breach of health information affecting 1,050 people to the US Department of Health and Human Services on August 7, 2026. HHS records the breach type as hacking/it incident, involving email. | Data breach | 1,050 | HHS Office for Civil Rights ↗ |
| 2026-08-07 | Central Arkansas Pediatrics, P.A. Healthcare | Central Arkansas Pediatrics, P.A.: a health data breach Central Arkansas Pediatrics, P.A., a healthcare provider in AR, reported a breach of health information affecting 1,500 people to the US Department of Health and Human Services on August 7, 2026. HHS records the breach type as hacking/it incident, involving network server. | Data breach | 1,500 | HHS Office for Civil Rights ↗ |
| 2026-08-07 | LEVI STRAUSS & COLEVI Apparel & Other Finishd Prods of Fabrics & Similar Matl | LEVI STRAUSS & CO disclosed a cybersecurity incident Levi Strauss & Co. (the "Company") recently detected that the Company experienced a cybersecurity incident in which an unauthorized third party gained access to Company files through social engineering techniques that enabled unauthorized access to three employees' Company-issued computers. Following such detection, the Company initiated response protocols, implemented containment measures, launched an investigation, which remains ongoing and engaged the services of third-party cybersecurity experts. Based on preliminary findings from the Company's investigation, the Company believes that certain corporate information was accessed and exfiltrated as a result of the incident. As of the date of this filing, the Company believes that its rapid response efforts successfully contained and terminated the unauthorized access, and that no consumer data was impacted. The Company has not experienced any interruption in business operations as a result of the incident. Based on information available as of the date of this filing, the Company does not believe the incident has had, or is reasonably likely to have, a material impact on the Company's business strategy, operations, financial condition, or results of operations. The Company has provided and will provide notifications to affected parties and applicable regulators as appropriate and in accordance with applicable law. Forward-Looking Statements This Current Report on Form 8-K contains forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995, including, without limitation, statements regarding the scope, impact, and anticipated consequences of the cybersecurity incident described herein. The Company has based these forward-looking statements on its current reasonable assumptions, expectations and projections about future events. These forward-looking statements are necessary estimates reflecting the best judgment of our senior management and involve a number of risks and uncertainties, some of which are beyond our control, that could cause actual results to differ materially from those suggested by the forward-looking statements. Investors should consider the information contained in the Company's filings with the U.S. Securities and Exchange Commission, including its Annual Report on Form 10-K for fiscal year 2025 and its most recently-filed Quarterly Report on Form 10-Q. The Company undertakes no obligation to revise or update any forward-looking statements. | Regulatory filing | Not disclosed | SEC EDGAR ↗ |
| 2026-08-06 | Hamill & Kaplan | Hamill & Kaplan: a data breach Hamill & Kaplan notified the California Attorney General of a data breach on August 6, 2026. The notice covers more than 500 California residents; California does not publish the exact number. | Data breach | Not disclosed | California Attorney General ↗ |
About this tracker
- 435
- Incidents
- 296
- Ransomware gang claims
- 731
- Last 30 days
- 401
- Companies tracked
- 2,742,501,669
- Records disclosed