Incident tracker

Recent cyber attacks and data breaches

DisclosedCompanyWhat happenedTypeRecordsSource
2026-05-28KemperKemper: a data breach

In April 2026, the American insurance holding company Kemper Corporation was named by the ShinyHunters ransomware group in a "pay or leak" extortion campaign . The attackers allegedly accessed Kemper's Salesforce environment via social engineering as part of a broader campaign targeting hundreds of organisations using the same method. The group later published tens of gigabytes of data they claimed included internal directory data, Salesforce records and Stripe payment logs. Among the 269k unique email addresses were names, phone numbers, physical addresses and partial payment card data including the last 4 digits, expiry dates and card brands. Kemper confirmed the incident and stated they had engaged third-party cybersecurity experts and notified law enforcement.

Data breach
269,299Have I Been Pwned
2026-05-28Johnson-Peltier Electric, Inc.Johnson-Peltier Electric, Inc.: a data breach

Johnson-Peltier Electric, Inc. notified the California Attorney General of a data breach on May 28, 2026, with the breach dated March 10, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-05-28La Perouse LLCLa Perouse LLC: a data breach

La Perouse LLC notified the California Attorney General of a data breach on May 28, 2026, with the breach dated May 27, 2025. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-05-28Blue Teal Holdings, LLCBlue Teal Holdings, LLC: a data breach

Blue Teal Holdings, LLC notified the California Attorney General of a data breach on May 28, 2026, with the breach dated October 13, 2025. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-05-28Smith & James, CPAsSmith & James, CPAs: a data breach

Smith & James, CPAs notified the California Attorney General of a data breach on May 28, 2026, with the breach dated March 5, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-05-28Texas CapitalTexas Capital: a data breach

Texas Capital notified the Washington State Attorney General on May 28, 2026 of a data breach that occurred on April 26, 2026, affecting 5,134 Washington residents. Information involved: Name, Social Security Number, Full Date of Birth.

Data breach
Not disclosedCalifornia Attorney General

+1 more

2026-05-27MytheresaMytheresa: a data breach

In April 2026, the luxury fashion e-commerce platform Mytheresa was listed as a victim of the ShinyHunters "pay or leak" extortion group . After the ransom deadline passed, the group publicly released the data which contained 84k unique email addresses. The exposed data also included names, phone numbers, physical addresses, purchases and partial credit card data including card type, last 4 digits and expiry date.

Data breach
84,108Have I Been Pwned
2026-05-27Ampex Data Systems CorporationAmpex Data Systems Corporation: a data breach

Ampex Data Systems Corporation notified the California Attorney General of a data breach on May 27, 2026, with the breach dated March 21, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-05-26AmeripriseAmeriprise: a data breach

In March 2026, the financial services firm Ameriprise Financial was named by the ShinyHunters group in a "pay or leak" extortion campaign . The group claimed possession of more than 200GB of compressed data exfiltrated from Ameriprise's Salesforce environment and internal SharePoint infrastructure, and subsequently published the data after negotiations allegedly failed. The published data contained 500k unique email addresses as well as names, phone numbers, physical addresses and employer information. In their disclosure to state attorneys general , Ameriprise reported 47,876 affected people; the larger email address population represents contacts from Ameriprise's broader operational systems, including internal staff. Ameriprise further advised that they have "implemented heightened monitoring of your account(s) to include enhanced identity verification procedures".

Data breach
502,597Have I Been Pwned
2026-05-26ERMI LLCERMI LLC: a data breach

ERMI LLC notified the California Attorney General of a data breach on May 26, 2026, with the breach dated February 15, 2025. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General

About this tracker

435
Incidents
287
Ransomware gang claims
722
Last 30 days
389
Companies tracked
2,742,501,669
Records disclosed