Incident tracker

Recent cyber attacks and data breaches

DisclosedCompanyWhat happenedTypeRecordsSource
2026-08-27Psychiatry of Texas PLLC

Healthcare

Psychiatry of Texas PLLC: a health data breach

Psychiatry of Texas PLLC, a healthcare provider in TX, reported a breach of health information affecting 5,902 people to the US Department of Health and Human Services on August 27, 2026. HHS records the breach type as hacking/it incident, involving network server.

Data breach
5,902HHS Office for Civil Rights
2026-08-26Murfreesboro Medical ClinicMurfreesboro Medical Clinic: a data breach

Murfreesboro Medical Clinic notified the California Attorney General of a data breach on August 26, 2026, with the breach dated December 2, 2025. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-08-25CarharttCarhartt: a data breach

In August 2026, clothing retailer Carhartt was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data allegedly obtained from the company including 12.9M unique email addresses, names, phone numbers and physical addresses. The published corpus also contained millions of synthetic records that did not relate to real individuals and were excluded from the breach.

Data breach
12,933,413Have I Been Pwned
2026-08-25Livara Health Medical Group - dba SpineZoneLivara Health Medical Group - dba SpineZone: a data breach

Livara Health Medical Group - dba SpineZone notified the California Attorney General of a data breach on August 25, 2026, with the breach dated December 2, 2025. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-08-25Together Women's Health LLC - AestoTogether Women's Health LLC - Aesto: a data breach

Together Women's Health LLC - Aesto notified the California Attorney General of a data breach on August 25, 2026, with the breach dated December 2, 2025. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-08-25Shoshone Medical Center

Healthcare

Shoshone Medical Center: a health data breach

Shoshone Medical Center, a healthcare provider in ID, reported a breach of health information affecting 553 people to the US Department of Health and Human Services on August 25, 2026. HHS records the breach type as hacking/it incident, involving email.

Data breach
553HHS Office for Civil Rights
2026-08-24Museum Associates d/b/a Los Angeles Museum of Art (LACMA)Museum Associates d/b/a Los Angeles Museum of Art (LACMA): a data breach

Museum Associates d/b/a Los Angeles Museum of Art (LACMA) notified the California Attorney General of a data breach on August 24, 2026, with the breach dated July 7, 2025. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-08-24Allied HealthAllied Health: a data breach

Allied Health notified the California Attorney General of a data breach on August 24, 2026. The notice covers more than 500 California residents; California does not publish the exact number.

Data breach
Not disclosedCalifornia Attorney General
2026-08-24Pan American Group LLCPan American Group LLC: a data breach

Pan American Group LLC notified the Washington State Attorney General on August 24, 2026 of a data breach that occurred on April 8, 2026, affecting 12,309 Washington residents. Information involved: Name, Social Security Number, Driver's License or Washington ID Card Number, Financial & Banking Information, Full Date of Birth, Unique Private Key (e.g. used to authenticate or sign an electronic record), Student ID Number, Military ID Number, Passport Number, Health Insurance Policy or ID Number, Medical Information, Biometric Data.

Data breach
Not disclosedWashington State Attorney General

+1 more

2026-08-23NIUSNIUS: a data breach

In July 2025, the German news service NIUS suffered a data breach which was subsequently leaked publicly . The data included 6k unique email addresses along with names, physical addresses and payment details for purchases including either IBANs or partial credit card data (masked card number, type and expiry).

Data breach
6,090Have I Been Pwned

About this tracker

435
Incidents
287
Ransomware gang claims
722
Last 30 days
389
Companies tracked
2,742,501,669
Records disclosed