{
  "index": {
    "_comment": "Canonical HIH headline figures. Locked, nominal-only, matching the corrected manuscript (Built Wrong V41, footnotes 4 and 6): $2,074 against $343, a 6.05x ratio, 2014 to 2024.",
    "window": {
      "start": 2014,
      "end": 2024
    },
    "hero": {
      "input": 100,
      "cyber_value": 2074,
      "market_value": 343,
      "year_start": 2014,
      "year_end": 2024,
      "multiple": "6.05&times;",
      "multiple_tag": "Cybercrime loss outgrew the market over the decade: $2,074 against $343, both in nominal dollars, measured from year-end 2014 to year-end 2024.",
      "footnote": "Hacker in a Hoodie Index: reported losses to the FBI Internet Crime Complaint Center, $800,492,073 in 2014 against $16,600,000,000 in 2024. Compound annual growth rate 35.42 percent."
    },
    "rates": [
      {
        "value": "35.4%",
        "unit": "/yr",
        "label": "10-year window · 2014&ndash;2024"
      },
      {
        "value": "34.2%",
        "unit": "/yr",
        "label": "full record · 2001&ndash;2025"
      }
    ],
    "rate_note": "The IC3 growth rate barely moves across windows. The index is not built on a chosen base year, and the 6.05x multiple compares like with like: both figures are measured from year-end 2014 to year-end 2024, both in nominal dollars.",
    "provenance": {
      "ic3_2014_usd": 800492073,
      "ic3_2024_usd": 16600000000,
      "cagr_2014_2024_pct": 35.42,
      "sp500_nominal_from_100": 343,
      "hih_nominal_from_100": 2074,
      "ratio_nominal_to_nominal": 6.05,
      "sp500_citation": "S&P Dow Jones Indices, S&P 500 total return (dividends reinvested), year-end 2014 through year-end 2024, from the index total-return levels (12,911.82 / 3,769.44 = 3.4254).",
      "sp500_url": "https://www.slickcharts.com/sp500/returns",
      "note": "Compare nominal against nominal: both figures are measured in nominal dollars over the same year-end 2014 to year-end 2024 window. Never compare a nominal figure against an inflation-adjusted one; that mismatch produces a wrong multiple."
    }
  },
  "series": {
    "_comment": "Annual loss series. Values in USD. Add a year here and the chart redraws on next build.",
    "generated_at": "2026-09-03T18:11:13.466Z",
    "ic3": {
      "label": "IC3 reported losses",
      "meta": "/ US complaints / Verified",
      "color": "#1D4ED8",
      "_note": "2010 deliberately omitted: IC3's retrospective plots ~$1.0B while its contemporaneous 2010 report recorded $485M. The two disagree, so the point is left out.",
      "points": [
        {
          "year": 2001,
          "usd": 17800000
        },
        {
          "year": 2005,
          "usd": 183000000
        },
        {
          "year": 2014,
          "usd": 800492073
        },
        {
          "year": 2015,
          "usd": 1100000000
        },
        {
          "year": 2016,
          "usd": 1500000000
        },
        {
          "year": 2017,
          "usd": 1400000000
        },
        {
          "year": 2018,
          "usd": 2700000000
        },
        {
          "year": 2019,
          "usd": 3500000000
        },
        {
          "year": 2020,
          "usd": 4200000000
        },
        {
          "year": 2021,
          "usd": 6900000000
        },
        {
          "year": 2022,
          "usd": 10300000000
        },
        {
          "year": 2023,
          "usd": 12500000000
        },
        {
          "year": 2024,
          "usd": 16600000000
        },
        {
          "year": 2025,
          "usd": 20877000000
        }
      ]
    },
    "chainalysis": {
      "label": "Chainalysis ransom payments",
      "meta": "/ on-chain / revised",
      "color": "#7C3AED",
      "points": [
        {
          "year": 2019,
          "usd": 220000000
        },
        {
          "year": 2021,
          "usd": 1086000000
        },
        {
          "year": 2022,
          "usd": 637000000
        },
        {
          "year": 2023,
          "usd": 1230000000
        },
        {
          "year": 2025,
          "usd": 820000000
        }
      ]
    },
    "ibm": {
      "label": "IBM average cost per data breach",
      "color": "#64748B",
      "points": [
        {
          "year": 2014,
          "usd": 3500000
        },
        {
          "year": 2019,
          "usd": 3920000
        },
        {
          "year": 2024,
          "usd": 4880000
        },
        {
          "year": 2025,
          "usd": 4440000
        },
        {
          "year": 2026,
          "usd": 4990000
        }
      ]
    }
  },
  "sources": {
    "_comment": "The Verifiable Sources cards. Grade: V (Verified), A (Attested), I (Inferred).",
    "sources": [
      {
        "id": "ic3",
        "name": "FBI IC3",
        "color": "#1D4ED8",
        "latest": "$20.9B",
        "latest_label": "LATEST · 2025",
        "counts": "Losses from internet-crime complaints filed by US victims.",
        "excludes": "Crime never reported; non-US victims; the great majority of incidents, where no complaint is filed.",
        "growth": "34%/yr across 24 years (2001&ndash;2025)",
        "grade": "V",
        "cadence": "Annual, full series",
        "link_text": "FBI IC3 Annual Reports",
        "link_url": "https://www.ic3.gov/annualreport/reports"
      },
      {
        "id": "chainalysis",
        "name": "Chainalysis",
        "color": "#7C3AED",
        "latest": "$0.82B",
        "latest_label": "LATEST · 2025",
        "counts": "Cryptocurrency payments to ransomware actors, traced on-chain.",
        "excludes": "Recovery and downtime costs; untraced channels; anything that is not a ransom payment.",
        "growth": "Volatile. Peaked $1.23B in 2023, fell since.",
        "grade": "V",
        "cadence": "Annual, revised · anchors",
        "link_text": "Chainalysis Crypto Crime Report",
        "link_url": "https://www.chainalysis.com/reports/"
      },
      {
        "id": "ibm",
        "name": "IBM / Ponemon",
        "color": "#64748B",
        "latest": "$4.99M",
        "latest_label": "LATEST · 2026",
        "counts": "Modeled average cost of a single data breach across ~600 organizations.",
        "excludes": "Aggregate national or global totals. A per-event average, not a sum.",
        "growth": "~3%/yr since 2014, to a record $4.99M in 2026.",
        "grade": "A",
        "cadence": "Annual · anchors",
        "link_text": "IBM Cost of a Data Breach",
        "link_url": "https://www.ibm.com/reports/data-breach"
      }
    ]
  },
  "incidents": {
    "_comment": "Two separate feeds. The 8-K scoreboard is Verified primary filings only. The 'beyond' feed carries company statements (Attested) and outside estimates (Inferred). Never sum either feed.",
    "generated_at": "2026-09-03T18:11:13.466Z",
    "sector_counts": {
      "bars": [
        {
          "sector": "Healthcare and Life Sciences",
          "count": 64,
          "is_other": false
        },
        {
          "sector": "Financial Services",
          "count": 38,
          "is_other": false
        },
        {
          "sector": "Retail and Consumer",
          "count": 25,
          "is_other": false
        },
        {
          "sector": "Public Sector and Education",
          "count": 23,
          "is_other": false
        },
        {
          "sector": "Technology and Software",
          "count": 22,
          "is_other": false
        },
        {
          "sector": "Manufacturing",
          "count": 21,
          "is_other": false
        },
        {
          "sector": "Professional and Business Services",
          "count": 20,
          "is_other": false
        },
        {
          "sector": "Transportation and Logistics",
          "count": 10,
          "is_other": false
        },
        {
          "sector": "Wholesale and Distribution",
          "count": 7,
          "is_other": false
        },
        {
          "sector": "Real Estate and Construction",
          "count": 6,
          "is_other": false
        },
        {
          "sector": "Telecommunications",
          "count": 6,
          "is_other": false
        },
        {
          "sector": "Energy and Utilities",
          "count": 5,
          "is_other": false
        },
        {
          "sector": "Other",
          "count": 4,
          "is_other": true,
          "folds": 3
        }
      ],
      "n": 251,
      "pending": 0,
      "corroborations": 19,
      "fold_threshold": 3
    },
    "featured": null,
    "materiality": {
      "basis": "sec_8k_item_105",
      "filings": 53,
      "priced": 13,
      "unpriced": 40
    },
    "silence": {
      "n": 181,
      "priced": 27,
      "unpriced": 154,
      "excluded": 70,
      "by_feed": {
        "sec_8k": {
          "n": 115,
          "priced": 25,
          "unpriced": 90,
          "excluded": 70
        },
        "beyond_8k": {
          "n": 66,
          "priced": 2,
          "unpriced": 64,
          "excluded": 0
        }
      }
    },
    "sec_8k": {
      "ytd_year": 2026,
      "ytd_count": 38,
      "ytd_count_is_placeholder": false,
      "events": [
        {
          "org": "West Pharmaceutical Services",
          "breached_entity": null,
          "date": "May 2026",
          "disclosed": "2026-05-01",
          "group": "14e78d82-1d78-4e19-887c-fb1aa52e961b",
          "slug": null,
          "is_primary": false,
          "detail": "Material attack. Data exfiltrated, systems encrypted, global operations disrupted.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/105770/000010577026000068/wst-20260507.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "single",
            "amount": "$7M",
            "amount_usd": 7000000,
            "category": "business_interruption",
            "grade": "V",
            "state": "estimated",
            "source_url": "https://www.sec.gov/Archives/edgar/data/105770/000010577026000099/wst-20260630.htm",
            "source_label": "SEC 10-Q",
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Stryker Corp",
          "breached_entity": null,
          "date": "Mar 2026",
          "disclosed": "2026-03-01",
          "group": "42ef78b4-8083-4e0e-8014-0e43305a5ea3",
          "slug": "stryker-corp-2026-04-09",
          "is_primary": false,
          "detail": "Material incident disclosed; operations since restored. Cost disclosure pending.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/310764/000119312526149607/d112875d8ka.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "CB Financial Services",
          "breached_entity": null,
          "date": "May 2026",
          "disclosed": "2026-05-01",
          "group": "ad9e7575-9f70-461b-9d7d-6364dc247910",
          "slug": "community-bank-2026-05-11",
          "is_primary": false,
          "detail": "Determined material. Customer names, Social Security numbers and dates of birth disclosed.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1605301/000160530126000021/cbfv-20260507.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "8X8 INC",
          "breached_entity": "Klue",
          "date": "Jun 2026",
          "disclosed": "2026-06-23",
          "group": "69517a2c-8457-4a37-99a3-24211996b87e",
          "slug": "klue-2026-06-23",
          "is_primary": true,
          "detail": "8x8 learned on June 13, 2026, that a threat actor exploited the Klue Labs application programming interface plugged into its Salesforce CRM. The filing names the vendor and the integration; it says nothing about what data moved through that connection or how many records. Klue has not said how many of its hundreds of customers are affected. Several companies have come forward to confirm they had data stolen during the attack, including Gong, Jamf, HackerOne, Insurity, OneTrust, Recorded Future, Snyk, Sprout Social, and Tanium.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1023731/000102373126000084/eght-20260617.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Technology and Software",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "iRhythm Holdings, Inc.",
          "breached_entity": null,
          "date": "Jun 2026",
          "disclosed": "2026-06-15",
          "group": "2f099860-9e09-44cd-a5ae-26a7cbba286a",
          "slug": "irhythm-holdings-inc-2026-06-15",
          "is_primary": true,
          "detail": "Unauthorized activity struck iRhythm Holdings' data inside 'certain third-party-hosted business applications' on June 8, 2026, a phrase that names no vendor, no entry point, and no data type. The filing quantifies the damage at $700K before it quantifies what was actually taken. Outsourcing the application does not outsource the exposure; the perimeter is wherever the vendor's login page sits. A breach description this vague is not discretion; it is a structural admission that nobody yet knows the shape of the failure.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1388658/000138865826000055/irtc-20260610.htm",
          "enforcement": null,
          "amount": "$700K",
          "grade": "V",
          "money": {
            "case": "single",
