Incident tracker

Recent cyber attacks and data breaches

DisclosedCompanyWhat happenedTypeRecordsSource
2026-08-06IEH CorpIEHC

Electronic Connectors

IEH Corp disclosed a cybersecurity incident

On August 4, 2026, IEH Corporation ("IEH" or the "Company") discovered that it sustained a cybersecurity incident whereby a threat actor using an alias gained unauthorized access to the Microsoft 365 mailbox of an employee of the Company. As soon as the incident was observed, the Company took action to contain the unauthorized access. An investigation determined the compromise originated from a phishing attack in which a malicious actor impersonated a prospective business contact and delivered a hyperlink disguised as a Microsoft document-sharing link. The user accessed the link and entered Microsoft 365 credentials into a fraudulent login page, resulting in unauthorized account access. The threat actor gained access to mailbox contents, including email messages, attachments, customer communications, purchase orders, engineering-related documentation, and potentially export-controlled technical information. No evidence currently exists that unauthorized emails were transmitted from the account or that data was successfully exfiltrated. However, sensitive information was accessible to the unauthorized party during the compromise period. The account was secured, malicious mailbox rules were disabled, evidence was preserved, and corrective actions are underway. Following containment and investigation activities, the Company initiated a review of account security controls and authentication protections applicable to Microsoft 365 services. The Company has already taken and completed a series of corrective actions to contain any impact of the unauthorized access. However, at this time, the Company has no evidence that information was transmitted externally, downloaded or infiltrated. The Company only knows that the information was accessible to the unauthorized actor during the compromise period. The Company is continuing to review the impacted communications and will provide, if necessary, any required notifications to affected parties and applicable regulatory agencies. As of the date of this filing on Form 8-K, the Company believes that the incident will not have a material adverse effect on its business operations. The Company is continuing to investigate the incident. Cautionary Statement Regarding Forward Looking Statements Certain of the statements included in this Report constitute forward-looking statements within the meaning of the U.S. Private Securities Litigation Reform Act of 1995. Forward-looking statements are made based on management's current expectations and beliefs concerning future developments and their potential effects upon the Company and its subsidiaries. The Company's actual results may differ, possibly materially, from expectations or estimates reflected in such forward-looking statements. Certain important factors that could cause actual results to differ, possibly materially, from expectations or estimates reflected in such forward-looking statements can be found in the "Risk Factors" and "Forward-Looking Statements" sections included in the Company's Annual Reports on Form 10-K and Quarterly Reports on Form 10-Q. The Company does not undertake to update any particular forward-looking statement included in this document. 2

Regulatory filing
Not disclosedSEC EDGAR
2026-08-05Inter-Con SecurityInter-Con Security: a data breach

In June 2026, Inter-Con Security was targeted in a ShinyHunters “pay or leak” extortion campaign . The group subsequently published data it alleged was taken from the company, including 276k unique email addresses along with names, physical addresses, job titles and phone numbers. The data encompassed a combination of contacts, internal users and leads.

Data breach
276,114Have I Been Pwned
2026-08-05Robert ArshagouniRobert Arshagouni: a data breach

Robert Arshagouni notified the California Attorney General of a data breach on August 5, 2026, with the breach dated January 12, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-08-05New York City Regional Center, LLCNew York City Regional Center, LLC: a data breach

New York City Regional Center, LLC notified the California Attorney General of a data breach on August 5, 2026, with the breach dated March 30, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-08-05Station Casinos, LLCStation Casinos, LLC: a data breach

Station Casinos, LLC notified the California Attorney General of a data breach on August 5, 2026, with the breach dated March 5, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-08-05NFI North, Inc.

Healthcare

NFI North, Inc.: a health data breach

NFI North, Inc., a healthcare provider in NH, reported a breach of health information affecting 49,540 people to the US Department of Health and Human Services on August 5, 2026. HHS records the breach type as hacking/it incident, involving network server.

Data breach
49,540HHS Office for Civil Rights
2026-08-04UCLA HealthUCLA Health: a data breach

UCLA Health notified the California Attorney General of a data breach on August 4, 2026, with the breach dated December 27, 2024. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-08-04Malin + Goetz, Inc.Malin + Goetz, Inc.: a data breach

Malin + Goetz, Inc. notified the California Attorney General of a data breach on August 4, 2026, with the breach dated May 22, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-08-04Aesto, LLC (Grant County Public Hospital District #2)Aesto, LLC (Grant County Public Hospital District #2): a data breach

Aesto, LLC (Grant County Public Hospital District #2) notified the Washington State Attorney General on August 4, 2026 of a data breach that occurred on December 2, 2025, affecting 37,253 Washington residents. Information involved: Name, Social Security Number, Driver's License or Washington ID Card Number, Financial & Banking Information, Full Date of Birth, Medical Information, Protected Health Information owned or licensed by a HIPAA covered entity.

Data breach
Not disclosedWashington State Attorney General
2026-08-03CTS Journey Holdings, LLC, a Delaware limited liability company (DBA Corporate Travel Service)CTS Journey Holdings, LLC, a Delaware limited liability company (DBA Corporate Travel Service): a data breach

CTS Journey Holdings, LLC, a Delaware limited liability company (DBA Corporate Travel Service) notified the California Attorney General of a data breach on August 3, 2026, with the breach dated December 3, 2025. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General

About this tracker

435
Incidents
296
Ransomware gang claims
731
Last 30 days
401
Companies tracked
2,742,501,669
Records disclosed