Incident tracker

Recent cyber attacks and data breaches

DisclosedCompanyWhat happenedTypeRecordsSource
2026-08-08Brinks HomeBrinks Home: a data breach

In July 2026, Brinks Home was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data they alleged was taken from the company, including 732k unique email addresses and other personal information relating to leads, customers and Brinks staff such as name, phone numbers and physical addresses. The data also included purchases from Brinks along with partial credit card data (last 4 digits, card type and expiry). In Brinks' disclosure notice , they acknowledged the incident and risk of disclosure, and advised that they would notify impacted parties "consistent with applicable law".

Data breach
732,162Have I Been Pwned
2026-08-07Exact SciencesExact Sciences: a data breach

In July 2026, Exact Sciences (now owned by Abbott Laboratories) was the target of a ShinyHunters "pay or leak" extortion campaign . The group claimed to have obtained data from the company's cancer diagnostics business, which they later published publicly. The breach contained 10.9M unique email addresses belonging to customers, patients and healthcare providers, along with names, addresses, phone numbers and health records. Abbott subsequently published a public notice advising that "some of the impacted files contain personal information and/or personal health information" and that more specific information would follow once their review of the incident was complete. For context, Exact Sciences is the maker of the Cologuard at-home colorectal cancer screening test.

Data breach
10,869,543Have I Been Pwned
2026-08-07American Addiction CentersAmerican Addiction Centers: a data breach

American Addiction Centers notified the Washington State Attorney General on August 7, 2026 of a data breach that occurred on May 12, 2026, affecting 1,155 Washington residents. Information involved: Name, Social Security Number, Health Insurance Policy or ID Number, Medical Information.

Data breach
Not disclosedWashington State Attorney General

+1 more

2026-08-07Golden Opportunities And Local Support, LLCGolden Opportunities And Local Support, LLC: a data breach

Golden Opportunities And Local Support, LLC notified the Washington State Attorney General on August 7, 2026 of a data breach. Information involved: Name, Full Date of Birth, Other, Protected Health Information owned or licensed by a HIPAA covered entity.

Data breach
Not disclosedWashington State Attorney General
2026-08-07Horizon Eye Care Laser & Eye Surgery Center

Healthcare

Horizon Eye Care Laser & Eye Surgery Center: a health data breach

Horizon Eye Care Laser & Eye Surgery Center, a healthcare provider in NJ, reported a breach of health information affecting 501 people to the US Department of Health and Human Services on August 7, 2026. HHS records the breach type as hacking/it incident, involving network server.

Data breach
501HHS Office for Civil Rights
2026-08-07Indico Data Solutions, Inc.

Healthcare

Indico Data Solutions, Inc.: a health data breach

Indico Data Solutions, Inc., a business associate in MA, reported a breach of health information affecting 4,840 people to the US Department of Health and Human Services on August 7, 2026. HHS records the breach type as hacking/it incident, involving network server.

Data breach
4,840HHS Office for Civil Rights

+1 more

2026-08-07Deseye, PLLC d/b/a Princeton Family Eye Care

Healthcare

Deseye, PLLC d/b/a Princeton Family Eye Care: a health data breach

Deseye, PLLC d/b/a Princeton Family Eye Care, a healthcare provider in TX, reported a breach of health information affecting 1,050 people to the US Department of Health and Human Services on August 7, 2026. HHS records the breach type as hacking/it incident, involving email.

Data breach
1,050HHS Office for Civil Rights
2026-08-07Central Arkansas Pediatrics, P.A.

Healthcare

Central Arkansas Pediatrics, P.A.: a health data breach

Central Arkansas Pediatrics, P.A., a healthcare provider in AR, reported a breach of health information affecting 1,500 people to the US Department of Health and Human Services on August 7, 2026. HHS records the breach type as hacking/it incident, involving network server.

Data breach
1,500HHS Office for Civil Rights
2026-08-07LEVI STRAUSS & COLEVI

Apparel & Other Finishd Prods of Fabrics & Similar Matl

LEVI STRAUSS & CO disclosed a cybersecurity incident

Levi Strauss & Co. (the "Company") recently detected that the Company experienced a cybersecurity incident in which an unauthorized third party gained access to Company files through social engineering techniques that enabled unauthorized access to three employees' Company-issued computers. Following such detection, the Company initiated response protocols, implemented containment measures, launched an investigation, which remains ongoing and engaged the services of third-party cybersecurity experts. Based on preliminary findings from the Company's investigation, the Company believes that certain corporate information was accessed and exfiltrated as a result of the incident. As of the date of this filing, the Company believes that its rapid response efforts successfully contained and terminated the unauthorized access, and that no consumer data was impacted. The Company has not experienced any interruption in business operations as a result of the incident. Based on information available as of the date of this filing, the Company does not believe the incident has had, or is reasonably likely to have, a material impact on the Company's business strategy, operations, financial condition, or results of operations. The Company has provided and will provide notifications to affected parties and applicable regulators as appropriate and in accordance with applicable law. Forward-Looking Statements This Current Report on Form 8-K contains forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995, including, without limitation, statements regarding the scope, impact, and anticipated consequences of the cybersecurity incident described herein. The Company has based these forward-looking statements on its current reasonable assumptions, expectations and projections about future events. These forward-looking statements are necessary estimates reflecting the best judgment of our senior management and involve a number of risks and uncertainties, some of which are beyond our control, that could cause actual results to differ materially from those suggested by the forward-looking statements. Investors should consider the information contained in the Company's filings with the U.S. Securities and Exchange Commission, including its Annual Report on Form 10-K for fiscal year 2025 and its most recently-filed Quarterly Report on Form 10-Q. The Company undertakes no obligation to revise or update any forward-looking statements.

Regulatory filing
Not disclosedSEC EDGAR
2026-08-06Hamill & KaplanHamill & Kaplan: a data breach

Hamill & Kaplan notified the California Attorney General of a data breach on August 6, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General

About this tracker

435
Incidents
296
Ransomware gang claims
731
Last 30 days
401
Companies tracked
2,742,501,669
Records disclosed