            "amount": "$700K",
            "amount_usd": 700000,
            "category": "direct_expense",
            "grade": "V",
            "state": null,
            "source_url": "https://www.sec.gov/Archives/edgar/data/1388658/000138865826000072/irtc-20260630.htm",
            "source_label": "SEC 10-Q",
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": 52,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$700K",
              "amount_usd": "700000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/1388658/000138865826000072/irtc-20260630.htm",
              "disclosed": "2026-08-06",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "AdaptHealth Corp.",
          "breached_entity": null,
          "date": "Jun 2026",
          "disclosed": "2026-07-02",
          "group": "337e08e8-76ee-44b2-a2aa-a1b9b092439a",
          "slug": null,
          "is_primary": true,
          "detail": "A social-engineering attack compromised a third-party contractor’s user session and gave the attacker access to AdaptHealth cloud applications, patient systems and external EHR portals. Data was exfiltrated, including patient PII/PHI and insurance-billing password data. This is a clean cyber incident: compromised identity, unauthorized access and confirmed data theft.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1725255/000110465926080297/ahco-20260627x8k.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "River Financial Corp",
          "breached_entity": null,
          "date": "Jun 2026",
          "disclosed": "2026-07-10",
          "group": "44366b3c-853b-47c0-b9c5-53d660f0847c",
          "slug": null,
          "is_primary": true,
          "detail": "River Financial said an unauthorized actor got into its network and ransomware was deployed across portions of the server environment. The later update added that data was removed, which pivots this from a disruption story into a theft story too. River Financial publicly stated that ue to the preliminary nature of the forensic investigation and the early stages of the legal proceedings, management is currently unable to predict the ultimate outcome of these matters or reasonably estimate the amount or range of potential financial loss, if any, that may result.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1641601/000119312526300763/ck0001641601-20260619.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "NAVIENT CORP  (JSM, NAVI)",
          "breached_entity": null,
          "date": "Jun 2026",
          "disclosed": "2026-07-02",
          "group": "0b324722-818f-40c1-8353-81c096cfca3d",
          "slug": "navient-corp-jsm-navi-2026-07-02",
          "is_primary": true,
          "detail": "Navient's June 8, 2026 filing names a ransomware attack on a third-party law firm the company retains, and stops there. No entry point, no record count, no data type; the filing is silent on all three. Outside counsel sits inside the trust boundary by necessity, holding files a servicer can't keep in house, and nobody audits that firm's systems the way regulators audit Navient's. The breach happened on someone else's network, but the exposure, whatever it turns out to be, happened to Navient's business.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1593538/000114036126027441/ef20077249_8k.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "AFLAC INC",
          "breached_entity": "Aflac Life Insurance Japan Ltd.",
          "date": "Jun 2026",
          "disclosed": "2026-06-30",
          "group": "5e38686a-ae23-499e-81c2-a65e3a2b70b2",
          "slug": null,
          "is_primary": true,
          "detail": "Other Events. On June 30, 2026, Aflac Life Insurance Japan Ltd. (\"Aflac Japan\"), a wholly owned subsidiary of Aflac Incorporated, a Georgia corporation (the \"Company\"), issued a press release announcing that, on June 25, 2026, Aflac Japan discovered an unauthorized third-party had unlawfully accessed certain of Aflac Japan systems and data.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/4977/000162828026046124/afl-20260630.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "SR Bancorp, Inc.",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-07-10",
          "group": "2b539ba3-6354-4a18-abf9-72136ea7f9bf",
          "slug": null,
          "is_primary": true,
          "detail": "Other Events Mercadien, P.C. CPAs (\"Mercadien\"), which provides internal audit-related services to SR Bancorp, Inc (the \"Company\") and Somerset Regal Bank (the \"Bank\"), has discovered a data security incident in which an unauthorized actor accessed and acquired certain files on Mercadien's computer servers.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1951276/000094337426000261/srbk-20260706.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "UNITED NATURAL FOODS INC",
          "breached_entity": null,
          "date": "Jun 2025",
          "disclosed": "2025-06-26",
          "group": "3574b5dd-8985-4f16-87f9-cead2db2692c",
          "slug": null,
          "is_primary": true,
          "detail": "United Natural Foods pulled its own network offline to stop the June 5, 2025 intrusion, freezing the order and fulfillment systems that feed some 30,000 grocery stores, Whole Foods included. The company never named the attack or the actor, and no group claimed it; what mattered was not who got in but what a single intrusion could reach. When one distributor is the spine for a continent of shelves, the damage is counted not in stolen records but in the $350 to $400 million of orders that never shipped.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1020859/000102085925000036/unfi-20250621.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "set",
            "amount": null,
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": [
              {
                "amount": "$400M",
                "amount_usd": 400000000,
                "category": "business_interruption",
                "state": "estimated",
                "grade": "V",
                "disclosure": null,
                "source_url": "https://www.sec.gov/Archives/edgar/data/1020859/000102085925000054/unfi-20250802.htm",
                "source_label": "SEC 10-K"
              },
              {
                "amount": "$50M",
                "amount_usd": 50000000,
                "category": "business_interruption",
                "state": "estimated",
                "grade": "V",
                "disclosure": null,
                "source_url": "https://www.sec.gov/Archives/edgar/data/1020859/000102085925000054/unfi-20250802.htm",
                "source_label": "SEC 10-K"
              },
              {
                "amount": "$22M",
                "amount_usd": 22000000,
                "category": "direct_expense",
                "state": "realized",
                "grade": "V",
                "disclosure": null,
                "source_url": "https://www.sec.gov/Archives/edgar/data/1020859/000102085926000015/unfi-20260502.htm",
                "source_label": "SEC 10-Q"
              }
            ]
          },
          "sector": "Wholesale and Distribution",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "SONIC AUTOMOTIVE INC",
          "breached_entity": null,
          "date": "Jul 2024",
          "disclosed": "2024-08-05",
          "group": "c7779673-fe4b-4c9f-994a-cbbb1a0088b3",
          "slug": null,
          "is_primary": false,
          "detail": "Sonic Automotive could not sell cars for the better part of two weeks, not because its own network fell but because CDK Global, the single vendor running its dealer management system, was ransomwared by a crew reporting ties to BlackSuit. When one SaaS provider is the floor beneath every franchise's sales, inventory, and accounting, its outage is the dealership's outage. Sonic booked a material hit to the quarter over software it did not run and could not bring back.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1043509/000104350924000063/sah-20240705.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "DATA I/O CORP",
          "breached_entity": null,
          "date": "Sep 2025",
          "disclosed": "2025-09-10",
          "group": "3a0ed6fe-9e6d-4abe-922f-e7fc3c37f4bf",
          "slug": null,
          "is_primary": true,
          "detail": "Data I/O's intrusion came through the firewall itself, a vulnerability in a commercial third-party appliance, the box sold to be the perimeter serving instead as the door. The August 16 ransomware froze shipping, manufacturing, and communications at a company that programs chips for Apple and Bosch, and cost roughly $388,000 before systems returned by September 4. No group has claimed it and no customer data theft has surfaced, leaving the entry point named and the intruder anonymous.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/351998/000165495425010613/daio_8k.htm",
          "enforcement": null,
          "amount": "$388K",
          "grade": "V",
          "money": {
            "case": "single",
            "amount": "$388K",
            "amount_usd": 388000,
            "category": "direct_expense",
            "grade": "V",
            "state": "realized",
            "source_url": "https://www.sec.gov/Archives/edgar/data/351998/000165495426003625/daio_10k.htm",
            "source_label": "SEC 10-K",
            "caveat": null,
            "figures": []
          },
          "sector": "Manufacturing",
          "needs_grading": false,
          "lag_days": 218,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$388K",
              "amount_usd": "388000",
              "grade": "V",
              "source": "SEC 10-K",
              "url": "https://www.sec.gov/Archives/edgar/data/351998/000165495426003625/daio_10k.htm",
              "disclosed": "2026-04-16",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "CareCloud, Inc.  (CCLD, CCLDO)",
          "breached_entity": null,
          "date": "Mar 2026",
          "disclosed": "2026-03-27",
          "group": "c71b54a1-7250-4de9-9187-2e76faf4b23c",
          "slug": null,
          "is_primary": true,
          "detail": "CareCloud restored functionality within eight hours and called March 16 a temporary network disruption, but the outage was the symptom, not the breach. An unauthorized party had been inside one of its AWS environments since March 10, six days copying databases before anything showed. The count settled at 3.76 million people, Social Security numbers, financial and medical records, up from an initial 345,000. A cloud environment that registers a week of theft as an eight-hour outage was the front door all along.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1582982/000149315226013239/form8-k.htm",
          "enforcement": null,
          "amount": "$100K",
          "grade": "V",
          "money": {
            "case": "total",
            "amount": "$100K",
            "amount_usd": 100000,
            "category": "total_incident_cost",
            "grade": "A",
            "state": "realized",
            "source_url": "https://www.sec.gov/Archives/edgar/data/1582982/000149315226036363/form10-q.htm",
            "source_label": "SEC 10-Q",
            "caveat": "The company's own complete incident total.",
            "figures": [],
            "cumulative": null
          },
          "sector": "Technology and Software",
          "needs_grading": false,
          "lag_days": 132,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$100K",
              "amount_usd": "100000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/1582982/000149315226036363/form10-q.htm",
              "disclosed": "2026-08-06",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "NUCOR CORP",
          "breached_entity": null,
          "date": "May 2025",
          "disclosed": "2025-06-20",
          "group": "05843d30-cac1-4927-9dc6-11b0fe4b7fb3",
          "slug": null,
          "is_primary": true,
          "detail": "Nucor took steel mills offline across multiple sites after a threat actor reached its corporate IT systems, the wall between office networks and the plant floor apparently thinner than the org chart suggested. The company calls the stolen data limited and the impact immaterial, though no one has said what left, how much, or who took it, and no group has claimed the attack. When an intrusion in the back office can idle a blast furnace, the boundary was never really there.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/73309/000119312525143135/d926586d8ka.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Manufacturing",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Bitcoin Depot Inc.  (BTM, BTMWW)",
          "breached_entity": null,
          "date": "Mar 2026",
          "disclosed": "2026-04-08",
          "group": "24de0d3a-cb58-4fe4-930b-e9be95d55307",
          "slug": null,
          "is_primary": true,
