Incident tracker

Recent cyber attacks and data breaches

DisclosedCompanyWhat happenedTypeRecordsSource
2026-06-10University of NottinghamUniversity of Nottingham: a data breach

In June 2026, the University of Nottingham was the target of a cyber attack , later linked to a ShinyHunters "pay or leak" extortion campaign. Tens of gigabytes of data were subsequently published online and included 455k unique email addresses along with extensive personal information including names, addresses, phone numbers, ethnicities, disabilities, passport numbers and information relating to academic enrolments and fee payments. In a post about the incident , the university advised that the breach affected both "current students, and alumni".

Data breach
454,635Have I Been Pwned
2026-06-10Casino, LLC dba Larry Flynt's Lucky Lady CasinoCasino, LLC dba Larry Flynt's Lucky Lady Casino: a data breach

Casino, LLC dba Larry Flynt's Lucky Lady Casino notified the California Attorney General of a data breach on June 10, 2026, with the breach dated May 14, 2025. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-06-09Pearlman, Brown & Wax LLPPearlman, Brown & Wax LLP: a data breach

Pearlman, Brown & Wax LLP notified the California Attorney General of a data breach on June 9, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-06-07Baker DistributingBaker Distributing: a data breach

In May 2026, the HVAC/R wholesale distributor Baker Distributing Company was added to the ShinyHunters data extortion group's "pay or leak" site . In early June, the group publicly published data they claimed had been obtained from Baker's SharePoint and Salesforce infrastructure including 103k unique email addresses along with names, physical addresses, phone numbers and tickets relating to the company's HVAC contractor customer base. The exposed data was largely corporate contact and support information with limited sensitivity.

Data breach
102,935Have I Been Pwned
2026-06-05BCD TravelBCD Travel: a data breach

In May 2026, the corporate travel management company BCD Travel was claimed as a victim of the ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from BCD was subsequently published publicly in early June and contained 396k unique email addresses. Other exposed data included names, addresses, phone numbers, job titles and employer names, spanning a variety of different data sets including leads, internal staff and support tickets.

Data breach
396,313Have I Been Pwned
2026-06-05Ultrahuman Healthcare Private LimitedUltrahuman Healthcare Private Limited: a data breach

Ultrahuman Healthcare Private Limited notified the California Attorney General of a data breach on June 5, 2026, with the breach dated March 27, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-06-05Towerpoint Wealth, LLCTowerpoint Wealth, LLC: a data breach

Towerpoint Wealth, LLC notified the California Attorney General of a data breach on June 5, 2026, with the breach dated April 24, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-06-05Lansing Community CollegeLansing Community College: a data breach

Lansing Community College notified the California Attorney General of a data breach on June 5, 2026, with the breach dated February 12, 2025. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-06-05Meta Platforms, Inc.Meta Platforms, Inc.: a data breach

Meta Platforms, Inc. notified the California Attorney General of a data breach on June 5, 2026, with the breach dated April 17, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-06-05Plaza Home Mortgage Inc.Plaza Home Mortgage Inc.: a data breach

Plaza Home Mortgage Inc. notified the Washington State Attorney General on June 5, 2026 of a data breach that occurred on February 17, 2026, affecting 9,598 Washington residents. Information involved: Name, Social Security Number, Driver's License or Washington ID Card Number, Full Date of Birth, Username and Password/Security Question Answers.

Data breach
Not disclosedWashington State Attorney General

+1 more

About this tracker

435
Incidents
287
Ransomware gang claims
722
Last 30 days
389
Companies tracked
2,742,501,669
Records disclosed