Incident tracker

Recent cyber attacks and data breaches

DisclosedCompanyWhat happenedTypeRecordsSource
2026-05-21Barnhart Crane & Rigging Company, Inc.Barnhart Crane & Rigging Company, Inc.: a data breach

Barnhart Crane & Rigging Company, Inc. notified the Washington State Attorney General on May 21, 2026 of a data breach that occurred on April 23, 2025, affecting 1,068 Washington residents. Information involved: Name, Social Security Number, Driver's License or Washington ID Card Number, Financial & Banking Information, Full Date of Birth, Passport Number, Health Insurance Policy or ID Number, Medical Information.

Data breach
Not disclosedWashington State Attorney General
2026-05-20Frost BankFrost Bank: a data breach

Frost Bank notified the California Attorney General of a data breach on May 20, 2026, with the breach dated December 6, 2025. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-05-20Cardinal Services, Inc, Cardinal Employer Organization, and Preferred Employer Solutions, collectively (“Cardinal”)Cardinal Services, Inc, Cardinal Employer Organization, and Preferred Employer Solutions, collectively (“Cardinal”): a data breach

Cardinal Services, Inc, Cardinal Employer Organization, and Preferred Employer Solutions, collectively (“Cardinal”) notified the California Attorney General of a data breach on May 20, 2026, with the breach dated June 25, 2025. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-05-20VacPartsWarehouse.comVacPartsWarehouse.com: a data breach

VacPartsWarehouse.com notified the California Attorney General of a data breach on May 20, 2026, with the breach dated October 31, 2025. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-05-20VacPartsWarehouse.com LLC (PartsWarehouse.com)VacPartsWarehouse.com LLC (PartsWarehouse.com): a data breach

VacPartsWarehouse.com LLC (PartsWarehouse.com) notified the Washington State Attorney General on May 20, 2026 of a data breach that occurred on October 31, 2025, affecting 695 Washington residents. Information involved: Name, Financial & Banking Information.

Data breach
Not disclosedWashington State Attorney General
2026-05-20Cardinal Services, Inc, Cardinal Employer Organization, andCardinal Services, Inc, Cardinal Employer Organization, and: a data breach

Cardinal Services, Inc, Cardinal Employer Organization, and notified the Washington State Attorney General on May 20, 2026 of a data breach that occurred on June 30, 2025, affecting 2,066 Washington residents. Information involved: Name, Social Security Number, Driver's License or Washington ID Card Number, Financial & Banking Information, Full Date of Birth, Passport Number, Medical Information.

Data breach
Not disclosedWashington State Attorney General
2026-05-20WEST PHARMACEUTICAL SERVICES INCWST

Surgical & Medical Instruments & Apparatus

WEST PHARMACEUTICAL SERVICES INC disclosed a material cybersecurity incident
Regulatory filing
Not disclosedSEC EDGAR
2026-05-19CTTCTT: a data breach

In April 2026, data allegedly obtained from CTT, Portugal's national postal service, was posted to a public hacking forum . The data included 468k unique email addresses along with names, phone numbers and parcel tracking numbers which can be used to retrieve the tracking history of the parcel.

Data breach
468,124Have I Been Pwned
2026-05-18AddiAddi: a data breach

In March 2026, the Colombian fintech company Addi identified unauthorised activity on its platform and advised customers that "it is possible that your personal information may have been compromised". The "pay or leak" extortion group ShinyHunters subsequently claimed responsibility and published a large trove of personal data allegedly obtained from Addi. The data included 34M unique email addresses from credit scoring requests, credit bureau records, customer identity records and email validation logs. It also contained government issued IDs (Cédula de Ciudadanía), estimated income, socioeconomic levels, purchases and other credit-related data points.

Data breach
34,532,941Have I Been Pwned
2026-05-14AbrigoAbrigo: a data breach

In April 2026, the fintech software company Abrigo was targeted in a "pay or leak" extortion attempt by the ShinyHunters group . Shortly after, data allegedly taken from the company's Salesforce instance was published publicly and contained over 700k unique email addresses belonging to both Abrigo staff and external contacts. Whilst separate from Abrigo's Salesforce compromise via the Drift application connector the previous year , the data fields described in that incident are consistent with the ShinyHunters data, namely that it was "business contact information" including "institution name, employee name, email addresses, and phone numbers".

Data breach
711,099Have I Been Pwned

About this tracker

435
Incidents
295
Ransomware gang claims
730
Last 30 days
395
Companies tracked
2,742,501,669
Records disclosed