          "detail": "Bitcoin Depot disclosed that attackers compromised internal systems and stole approximately $3.665 million in Bitcoin from company-controlled corporate wallets. The company stated that the incident involved its internal settlement accounts and, based on its investigation, did not impact customer wallets or customer cryptocurrency holdings.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1901799/000119312526147772/btm-20260406.htm",
          "enforcement": null,
          "amount": "$3.665M",
          "grade": "V",
          "money": {
            "case": "single",
            "amount": "$3.665M",
            "amount_usd": 3665000,
            "category": null,
            "grade": "V",
            "state": "estimated",
            "source_url": "https://www.sec.gov/Archives/edgar/data/1901799/000119312526147772/btm-20260406.htm",
            "source_label": "SEC 8-K, Item 1.05",
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": -2,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$3.665M",
              "amount_usd": "3665000",
              "grade": "V",
              "source": "SEC 8-K, Item 1.05",
              "url": "https://www.sec.gov/Archives/edgar/data/1901799/000119312526147772/btm-20260406.htm",
              "disclosed": "2026-04-06",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "F5, INC.",
          "breached_entity": null,
          "date": "Oct 2025",
          "disclosed": "2025-10-15",
          "group": "1e72e9e3-9a42-4140-9533-14d58eb7c442",
          "slug": null,
          "is_primary": true,
          "detail": "The stolen files were not customer records but F5's blueprints: BIG-IP source code and the vulnerabilities it had not yet patched, taken from the vendor whose appliances sit at the edge of 48 of the Fortune 50. Reporting ties the intrusion to a China-nexus group that held persistent access for at least a year before F5 noticed. When the vendor guarding everyone's front door keeps its unfixed flaws in one place, the perimeter and the arsenal are the same building.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1048695/000104869525000149/ffiv-20251015.htm",
          "enforcement": null,
          "amount": "$23.5M",
          "grade": "V",
          "money": {
            "case": "single",
            "amount": "$26.5M",
            "amount_usd": 26500000,
            "category": "direct_expense",
            "grade": "V",
            "state": "realized",
            "source_url": "https://d18rn0p25nwr6d.cloudfront.net/CIK-0001048695%20/613655dc-0b4b-4121-b52d-1de9a05a5b27.pdf",
            "source_label": "SEC 10-Q",
            "caveat": null,
            "figures": []
          },
          "sector": "Technology and Software",
          "needs_grading": false,
          "lag_days": 113,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$17.5M",
              "amount_usd": "17500000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/1048695/000104869526000023/ffiv-20251231.htm",
              "disclosed": "2026-02-05",
              "pre_tracking": false
            },
            {
              "amount": "$23.5M",
              "amount_usd": "23500000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/1048695/000104869526000051/ffiv-20260331.htm",
              "disclosed": "2026-05-05",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "AT&T INC.  (T, TBB, TBC, T-PA, T-PC)",
          "breached_entity": null,
          "date": "May 2024",
          "disclosed": "2024-07-12",
          "group": "275f06eb-09d1-468b-8d76-b92a9085cc2d",
          "slug": null,
          "is_primary": true,
          "detail": "The breach was in a Snowflake data warehouse, not AT&T's network, reached with stolen passwords because no second factor stood in the way, and it held the call and text records of nearly every AT&T customer. Not the words, just who contacted whom, how long, and roughly where: the shape of 110 million lives. AT&T reportedly paid about $370,000 to have the file deleted, which assumes a copy is a thing you can take back.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/732717/000073271724000046/t-20240506.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Telecommunications",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Federal Home Loan Bank of New York",
          "breached_entity": null,
          "date": "Feb 2024",
          "disclosed": "2024-03-01",
          "group": "bba262f4-54ed-4515-8518-bfa46c980d4c",
          "slug": null,
          "is_primary": true,
          "detail": "The fraud reached the Federal Home Loan Bank of New York through a fourth-party vendor, a supplier of one of its own suppliers, a party the Bank never contracted with yet left a path toward its funds. Its operational controls caught the attempt on February 21, 2024, and no money moved. Neither the compromised firm nor the people behind it was ever named: the trust boundary ran one vendor past anyone the Bank could actually see.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1329842/000165495424002505/fhlbny_8k.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "GLOBE LIFE INC.  (GL, GL-PD)",
          "breached_entity": null,
          "date": "Jun 2024",
          "disclosed": "2024-06-14",
          "group": "e6ab5507-14f1-46fb-9012-f31007dd393d",
          "slug": null,
          "is_primary": true,
          "detail": "Globe Life's agent web portal ran on access permissions and identity checks that could not tell a real user from an impostor, and that portal was the door out. Because the records sat in databases held by its independent agency owners rather than one hardened store, a single portal flaw reached roughly 850,000 people: names, Social Security numbers, health details. The company named the extortion note that followed, never the attacker behind it. When identity is the only lock, a broken check is the whole breach.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/320335/000032033524000029/gl-20240614.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "DICK'S SPORTING GOODS, INC.",
          "breached_entity": null,
          "date": "Aug 2024",
          "disclosed": "2024-08-28",
          "group": "5582611b-6272-48bf-bdab-c7836410fd71",
          "slug": null,
          "is_primary": true,
          "detail": "Dick's Sporting Goods contained the intrusion by locking all of its roughly 55,500 employees out of their own accounts, restoring access only after IT verified identities one video call at a time. When credentials are the perimeter, containment means treating the entire workforce as a suspect. What was taken, who took it, and how many people it reached were never named: an intrusion acknowledged, and almost nothing around it.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1089063/000108906324000104/dks-20240821.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "First American Financial Corp",
          "breached_entity": null,
          "date": "Dec 2023",
          "disclosed": "2023-12-29",
          "group": "62286217-a89a-4e56-b8d7-7206171e88bc",
          "slug": null,
          "is_primary": true,
          "detail": "First American took its website, email, and much of its network offline in late December 2023 after intruders reached certain non-production servers, copied their contents, and encrypted the rest. The company never named the group, the vector, or the ransom, so the architecture speaks for itself: the names and driver's license numbers of about 44,000 people sat on machines it classified as non-production. Non-production is a label about the server, not the people whose identities lived on it.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1472787/000095017023073848/faf-20231220.htm",
          "enforcement": null,
          "amount": "$11M",
          "grade": "V",
          "money": {
            "case": "single",
            "amount": "$11M",
            "amount_usd": 11000000,
            "category": "direct_expense",
            "grade": "V",
            "state": null,
            "source_url": "https://www.sec.gov/Archives/edgar/data/1472787/000095017024017418/faf-20231231.htm",
            "source_label": "SEC 10-K",
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": 54,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Fidelity National Financial, Inc.",
          "breached_entity": null,
          "date": "Nov 2023",
          "disclosed": "2024-01-09",
          "group": "75e32238-ff44-4f76-b6f0-9d36a68c1f28",
          "slug": null,
          "is_primary": true,
          "detail": "Fidelity National Financial locked its own systems to stop the intrusion and froze the title and escrow work sitting at the center of American home closings: hundreds of sales stalled because one title insurer went dark. Non-self-propagating malware still left with data on about 1.3 million people, names, Social Security numbers, loan numbers, from a network where one foothold reached far more than it should have. ALPHV/BlackCat claimed the attack and quietly pulled FNF from its leak site by mid-December, the usual tell of a ransom paid.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1331875/000133187524000005/fnf-20231119.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "First American Financial Corp",
          "breached_entity": null,
          "date": "Dec 2023",
          "disclosed": "2024-01-12",
          "group": "62286217-a89a-4e56-b8d7-7206171e88bc",
          "slug": null,
          "is_primary": false,
          "detail": "First American took its website, email, and much of its network offline in late December 2023 after intruders reached certain non-production servers, copied their contents, and encrypted the rest. The company never named the group, the vector, or the ransom, so the architecture speaks for itself: the names and driver's license numbers of about 44,000 people sat on machines it classified as non-production. Non-production is a label about the server, not the people whose identities lived on it.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1472787/000095017024004247/faf-20231220.htm",
          "enforcement": null,
          "amount": "$11M",
          "grade": "V",
          "money": {
            "case": "single",
            "amount": "$11M",
            "amount_usd": 11000000,
            "category": "direct_expense",
            "grade": "V",
            "state": null,
            "source_url": "https://www.sec.gov/Archives/edgar/data/1472787/000095017024017418/faf-20231231.htm",
            "source_label": "SEC 10-K",
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": 54,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$11M",
              "amount_usd": "11000000",
              "grade": "V",
              "source": "SEC 10-K",
              "url": "https://www.sec.gov/Archives/edgar/data/1472787/000095017024017418/faf-20231231.htm",
              "disclosed": "2024-02-21",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "V F CORP",
          "breached_entity": null,
          "date": "Dec 2023",
          "disclosed": "2024-01-18",
          "group": "76c43f4b-2fe8-4f7d-914e-cd8a597f13b7",
          "slug": null,
          "is_primary": true,
          "detail": "VF Corporation runs Vans, The North Face, Timberland, and Supreme off one shared operational core, which is why a single December intrusion reached the personal data of about 35.5 million consumers. The company took its systems offline mid-holiday, then noted it retains no card numbers or Social Security numbers, as if the names, addresses, and order histories that did leave were a consolation prize. Reporting ties the attack to the ALPHV/BlackCat crew; how the access was gained VF never said.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/103379/000119312524010243/d641969d8ka.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Manufacturing",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Hewlett Packard Enterprise Co",
          "breached_entity": null,
          "date": "Jan 2024",
          "disclosed": "2024-01-24",
          "group": "71045d35-d116-4892-9807-18a7a1825b76",
          "slug": null,
          "is_primary": true,
          "detail": "Midnight Blizzard, the crew tied to Russia's SVR, sat inside HPE's cloud email environment for months before anyone noticed, reading the mailboxes of the cybersecurity, marketing, and business teams themselves. How the door opened HPE never said; what it left on the record is a mail tenant treated as the soft interior of the network, where a nation-state could browse the security team's own inbox at its leisure. Dwell time here was measured in seasons, not minutes.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1645590/000164559024000009/hpe-20240119.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Technology and Software",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "WILLIS LEASE FINANCE CORP",
          "breached_entity": null,
          "date": "Feb 2024",
          "disclosed": "2024-02-09",
          "group": "7f8989dc-6e34-4790-b40c-02a969558086",
          "slug": null,
          "is_primary": true,
