Incident tracker
Recent cyber attacks and data breaches
| Disclosed | Company | What happened | Type | Records | Source |
|---|---|---|---|---|---|
| 2026-07-29 | Quantum Health Healthcare | Quantum Health: a health data breach Quantum Health, a business associate in OH, reported a breach of health information affecting 2,104 people to the US Department of Health and Human Services on July 29, 2026. HHS records the breach type as hacking/it incident, involving network server. | Data breach | 2,104 | HHS Office for Civil Rights ↗ +2 more |
| 2026-07-29 | Central Texas Oral Health Healthcare | Central Texas Oral Health: a health data breach Central Texas Oral Health, a healthcare provider in TX, reported a breach of health information affecting 1,389 people to the US Department of Health and Human Services on July 29, 2026. HHS records the breach type as hacking/it incident, involving desktop computer, email. | Data breach | 1,389 | HHS Office for Civil Rights ↗ |
| 2026-07-29 | Associated Endocrinologists Healthcare | Associated Endocrinologists: a health data breach Associated Endocrinologists, a healthcare provider in MI, reported a breach of health information affecting 4,979 people to the US Department of Health and Human Services on July 29, 2026. HHS records the breach type as hacking/it incident, involving network server. | Data breach | 4,979 | HHS Office for Civil Rights ↗ |
| 2026-07-29 | Nephrology Associates, M.D., P.A. Healthcare | Nephrology Associates, M.D., P.A.: a health data breach Nephrology Associates, M.D., P.A., a healthcare provider in KS, reported a breach of health information affecting 24,088 people to the US Department of Health and Human Services on July 29, 2026. HHS records the breach type as hacking/it incident, involving network server. | Data breach | 24,088 | HHS Office for Civil Rights ↗ |
| 2026-07-29 | HEALTHSTREAM INCHSTM Services-Computer Programming, Data Processing, Etc. | HEALTHSTREAM INC disclosed a cybersecurity incident HealthStream, Inc. (the "Company") recently detected that the Company had experienced a cybersecurity incident in which an unauthorized third party gained access to a limited portion of files on the Company's corporate file server as described below. Following such detection, the Company initiated response protocols, launched an investigation, which remains ongoing, engaged the services of cybersecurity and forensics specialists and advisors, and notified certain law enforcement authorities. Based on the Company's investigation to date, we do not believe that any customer-facing systems were accessed or compromised. In addition, the Company has not identified evidence to date that protected health information, as defined by the Health Insurance Portability and Accountability Act ("HIPAA") was accessed or exfiltrated. Moreover, the Company has not identified any evidence indicating that any files were encrypted by the unauthorized third party. We have not experienced any interruption in our product or service delivery to customers or to our business operations. Based on the Company's investigation to date, the Company believes that certain information of the Company's employees, as well as billing related information of certain customers and vendors, and corporate and legal information of the Company, was accessed and/or exfiltrated from the Company's corporate file servers as the result of the incident. In addition, for approximately 75 of our credentialing customers, the Company had copied certain customer data to the Company's corporate file servers for purposes of data conversion, analytics, and troubleshooting for these customers. The Company has notified such customers regarding this incident. We have incurred, and expect to continue to incur, certain expenses related to this incident, including, among others, expenses to respond to, remediate and investigate this incident. To the extent required by contract or law, the Company will ensure that any additional notification is provided to individuals or other entities affected by this incident. While the Company's investigation is ongoing, based on information currently known, the Company does not expect that this incident will have a material adverse impact on the Company's business, operations or financial results. Cautionary Note regarding Forward-Looking Statements This Current Report on Form 8-K contains forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995 and federal securities laws that may relate to, among other things, statements regarding our current beliefs, understanding and expectations regarding this cybersecurity incident and its anticipated impact on our business, operations and financial results. Forward-looking statements are based on management's current expectations and beliefs concerning future developments and their potential effects on the Company. Forward-looking statements are not a guarantee of future events, results or performance and are subject to a variety of risks and uncertainties, many of which are beyond our control. Future events and actual results and performance could differ materially from those set forth in, contemplated by or underlying the forward-looking statements. Factors that could cause actual events, results or performance to differ from forward-looking statements include legal, reputational, and financial risks resulting from this cybersecurity incident, our ongoing investigation of this cybersecurity incident, including the Company's potential discovery of additional information related to the incident in connection with this investigation or otherwise, the potential impact of this incident on customer and vendor relationships and our business, the extent of available insurance coverage, the extent of expenses that are incurred by the Company in connection with this incident, and the risks set forth in Item 1A - "Risk Factors" in the Company's Annual Report on Form 10-K f | Regulatory filing | Not disclosed | SEC EDGAR ↗ |
| 2026-07-28 | Houston City College | Houston City College: a data breach In June 2026, Houston City College was the target of a ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from the college was later published publicly and included 832k unique email addresses along with names, addresses, phone numbers, academic records, and other personal information relating to both current students and alumni. | Data breach | 831,642 | Have I Been Pwned ↗ |
| 2026-07-28 | Fresno County Department of Social Services | Fresno County Department of Social Services: a data breach Fresno County Department of Social Services notified the California Attorney General of a data breach on July 28, 2026, with the breach dated August 26, 2025. The notice covers more than 500 California residents; California does not publish the exact number. | Data breach | Not disclosed | California Attorney General ↗ |
| 2026-07-28 | Sunrise Company | Sunrise Company: a data breach Sunrise Company notified the California Attorney General of a data breach on July 28, 2026, with the breach dated April 23, 2026. The notice covers more than 500 California residents; California does not publish the exact number. | Data breach | Not disclosed | California Attorney General ↗ |
| 2026-07-28 | ADT, Inc. | ADT, Inc.: a data breach ADT, Inc. notified the Washington State Attorney General on July 28, 2026 of a data breach that occurred on April 20, 2026, affecting 5,129 Washington residents. Information involved: Name, Social Security Number, Full Date of Birth. | Data breach | Not disclosed | Washington State Attorney General ↗ |
| 2026-07-27 | Regional Center of Orange County | Regional Center of Orange County: a data breach Regional Center of Orange County notified the California Attorney General of a data breach on July 27, 2026, with the breach dated May 27, 2026. The notice covers more than 500 California residents; California does not publish the exact number. | Data breach | Not disclosed | California Attorney General ↗ |
About this tracker
- 435
- Incidents
- 298
- Ransomware gang claims
- 733
- Last 30 days
- 401
- Companies tracked
- 2,742,501,669
- Records disclosed