          "detail": "Willis Lease Finance took systems offline on January 31, 2024, after intruders reached the archive an aircraft-engine lessor quietly accumulates: employee Social Security numbers, passport scans, airline leasing agreements, the NDAs that bind them. How the intrusion happened was never stated; what left was, once Black Basta claimed the theft and posted roughly 910 GB to its leak site. A niche financier is still a warehouse of everyone else's secrets, which is why one break-in spills an entire industry's paperwork.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1018164/000101816424000005/wlfc-20240209.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "PRUDENTIAL FINANCIAL INC  (PFH, PRH, PRS, PRU)",
          "breached_entity": null,
          "date": "Feb 2024",
          "disclosed": "2024-02-21",
          "group": "a0e2ffc7-6f30-4511-b8cd-ab4db3b609b5",
          "slug": null,
          "is_primary": true,
          "detail": "The intruders walked in through employee and contractor accounts, the kind of access that treats a valid login as proof of belonging, and left with names, addresses, and driver's license numbers. Prudential first put the count at roughly 36,000; the final tally was 2,556,210, a blast radius it underestimated by close to seventy to one. ALPHV claimed the theft on its leak site, but the harder number is how long the company took to learn the size of its own breach.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1137774/000119312524040749/d766318d8ka.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "loanDepot, Inc.",
          "breached_entity": null,
          "date": "Jan 2024",
          "disclosed": "2024-02-27",
          "group": "10856809-0091-4fa0-a00e-ebb0e721b7ff",
          "slug": null,
          "is_primary": true,
          "detail": "loanDepot ran origination, servicing, and its customer portal on ground flat enough that one phished login could encrypt the whole thing and reach roughly 16.6 million people's Social Security numbers, financial accounts, and loan files. ALPHV/BlackCat claimed the intrusion and demanded $10 million; the company refused, then spent three weeks and about $27 million rebuilding what a single email had unlocked. A network with no interior walls is not breached so much as opened.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1831631/000183163124000020/ldi-20240104.htm",
          "enforcement": null,
          "amount": "$24.6M",
          "grade": "V",
          "money": {
            "case": "total",
            "amount": "$24.6M",
            "amount_usd": 24600000,
            "category": "total_incident_cost",
            "grade": "V",
            "state": "realized",
            "source_url": "https://www.sec.gov/Archives/edgar/data/1831631/000183163125000023/ldi-20241231.htm",
            "source_label": "SEC 10-K",
            "caveat": "Company-stated total, of which: direct response costs $1.8M.",
            "figures": [
              {
                "amount": "$1.8M",
                "amount_usd": 1800000,
                "category": "direct_expense",
                "state": "realized",
                "grade": "V",
                "disclosure": null,
                "source_url": "https://www.sec.gov/Archives/edgar/data/1831631/000183163125000023/ldi-20241231.htm",
                "source_label": "SEC 10-K"
              }
            ],
            "cumulative": null
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": 380,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$24.6M",
              "amount_usd": "24600000",
              "grade": "V",
              "source": "SEC 10-K",
              "url": "https://www.sec.gov/Archives/edgar/data/1831631/000183163125000023/ldi-20241231.htm",
              "disclosed": "2025-03-13",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "MICROSOFT CORP",
          "breached_entity": null,
          "date": "Jan 2024",
          "disclosed": "2024-03-08",
          "group": "00ac3160-ac3d-4388-9541-91c6e4d66553",
          "slug": null,
          "is_primary": true,
          "detail": "The intrusion ran through a legacy test tenant Microsoft had left standing with no multifactor authentication and a guessable password, which a password spray walked straight into. From there the attackers reached an old test OAuth app that still carried full access to corporate mailboxes, and read the email of senior leadership, cybersecurity, and legal. The perimeter that failed was not a network but a forgotten account the security giant never turned off; Microsoft named the actor as Midnight Blizzard, a Russian state group.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/789019/000119312524062997/d808756d8ka.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Technology and Software",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "RADIANT LOGISTICS, INC",
          "breached_entity": null,
          "date": "Mar 2024",
          "disclosed": "2024-03-20",
          "group": "24c386c7-2476-49a8-a887-99ce4ab04a2d",
          "slug": null,
          "is_primary": true,
          "detail": "Radiant Logistics contained the intrusion by cutting its Canadian operations loose from the rest of the network, a tidy way of admitting the boundary did not exist until the fire forced someone to draw it. Segmentation improvised mid-attack is not architecture; it is triage. What got in, whether data left, and how many people sat behind that suddenly necessary wall all went unsaid, and the only name attached to the breach surfaced later on Akira's leak site, not in Radiant's own telling.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1171155/000095017024033954/rlgt-20240319.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Transportation and Logistics",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "SouthState Corp",
          "breached_entity": null,
          "date": "Feb 2024",
          "disclosed": "2024-03-29",
          "group": "9fdd4fd4-9e85-4f9d-8d81-a07a318f0ba7",
          "slug": null,
          "is_primary": true,
          "detail": "An intrusion reached SouthState's network on February 7, 2024, and the unauthorized party walked into folders holding more than 840,000 people's Social Security numbers and account details, which the class action alleges sat unencrypted. The exposure was not the break-in; it was a bank storing its most sensitive records in a shared drive and trusting the outer edge to hold. SouthState never named the actor or the vector, leaving the count as the only firm fact in the file.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/764038/000155837024004390/ssb-20240206x8ka.htm",
          "enforcement": null,
          "amount": "$8.3M",
          "grade": "V",
          "money": {
            "case": "single",
            "amount": "$8.3M",
            "amount_usd": 8300000,
            "category": "direct_expense",
            "grade": "V",
            "state": null,
            "source_url": "https://www.sec.gov/Archives/edgar/data/764038/000155837025001274/ssb-20241231x10k.htm",
            "source_label": "SEC 10-K",
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": 35,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$4.4M",
              "amount_usd": "4400000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/764038/000155837024006602/ssb-20240331x10q.htm",
              "disclosed": "2024-05-03",
              "pre_tracking": false
            },
            {
              "amount": "$7.9M",
              "amount_usd": "7900000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/764038/000155837024010655/ssb-20240630x10q.htm",
              "disclosed": "2024-08-02",
              "pre_tracking": false
            },
            {
              "amount": "$8M",
              "amount_usd": "8000000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/764038/000155837024014094/ssb-20240930x10q.htm",
              "disclosed": "2024-11-01",
              "pre_tracking": false
            },
            {
              "amount": "$8.3M",
              "amount_usd": "8300000",
              "grade": "V",
              "source": "SEC 10-K",
              "url": "https://www.sec.gov/Archives/edgar/data/764038/000155837025001274/ssb-20241231x10k.htm",
              "disclosed": "2025-02-21",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "MARINEMAX INC",
          "breached_entity": null,
          "date": "Mar 2024",
          "disclosed": "2024-04-01",
          "group": "6c0b6ddd-28f1-47b6-aa33-eae1ba65ab27",
          "slug": null,
          "is_primary": true,
          "detail": "An intruder moved through MarineMax's systems for ten days before the boat retailer noticed, leaving with the personal data of roughly 123,000 customers and employees, driver's licenses and passports included. The company first assured regulators that nothing sensitive lived on the breached systems, then reversed itself two weeks later: it could not map what its own network held. Rhysida claimed the theft and posted a 225 gigabyte archive, and a firm that cannot inventory its data is in no position to dispute the count.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1057060/000095017024038881/hzo-20240310.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "B. Riley Financial, Inc.  (RILY, RILYG, RILYK, RILYL, RILYM, RILYN, RILYP, RILYT, RILYZ)",
          "breached_entity": null,
          "date": "Apr 2024",
          "disclosed": "2024-04-08",
          "group": "8afaf164-9d31-47da-b7c9-7f7ab532434a",
          "slug": null,
          "is_primary": true,
          "detail": "Targus shut its own network down to stop the intrusion, a reflex that reveals where the sensitive data sat: not in a hardened vault but in ordinary file servers, where a single foothold reaches everything, Social Security numbers included. How the threat actor got in was never stated, and the count of people affected never arrived at all. Red Ransomware claimed the theft, and Targus took roughly six months to say what had actually left.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1464790/000121390024031252/ea0203500-8k_briley.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "ORASURE TECHNOLOGIES INC",
          "breached_entity": null,
          "date": "Apr 2024",
          "disclosed": "2024-04-12",
          "group": "477e6faa-f75b-48c7-9146-2581b56825a0",
          "slug": null,
          "is_primary": true,
          "detail": "OraSure Technologies builds the tests that carry the most sensitive data a person has, HIV results and genetic samples through its DNA Genotek arm, and the intrusion it contained in late March 2024 was described only as files taken from certain systems. The company vouched for its core financial and operational machinery while the real question, whose health data left and how much, went unanswered. No count, no vector, no named data: a breach a company cannot describe is not contained, it is only quiet.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1116463/000119312524094797/d825009d8k.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Frontier Communications Parent, Inc.",
          "breached_entity": null,
          "date": "Apr 2024",
          "disclosed": "2024-04-18",
          "group": "9055aaf9-ef11-4972-ba57-41f2f1bb31ad",
          "slug": null,
          "is_primary": true,
          "detail": "Frontier pulled portions of its IT environment offline the day it detected the intruder, which is what containment looks like when one open door reaches the rest of the house. RansomHub, which claimed the theft, put it at more than two million people; Frontier's own notice came to roughly 751,000: names, Social Security numbers, dates of birth. How the access was gained was never stated. The count an extortion crew posts and the count a company files are rarely the same, and only one of them carries a penalty for being wrong.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/20520/000119312524100764/d784189d8k.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Telecommunications",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "UNITEDHEALTH GROUP INC",
          "breached_entity": null,
          "date": "Feb 2024",
          "disclosed": "2024-04-24",
          "group": "7bfb6368-d0b9-4850-abdc-2c5e9c4b7059",
          "slug": null,
          "is_primary": true,
          "detail": "The intrusion reached Change Healthcare through a Citrix portal with no second factor, one stolen credential opening a clearinghouse that routes roughly a third of American medical claims. Nine quiet days later the records of about 192.7 million people were gone, the largest healthcare breach on record, because a country wired its billing through a single chokepoint and guarded it with a password. UnitedHealth paid $22 million to bury the files, then watched a second crew arrive to extort the same data again.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/731766/000073176624000150/unh-20240221.htm",
          "enforcement": null,
          "amount": "$2.2B",
          "grade": "V",
          "money": {
            "case": "total",
            "amount": "$3.09B",
            "amount_usd": 3090000000,
            "category": "total_incident_cost",
            "grade": "V",
            "state": "realized",
            "source_url": "https://www.sec.gov/Archives/edgar/data/731766/000073176625000022/a2024q4exhibit991.htm",
            "source_label": "SEC 8-K Ex. 99.1, \"UnitedHealth Group Reports 2024 Results\" (Jan 16, 2025)",
            "caveat": "Company-stated total, of which: direct response costs $2.2B, business disruption $867M.",
            "figures": [
              {
                "amount": "$2.2B",
                "amount_usd": 2200000000,
                "category": "direct_expense",
                "state": "realized",
                "grade": "V",
                "disclosure": null,
                "source_url": "https://www.sec.gov/Archives/edgar/data/731766/000073176625000063/unh-20241231.htm",
                "source_label": "SEC 10-K"
              },
              {
                "amount": "$867M",
                "amount_usd": 867000000,
                "category": "business_interruption",
                "state": "realized",
                "grade": "V",
                "disclosure": null,
                "source_url": "https://www.sec.gov/Archives/edgar/data/731766/000073176625000022/a2024q4exhibit991.htm",
                "source_label": "SEC 8-K Ex. 99.1, \"UnitedHealth Group Reports 2024 Results\" (Jan 16, 2025)"
              }
            ],
            "cumulative": {
              "amount_usd": 3889000000,
              "amount_display": "$3.89B",
              "company_stated": false,
              "periods": [
                {
                  "kind": "total",
                  "label": "FY2024",
                  "amount_display": "$3.09B",
                  "amount_usd": 3090000000
                },
                {
                  "kind": "increment",
                  "label": "FY2025",
                  "amount_display": "$799M",
                  "amount_usd": 799000000
                }
              ]
            }
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": 15,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$340M",
              "amount_usd": "340000000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/731766/000073176624000155/unh-20240331.htm",
              "disclosed": "2024-05-09",
              "pre_tracking": false
            },
            {
              "amount": "$776M",
              "amount_usd": "776000000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/731766/000073176624000262/unh-20240630.htm",
              "disclosed": "2024-08-09",
              "pre_tracking": false
            },
            {
              "amount": "$1.4B",
              "amount_usd": "1400000000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/731766/000073176624000262/unh-20240630.htm",
              "disclosed": "2024-08-09",
              "pre_tracking": false
            },
            {
              "amount": "$290M",
              "amount_usd": "290000000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/731766/000073176624000262/unh-20240630.htm",
              "disclosed": "2024-08-09",
              "pre_tracking": false
            },
            {
              "amount": "$630M",
              "amount_usd": "630000000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/731766/000073176624000262/unh-20240630.htm",
              "disclosed": "2024-08-09",
              "pre_tracking": false
            },
            {
              "amount": "$341M",
              "amount_usd": "341000000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/731766/000073176624000323/unh-20240930.htm",
              "disclosed": "2024-11-04",
              "pre_tracking": false
            },
            {
              "amount": "$1.7B",
              "amount_usd": "1700000000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/731766/000073176624000323/unh-20240930.htm",
              "disclosed": "2024-11-04",
              "pre_tracking": false
            },
            {
              "amount": "$2.2B",
              "amount_usd": "2200000000",
              "grade": "V",
              "source": "SEC 10-K",
              "url": "https://www.sec.gov/Archives/edgar/data/731766/000073176625000063/unh-20241231.htm",
              "disclosed": "2025-02-27",
              "pre_tracking": false
            },
            {
              "amount": "$640M",
              "amount_usd": "640000000",
              "grade": "V",
              "source": "SEC 10-K",
              "url": "https://www.sec.gov/Archives/edgar/data/731766/000073176625000063/unh-20241231.htm",
              "disclosed": "2025-02-27",
              "pre_tracking": false
            },
            {
              "amount": "$799M",
              "amount_usd": "799000000",
              "grade": "V",
              "source": "SEC 10-K",
              "url": "https://www.sec.gov/Archives/edgar/data/731766/000073176626000062/unh-20251231.htm",
              "disclosed": "2026-03-02",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "DROPBOX, INC.",
          "breached_entity": null,
          "date": "Apr 2024",
          "disclosed": "2024-05-01",
          "group": "fd9fba38-fe73-43bf-a5f5-770cb2c50d22",
          "slug": null,
          "is_primary": true,
          "detail": "Dropbox Sign's production environment was reached through a compromised service account, a non-human identity carrying broad standing privileges that nobody was watching, and from there the intruder reached the customer database. Every user's email and username left, and for a subset so did the API keys, OAuth tokens, and MFA material: at a signature company, the very proofs of identity walked out as loot. The actor was never named.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1467623/000146762324000024/dbx-20240429.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Technology and Software",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "BRANDYWINE REALTY TRUST",
          "breached_entity": null,
          "date": "May 2024",
          "disclosed": "2024-05-07",
          "group": "b25251a2-4362-419d-8c54-2e86ed9d7140",
          "slug": null,
          "is_primary": true,
          "detail": "A third party encrypted part of Brandywine Realty Trust's corporate IT estate on May 1, 2024, the same one that ran financial reporting and held personal files, with nothing between the back office and the data. The encryption was the noise; the theft was the quiet part, files walked out before the locks went on. No group claimed it and no victim count surfaced, an unusual silence for a landlord that could not say who had been in the building.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/790816/000119312524133132/d824906d8k.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Real Estate and Construction",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "DocGo Inc.",
          "breached_entity": null,
          "date": "May 2024",
          "disclosed": "2024-05-07",
          "group": "92aca853-145c-4af4-a728-f084fe4ebe61",
          "slug": null,
          "is_primary": true,
          "detail": "A threat actor spent four days inside DocGo's U.S. ambulance operation, long enough to copy names, Social Security numbers, insurance claims, and treatment records. The company called it a limited number of healthcare records; the notification list came to roughly 858,000 people. How the intruder got in was never named, which is its own architecture: a mobile-medical roll-up bolts ambulance services together faster than it maps where the trust boundaries sit.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1822359/000182235924000037/dcgo-20240507.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "KULICKE & SOFFA INDUSTRIES INC",
          "breached_entity": null,
          "date": "May 2024",
          "disclosed": "2024-05-28",
          "group": "27ecaaa1-7ebf-4ba4-8353-0cf074b6b4cd",
          "slug": null,
          "is_primary": true,
          "detail": "Kulicke and Soffa caught unauthorized access on May 12, 2024, and first concluded no data had left; the group calling itself LockBit claimed it had been inside for months and walked out with roughly 12 million files, source code, engineering drawings, business partner records, and personal information among them. A network that treats detection as the whole of its defense learns the size of the intrusion only after the intruder publishes it. The alarm marked the end of the visit, not the start.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/56978/000005697824000073/klic-20240528.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Technology and Software",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "KEY TRONIC CORP",
          "breached_entity": null,
          "date": "May 2024",
          "disclosed": "2024-06-14",
          "group": "f61ab967-35fa-44e8-bc8a-483873da32a9",
          "slug": null,
          "is_primary": true,
          "detail": "Key Tronic's plants in Washington and Mexico sat idle for two weeks in May 2024, not because a machine broke but because the office IT they run on was encrypted, one trust boundary shared between the business network and the factory floor. Black Basta claimed the intrusion and leaked roughly 530 gigabytes, employee passports and Social Security cards among it, while the company confirmed personal data had left the building. How the access first began was never named. The bill ran to about $17 million, most of it revenue that simply stopped when a breach reached the plant floor.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/719733/000071973324000035/ktcc-20240506.htm",
          "enforcement": null,
          "amount": "$2.3M",
          "grade": "V",
          "money": {
            "case": "set",
            "amount": null,
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": [
              {
                "amount": "$2.3M",
                "amount_usd": 2300000,
                "category": "direct_expense",
                "state": "realized",
                "grade": "V",
                "disclosure": null,
                "source_url": "https://www.sec.gov/Archives/edgar/data/719733/000071973324000047/ktcc-20240506.htm",
                "source_label": "SEC 8-K/A"
              },
              {
                "amount": "$15M",
                "amount_usd": 15000000,
                "category": "business_interruption",
                "state": "estimated",
                "grade": "V",
                "disclosure": null,
                "source_url": "https://www.sec.gov/Archives/edgar/data/719733/000071973324000047/ktcc-20240506.htm",
                "source_label": "SEC 8-K/A"
              }
            ]
          },
          "sector": "Manufacturing",
          "needs_grading": false,
          "lag_days": 53,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$2.3M",
              "amount_usd": "2300000",
              "grade": "V",
              "source": "SEC 8-K/A",
              "url": "https://www.sec.gov/Archives/edgar/data/719733/000071973324000047/ktcc-20240506.htm",
              "disclosed": "2024-08-06",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "PENSKE AUTOMOTIVE GROUP, INC.",
          "breached_entity": null,
          "date": "Jun 2024",
          "disclosed": "2024-06-21",
          "group": "4eab6c01-8514-40ce-bdbf-451ae5d876c2",
          "slug": null,
          "is_primary": true,
          "detail": "Penske's own network held; what went dark was CDK Global, the dealer management software running its Premier Truck Group back office, hit by ransomware that reporting ties to the BlackSuit group. When one vendor is the operating system for roughly 15,000 dealerships, its outage is your outage, and Premier Truck spent the shutdown selling heavy trucks on paper. Concentration is not a convenience here: it is a single point of failure with a logo.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1019849/000101984924000089/pag-20240619.htm",
          "enforcement": null,
          "amount": "$2.5M",
          "grade": "V",
          "money": {
            "case": "total",
            "amount": "$2.5M",
            "amount_usd": 2500000,
            "category": "total_incident_cost",
            "grade": "V",
            "state": "realized",
            "source_url": "https://www.sec.gov/Archives/edgar/data/1019849/000162828025047533/pag-20250930.htm",
            "source_label": "SEC 10-Q",
            "caveat": "The company's own complete incident total.",
            "figures": [],
            "cumulative": null
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": 496,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$2.5M",
              "amount_usd": "2500000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/1019849/000162828025047533/pag-20250930.htm",
              "disclosed": "2025-10-30",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "SONIC AUTOMOTIVE INC",
          "breached_entity": null,
          "date": "Jun 2024",
          "disclosed": "2024-06-21",
          "group": "c7779673-fe4b-4c9f-994a-cbbb1a0088b3",
          "slug": null,
          "is_primary": true,
          "detail": "Sonic Automotive could not sell cars for the better part of two weeks, not because its own network fell but because CDK Global, the single vendor running its dealer management system, was ransomwared by a crew reporting ties to BlackSuit. When one SaaS provider is the floor beneath every franchise's sales, inventory, and accounting, its outage is the dealership's outage. Sonic booked a material hit to the quarter over software it did not run and could not bring back.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1043509/000104350924000059/sah-20240619.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "LITHIA MOTORS INC",
          "breached_entity": null,
          "date": "Jun 2024",
          "disclosed": "2024-06-24",
          "group": "12636a1d-ec67-4438-9054-ef7132746474",
          "slug": null,
          "is_primary": true,
          "detail": "Lithia Motors was not breached; the dealer management system it and thousands of other dealerships run sales, financing, and customer records through was. That platform belongs to CDK Global, one vendor that had quietly become the operational nervous system of American car retail, so a single ransomware intrusion, reported to be BlackSuit's, sent roughly 15,000 dealer locations back to pen and paper at once. Outsourcing the entire front office to one platform is efficient right up to the morning it stops answering.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1023128/000102312824000079/lad-20240619.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "GROUP 1 AUTOMOTIVE INC",
          "breached_entity": null,
          "date": "Jun 2024",
          "disclosed": "2024-06-24",
          "group": "44903399-bbc3-4d08-8335-2d042b01daa0",
          "slug": null,
          "is_primary": true,
          "detail": "Group 1's U.S. dealerships ran sales, service, and back office through CDK, so when a ransomware crew took the vendor dark, thousands of storefronts went dark with it. The failure was not a breach of Group 1's network but a single point of dependence: the dealer management platform was the business, and someone else owned it. No records are believed to have left, only the uptime; the company booked $10 million in insurance for a spine it had outsourced.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1031203/000103120324000048/gpi-20240619.htm",
          "enforcement": null,
          "amount": "$5.9M",
          "grade": "V",
          "money": {
            "case": "single",
            "amount": "$5.9M",
            "amount_usd": 5900000,
            "category": "direct_expense",
            "grade": "V",
            "state": "realized",
            "source_url": "https://www.sec.gov/Archives/edgar/data/1031203/000103120325000013/gpi-20241231.htm",
            "source_label": "SEC 10-K",
            "caveat": null,
            "figures": []
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": 235,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$5.9M",
              "amount_usd": "5900000",
              "grade": "V",
              "source": "SEC 10-K",
              "url": "https://www.sec.gov/Archives/edgar/data/1031203/000103120325000013/gpi-20241231.htm",
              "disclosed": "2025-02-14",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "Affirm Holdings, Inc.",
          "breached_entity": null,
          "date": "Jun 2024",
          "disclosed": "2024-07-01",
          "group": "cec48acb-07fa-4d62-9c73-fe05260ee512",
          "slug": null,
          "is_primary": true,
          "detail": "Affirm's systems were never touched; the breach was at Evolve Bank & Trust, the sponsor bank that issues the Affirm Card and holds the customer data a fintech front end never keeps. One malicious link inside Evolve exposed names, Social Security numbers, and account details across its fintech partners, and reporting credits LockBit, which leaked the file when the ransom went unpaid. When the ledger lives at the sponsor bank, a fintech's own security is beside the point: the bank is the single door everyone's data waits behind.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1820953/000182095324000027/afrm-20240625.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "HEALTHEQUITY, INC.",
          "breached_entity": null,
          "date": "Jul 2024",
          "disclosed": "2024-07-02",
          "group": "bd15f5e0-cdbd-4593-ae94-eea5e8f6c27b",
          "slug": null,
          "is_primary": true,
          "detail": "A business partner's personal-use device carried the malware, and the account it compromised reached straight into a SharePoint repository holding data on about 4.3 million people: Social Security numbers, diagnoses, prescriptions. The vendor's laptop sat inside the trust boundary, and the member records sat in a shared drive rather than a guarded system. That access ran from March to late June before anyone noticed, which is less a break-in than a tenancy.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1428336/000142833624000055/hqy-20240702.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Professional and Business Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "SONIC AUTOMOTIVE INC",
          "breached_entity": null,
          "date": "Jul 2024",
          "disclosed": "2024-07-05",
          "group": "c7779673-fe4b-4c9f-994a-cbbb1a0088b3",
          "slug": null,
          "is_primary": false,
          "detail": "Sonic Automotive could not sell cars for the better part of two weeks, not because its own network fell but because CDK Global, the single vendor running its dealer management system, was ransomwared by a crew reporting ties to BlackSuit. When one SaaS provider is the floor beneath every franchise's sales, inventory, and accounting, its outage is the dealership's outage. Sonic booked a material hit to the quarter over software it did not run and could not bring back.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1043509/000104350924000060/sah-20240705.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Crimson Wine Group, Ltd",
          "breached_entity": null,
          "date": "Jun 2024",
          "disclosed": "2024-07-05",
          "group": "11a324b2-5995-446a-948c-d4c3d12c625d",
          "slug": null,
          "is_primary": true,
          "detail": "Crimson Wine Group pulled its own systems off the internet to stop the intrusion, which tells you the network was flat enough that containment and full shutdown were the same act. What a winery was doing holding Social Security numbers, driver's licenses, and medical records on 26,238 people goes unexplained, as does how the third party got in: no vector, no actor, no group was ever named. The data a business keeps is the data it eventually loses.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1562151/000156215124000030/cwgl-20240630.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Manufacturing",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "AUTONATION, INC.",
          "breached_entity": null,
          "date": "Jul 2024",
          "disclosed": "2024-07-15",
          "group": "7657b55d-2034-45d5-a0eb-5d43c487b6d4",
          "slug": null,
          "is_primary": true,
          "detail": "AutoNation lost no data of its own; it lost CDK Global, the dealer-management system 15,000 dealerships treat as the floor they stand on, taken down through a single phishing email by ransomware that reporting ties to BlackSuit. An always-on VPN had already seated the vendor inside every dealer's network, so one compromise closed an industry from a data center no dealer owned. The $1.50-a-share hit is what vendor concentration charges when the front door belongs to someone else.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/350698/000035069824000085/an-20240715.htm",
          "enforcement": null,
          "amount": "$10M",
          "grade": "V",
          "money": {
            "case": "single",
            "amount": "$43M",
            "amount_usd": 43000000,
            "category": "direct_expense",
            "grade": "V",
            "state": "realized",
            "source_url": "https://www.sec.gov/Archives/edgar/data/350698/000035069824000098/an-20240630.htm",
            "source_label": "SEC 10-Q",
            "caveat": null,
            "figures": []
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": 17,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$43M",
              "amount_usd": "43000000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/350698/000035069824000098/an-20240630.htm",
              "disclosed": "2024-08-01",
              "pre_tracking": false
            },
            {
              "amount": "$10M",
              "amount_usd": "10000000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/350698/000035069824000111/an-20240930.htm",
              "disclosed": "2024-10-25",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "REPLIGEN CORP",
          "breached_entity": null,
          "date": "Jul 2024",
          "disclosed": "2024-07-15",
          "group": "4f14177e-0e78-40c1-92b6-b37a8d7b31e3",
          "slug": null,
          "is_primary": true,
          "detail": "An unauthorized party reached certain files on Repligen's systems in July 2024, and the company's account stopped there: no count, no vector, no name. The scope surfaced elsewhere, on INC Ransom's leak site, where the group claimed roughly 500 gigabytes. When the most specific figure for a breach lives on the extortion group's directory and not in the filing, the accounting has been outsourced to the party that took the data.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/730272/000119312524179061/d868921d8k.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Cadre Holdings, Inc.",
          "breached_entity": null,
          "date": "Jul 2024",
          "disclosed": "2024-07-19",
          "group": "e88173ca-d7f0-4646-ae21-9d782c46b6e1",
          "slug": null,
          "is_primary": true,
          "detail": "Cadre Holdings arms police and bomb squads for a living, and its answer to an unauthorized third party inside certain technology systems in July 2024 was to take machines offline and wait. What data left, who took it, and how they got in all went unnamed, by the company and by any group that might have claimed it. A firm built to sell survivability could describe the threat to everyone but itself.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1860543/000110465924081176/tm2419841d1_8k.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "set",
            "amount": null,
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": [
              {
                "amount": "$6.4M",
                "amount_usd": 6400000,
                "category": "business_interruption",
                "state": "estimated",
                "grade": "V",
                "disclosure": null,
                "source_url": "https://www.sec.gov/Archives/edgar/data/1860543/000155837024014638/cdre-20240930x10q.htm",
                "source_label": "SEC 10-Q"
              },
              {
                "amount": "$22.3M",
                "amount_usd": 22300000,
                "category": "business_interruption",
                "state": "estimated",
                "grade": "V",
                "disclosure": null,
                "source_url": "https://www.sec.gov/Archives/edgar/data/1860543/000155837024014638/cdre-20240930x10q.htm",
                "source_label": "SEC 10-Q"
              }
            ]
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Crimson Wine Group, Ltd",
          "breached_entity": null,
          "date": "Jul 2024",
          "disclosed": "2024-07-25",
          "group": "11a324b2-5995-446a-948c-d4c3d12c625d",
          "slug": null,
          "is_primary": false,
          "detail": "Crimson Wine Group pulled its own systems off the internet to stop the intrusion, which tells you the network was flat enough that containment and full shutdown were the same act. What a winery was doing holding Social Security numbers, driver's licenses, and medical records on 26,238 people goes unexplained, as does how the third party got in: no vector, no actor, no group was ever named. The data a business keeps is the data it eventually loses.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1562151/000156215124000032/cwgl-20240725.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Manufacturing",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Cencora, Inc.",
          "breached_entity": null,
          "date": "Feb 2024",
          "disclosed": "2024-07-31",
          "group": "2d56c9fc-ef64-4eec-91c1-28bb3abdd709",
          "slug": null,
          "is_primary": true,
          "detail": "Cencora distributes drugs, but through its Lash Group patient-support arm it had become the record-keeper for more than a dozen rival drugmakers, so one February intrusion emptied the patient files of Bayer, Novartis, and Bristol Myers Squibb at once. Names, diagnoses, and medications for at least 1.43 million people left through a single back-office unit no one filed as a front door. Reporting ties the theft to Dark Angels and puts the ransom near $75 million, the largest known, which only buys a promise the copy was deleted.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1140859/000110465924084351/tm2420501d1_8ka.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Wholesale and Distribution",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "META MATERIALS INC.",
          "breached_entity": null,
          "date": "Jul 2024",
          "disclosed": "2024-08-01",
          "group": "54c868b6-3dcd-4315-a92c-7f3a03a2739a",
          "slug": null,
          "is_primary": true,
          "detail": "Meta Materials lost its website and email for four days in July 2024, not to an outside intruder but to a former executive who still held the keys and cancelled the renewal on his way out. The company had wired its public presence and stakeholder mail to a single registration one departed insider could revoke, because offboarding never took the credential back. No data theft was claimed, and the executive went unnamed: the failure was an access list that never noticed he had left.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1431959/000095017024089345/mmat-20240725.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Manufacturing",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "BASSETT FURNITURE INDUSTRIES INC",
          "breached_entity": null,
          "date": "Jul 2024",
          "disclosed": "2024-08-06",
          "group": "567e3b46-dca8-4374-9157-d72e508b483f",
          "slug": null,
          "is_primary": true,
          "detail": "Bassett Furniture ran its factories on the same IT estate as its back office, so when a ransomware crew encrypted a portion of its files, containment meant idling every manufacturing floor for four and a half days. No group claimed the attack, and the company named neither the vector nor the actor, leaving the entry point a blank. The plants did not fall to a genius adversary; the only firebreak between the corporate network and the production line was the power switch.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/10329/000143774924024679/bset20240805_8ka.htm",
          "enforcement": null,
          "amount": "$609K",
          "grade": "V",
          "money": {
            "case": "set",
            "amount": null,
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": [
              {
                "amount": "$609K",
                "amount_usd": 609000,
                "category": "direct_expense",
                "state": "realized",
                "grade": "V",
                "disclosure": null,
                "source_url": "https://www.sec.gov/Archives/edgar/data/10329/000143774925030703/bset20250830_10q.htm",
                "source_label": "SEC 10-Q"
              },
              {
                "amount": "$1M to $2M",
                "amount_usd": null,
                "category": "business_interruption",
                "state": "estimated",
                "grade": "V",
                "disclosure": null,
                "source_url": "https://www.sec.gov/Archives/edgar/data/10329/000143774924031014/bset20240831d_10q.htm",
                "source_label": "SEC 10-Q"
              }
            ]
          },
          "sector": "Manufacturing",
          "needs_grading": false,
          "lag_days": 65,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$98K",
              "amount_usd": "98000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/10329/000143774924031014/bset20240831d_10q.htm",
              "disclosed": "2024-10-10",
              "pre_tracking": false
            },
            {
              "amount": "$609K",
              "amount_usd": "609000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/10329/000143774925030703/bset20250830_10q.htm",
              "disclosed": "2025-10-08",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "ADT Inc.",
          "breached_entity": null,
          "date": "Aug 2024",
          "disclosed": "2024-08-08",
          "group": "de6dddd3-cd5e-406c-a751-bda7e850582b",
          "slug": null,
          "is_primary": true,
          "detail": "A company that sells perimeters for a living left its own customer order database reachable, and unauthorized actors walked out with the names, addresses, phone numbers, and purchase histories of roughly 30,000 people. How the door was opened, ADT never said; a forum poster called netnsher claimed the haul at 30,812 records before the filing caught up. The alarm company that watches everyone else's doors heard nothing until its customers were already listed for sale.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1703056/000095015724001064/form8k.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Professional and Business Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "ENZO BIOCHEM INC",
          "breached_entity": null,
          "date": "Aug 2024",
          "disclosed": "2024-08-14",
          "group": "e09acbcd-1500-46ae-a69c-97511947e357",
          "slug": null,
          "is_primary": true,
          "detail": "Enzo Biochem lost the clinical records of roughly 2.47 million people through two employee logins, one left unchanged for a decade and shared among five staff, with no second factor standing between an email password and the lab's patient data. What walked out was names, test results, and about 600,000 Social Security numbers. A credential shared by five people and rotated once a decade is not authentication; it is a group password taped to the door.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/316253/000121390024069031/ea0211342-8k_enzobio.htm",
          "enforcement": null,
          "amount": "$3M",
          "grade": "V",
          "money": {
            "case": "set",
            "amount": null,
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": [
              {
                "amount": "$7.5M",
                "amount_usd": 7500000,
                "category": "regulatory_legal_cost",
                "state": "realized",
                "grade": "A",
                "disclosure": null,
                "source_url": "https://news.bloomberglaw.com/litigation/enzo-biochem-to-pay-7-5-million-to-settle-suit-over-2023-breach",
                "source_label": "Media Report"
              },
              {
                "amount": "$4.5M",
                "amount_usd": 4500000,
                "category": "regulatory_legal_cost",
                "state": "realized",
                "grade": "V",
                "disclosure": null,
                "source_url": "https://www.njoag.gov/attorney-general-platkin-and-multistate-coalition-secure-4-5-million-from-enzo-biochem-for-failing-to-protect-health-data/",
                "source_label": "State AG"
              }
            ]
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": 76,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$5.2M",
              "amount_usd": "5200000",
              "grade": "V",
              "source": "SEC 10-K",
              "url": "https://www.sec.gov/Archives/edgar/data/316253/000121390024091798/ea0218602-10k_enzobio.htm",
              "disclosed": "2024-10-29",
              "pre_tracking": false
            },
            {
              "amount": "$3M",
              "amount_usd": "3000000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/316253/000121390024109311/ea0224507-10q_enzobio.htm",
              "disclosed": "2024-12-16",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "MICROCHIP TECHNOLOGY INC",
          "breached_entity": null,
          "date": "Aug 2024",
          "disclosed": "2024-08-20",
          "group": "772bce72-8081-4716-8fcc-9d5704a888c9",
          "slug": "microchip-technology-inc-2024-08-20",
          "is_primary": true,
          "detail": "Microchip Technology's fabs slowed below normal output after intruders disrupted the servers running its business, proof that a semiconductor plant is only as isolated as its weakest office network. The confirmed theft was modest, employee contact details and some hashed passwords, though the Play ransomware group, which claimed it, says it left with payroll, contracts, and IDs. How the access was gained went unnamed: when an IT breach can idle a factory floor, the boundary between the two was drawn as a wish.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/827054/000082705424000153/mchp-20240820.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Technology and Software",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "HALLIBURTON CO",
          "breached_entity": null,
          "date": "Aug 2024",
          "disclosed": "2024-09-03",
          "group": "2b8d4056-01dc-4cbe-bdcf-992599d565ed",
          "slug": null,
          "is_primary": true,
          "detail": "Halliburton pulled its own applications offline as a precaution, and in doing so showed how thin the wall was between corporate IT and oilfield operations: with production planning and shipment tracking down, customers could not cut a purchase order. Data left the building, though no count of the people behind the records ever followed. Reporting ties the intrusion to RansomHub, and the $35 million booked was the price of a boundary that lived mostly on paper.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/45012/000004501224000052/hal-20240830.htm",
          "enforcement": null,
          "amount": "$35M",
          "grade": "V",
          "money": {
            "case": "single",
            "amount": "$35M",
            "amount_usd": 35000000,
            "category": "direct_expense",
            "grade": "V",
            "state": "estimated",
            "source_url": "https://www.sec.gov/Archives/edgar/data/45012/000004501224000063/hal-20240930.htm",
            "source_label": "SEC 10-Q",
            "caveat": null,
            "figures": []
          },
          "sector": "Energy and Utilities",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$35M",
              "amount_usd": "35000000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/45012/000004501224000063/hal-20240930.htm",
              "disclosed": "2024-11-07",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "MICROCHIP TECHNOLOGY INC",
          "breached_entity": null,
          "date": "Sep 2024",
          "disclosed": "2024-09-04",
          "group": "772bce72-8081-4716-8fcc-9d5704a888c9",
          "slug": "microchip-technology-inc-2024-08-20",
          "is_primary": false,
          "detail": "The Company is aware that an unauthorized party claims to have acquired and posted online certain data from the Company’s systems. The Company is investigating the validity of this claim with assistance from its outside cybersecurity and forensic experts.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/827054/000082705424000181/mchp-20240904.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Technology and Software",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "ADT Inc.",
          "breached_entity": null,
          "date": "Oct 2024",
          "disclosed": "2024-10-07",
          "group": "477545de-6cb1-4d67-8504-83e8714deab0",
          "slug": null,
          "is_primary": true,
          "detail": "ADT's network was reached not through ADT but through a third-party business partner, whose compromised credentials let an unauthorized actor walk in and leave with encrypted internal data on employee accounts. Customer alarm codes were spared this time, though it was ADT's second intrusion in two months. When the trust boundary is drawn to include every partner holding a valid login, the perimeter is only as sound as the weakest vendor's password. ADT named no attacker, and the silence is doing work.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1703056/000119312524233900/d876174d8k.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Professional and Business Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "American Water Works Company, Inc.",
          "breached_entity": null,
          "date": "Oct 2024",
          "disclosed": "2024-10-07",
          "group": "c8c2ebb7-e5cd-4254-9b24-01c55cd7be3e",
          "slug": null,
          "is_primary": true,
          "detail": "American Water pulled its MyWater portal and paused billing to wall off unauthorized activity inside its corporate networks, then reassured 14 million customers that the water itself was never touched. That reassurance is the tell: the intrusion lived in the customer-facing IT stack, while the operational technology that treats the water sat behind a trust boundary that actually held. Months on, the largest water utility in the country had named neither the actor nor the vector, certain of what stayed safe and silent on what got in.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1410636/000119312524233300/d869346d8k.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Energy and Utilities",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "HEALTHCARE SERVICES GROUP INC",
          "breached_entity": null,
          "date": "Oct 2024",
          "disclosed": "2024-10-16",
          "group": "5eeea839-bae8-4b92-9cb1-04afcfc6aaec",
          "slug": null,
          "is_primary": true,
          "detail": "Healthcare Services Group handles the dining, laundry, and housekeeping for healthcare facilities, yet it held the Social Security numbers, financial accounts, and insurance records of 624,496 patients and employees across 48 states. Intruders moved through its systems for a week before anyone noticed on October 7, and the company still has not said how they got in. The ransomware group Underground claims 1.1 terabytes, a figure HCSG has not confirmed. When a janitorial contractor becomes a warehouse of medical identity, the breach was in the org chart long before it was in the network.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/731012/000073101224000134/hcsg-20241009.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "GLOBE LIFE INC.  (GL, GL-PD)",
          "breached_entity": null,
          "date": "Oct 2024",
          "disclosed": "2024-10-17",
          "group": "e6ab5507-14f1-46fb-9012-f31007dd393d",
          "slug": null,
          "is_primary": false,
          "detail": "Globe Life's agent web portal ran on access permissions and identity checks that could not tell a real user from an impostor, and that portal was the door out. Because the records sat in databases held by its independent agency owners rather than one hardened store, a single portal flaw reached roughly 850,000 people: names, Social Security numbers, health details. The company named the extortion note that followed, never the attacker behind it. When identity is the only lock, a broken check is the whole breach.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/320335/000032033524000056/gl-20241017.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Karat Packaging Inc.",
          "breached_entity": null,
          "date": "Oct 2024",
          "disclosed": "2024-10-23",
          "group": "0a173259-9522-4c46-820a-1e97f26ec1c6",
          "slug": null,
          "is_primary": true,
          "detail": "Karat Packaging activated its cybersecurity response plan on October 18, 2024, after unauthorized third-party access reached its information systems, and that is very nearly the whole of the public account. No vector, no named actor, no count of the people behind the records: the filing offers a plan and a contained threat and leaves the architecture unlit. A breach that can be closed out without ever explaining how the door opened is not a resolved incident; it is a disclosure that discloses nothing.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1758021/000121390024089965/ea0218366-8k_karat.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Manufacturing",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "NEWPARK RESOURCES INC",
          "breached_entity": null,
          "date": "Oct 2024",
          "disclosed": "2024-11-07",
          "group": "f3dd6921-2e98-434f-afef-5d3a925e68fb",
          "slug": null,
          "is_primary": true,
          "detail": "Newpark Resources kept its plants and rigs running on manual downtime procedures while ransomware took the internal systems that keep the books, a reminder that in an oilfield supplier the office network and the shop floor are two separate failure domains, wired as one. What never surfaced is the rest of it: no group claimed the intrusion, no files reached a leak site, no count of affected records was ever put on the record. The silence is not reassurance; it is the sound of no one having finished counting.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/71829/000007182924000111/nr-20241029.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Professional and Business Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "iLearningEngines, Inc.  (AILE, AILEW)",
          "breached_entity": null,
          "date": "Nov 2024",
          "disclosed": "2024-11-18",
          "group": "30f38419-5830-4819-a144-3da95a2aa4c5",
          "slug": null,
          "is_primary": true,
          "detail": "iLearningEngines lost $250,000 not to an exploit but to its own inbox: a threat actor moved through the company's email, redirected a wire, and deleted the messages that would have shown the switch. No ransomware crew claimed it and the company named no actor, which is business email compromise working as designed. When the mailbox is the authorization for a payment, the money goes wherever the mailbox says, and this money was never recovered.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1835972/000121390024099394/ea0221424-8k_ilearning.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Technology and Software",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "ARTIVION, INC.",
          "breached_entity": null,
          "date": "Dec 2024",
          "disclosed": "2024-12-09",
          "group": "f6a24a2e-98c8-4c17-ba63-b1827e8beefb",
          "slug": null,
          "is_primary": true,
          "detail": "Artivion, a maker of heart-surgery devices, was breached in a single day: an intruder copied files on November 20 and was gone by the 21st, ahead of the alarm. What left was not device blueprints but the back office, its own employees' Social Security numbers, passports, and direct deposit details, the HR store guarded like an afterthought. No group ever claimed the intrusion and the company never named the way in, so the tally surfaced one state at a time: 5,608 in Texas, thousands more counted elsewhere.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/784199/000078419924000253/aort-20241209.htm",
          "enforcement": null,
          "amount": "$3.5M",
          "grade": "V",
          "money": {
            "case": "total",
            "amount": "$4.6M",
            "amount_usd": 4600000,
            "category": "total_incident_cost",
            "grade": "V",
            "state": "realized",
            "source_url": "https://www.sec.gov/Archives/edgar/data/784199/000162828026009046/aort-20251231.htm",
            "source_label": "SEC 10-K",
            "caveat": "Company-stated total, of which: direct response costs $3.5M.",
            "figures": [
              {
                "amount": "$3.5M",
                "amount_usd": 3500000,
                "category": "direct_expense",
                "state": "realized",
                "grade": "V",
                "disclosure": null,
                "source_url": "https://www.sec.gov/Archives/edgar/data/784199/000162828026009046/aort-20251231.htm",
                "source_label": "SEC 10-K"
              }
            ],
            "cumulative": null
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": 436,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$3.5M",
              "amount_usd": "3500000",
              "grade": "V",
              "source": "SEC 10-K",
              "url": "https://www.sec.gov/Archives/edgar/data/784199/000162828026009046/aort-20251231.htm",
              "disclosed": "2026-02-18",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "Krispy Kreme, Inc.",
          "breached_entity": null,
          "date": "Dec 2024",
          "disclosed": "2024-12-11",
          "group": "795f9b88-bd58-4c9b-9511-1ae3fe5709ea",
          "slug": null,
          "is_primary": true,
          "detail": "The outage that halted online doughnut orders was the visible damage; the real loss was the identity file of roughly 161,000 people, almost all of them staff and their families, holding Social Security numbers, passports, biometrics, and military IDs. Play claimed the intrusion and leaked 184 gigabytes after the ransom went unpaid, though how the systems were first entered was never stated. A doughnut seller kept an HR intelligence dossier on the people who fry them, and that is the file the breach walked out with.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1857154/000185715424000123/dnut-20241211.htm",
          "enforcement": null,
          "amount": "$4.4M",
          "grade": "V",
          "money": {
            "case": "set",
            "amount": null,
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": [
              {
                "amount": "$11M",
                "amount_usd": 11000000,
                "category": "business_interruption",
                "state": "estimated",
                "grade": "V",
                "disclosure": null,
                "source_url": "https://www.sec.gov/Archives/edgar/data/1857154/000185715425000013/dnut-20241229.htm",
                "source_label": "SEC 10-K"
              },
              {
                "amount": "$10M",
                "amount_usd": 10000000,
                "category": "business_interruption",
                "state": "estimated",
                "grade": "V",
                "disclosure": null,
                "source_url": "https://www.sec.gov/Archives/edgar/data/1857154/000185715425000013/dnut-20241229.htm",
                "source_label": "SEC 10-K"
              },
              {
                "amount": "$5M",
                "amount_usd": 5000000,
                "category": "business_interruption",
                "state": "estimated",
                "grade": "V",
                "disclosure": null,
                "source_url": "https://www.sec.gov/Archives/edgar/data/1857154/000185715425000073/dnut-20250330.htm",
                "source_label": "SEC 10-Q"
              },
              {
                "amount": "$7.4M",
                "amount_usd": 7400000,
                "category": "direct_expense",
                "state": "realized",
                "grade": "V",
                "disclosure": null,
                "source_url": "https://www.sec.gov/Archives/edgar/data/1857154/000185715426000015/dnut-20251228.htm",
                "source_label": "SEC 10-K"
              }
            ]
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": 148,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$4.4M",
              "amount_usd": "4400000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/1857154/000185715425000073/dnut-20250330.htm",
              "disclosed": "2025-05-08",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "LKQ CORP",
          "breached_entity": null,
          "date": "Dec 2024",
          "disclosed": "2024-12-13",
          "group": "71b3fda6-582d-433c-b31b-aa6042a4d3c3",
          "slug": null,
          "is_primary": true,
          "detail": "LKQ contained the November intrusion the only way a sprawling parts conglomerate can, by walling off the single Canadian business unit whose IT systems attackers had reached, and operations there stalled for weeks. No group claimed it and no tally of what left was ever offered, which is its own kind of disclosure. Containment by amputation is not resilience; it is an admission the segment was already standing alone.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1065696/000106569624000134/lkq-20241213.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Wholesale and Distribution",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "ENGLOBAL CORP",
          "breached_entity": null,
          "date": "Nov 2024",
          "disclosed": "2025-01-27",
          "group": "f27e26dc-efb4-465e-b595-403173891bf5",
          "slug": null,
          "is_primary": true,
          "detail": "ENGlobal, a small engineering contractor woven into the energy sector and the federal supply chain, spent roughly six weeks locked out of its own financial systems after a threat actor encrypted its files and reached the personal data held in the same IT estate. Neither the entry vector nor the number of people exposed was ever named, and no ransomware group claimed the intrusion. For a firm whose product is trust across critical infrastructure, a flat internal network is not a footnote; it is the whole exposure.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/933738/000165495425000798/eng_8ka.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Professional and Business Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "GLOBE LIFE INC.  (GL, GL-PD)",
          "breached_entity": null,
          "date": "Oct 2024",
          "disclosed": "2025-01-30",
          "group": "e6ab5507-14f1-46fb-9012-f31007dd393d",
          "slug": null,
          "is_primary": false,
          "detail": "Globe Life's agent web portal ran on access permissions and identity checks that could not tell a real user from an impostor, and that portal was the door out. Because the records sat in databases held by its independent agency owners rather than one hardened store, a single portal flaw reached roughly 850,000 people: names, Social Security numbers, health details. The company named the extortion note that followed, never the attacker behind it. When identity is the only lock, a broken check is the whole breach.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/320335/000032033525000004/gl-20241017.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "LEE ENTERPRISES, Inc",
          "breached_entity": null,
          "date": "Feb 2025",
          "disclosed": "2025-02-18",
          "group": "ed5c40a3-12d1-40ce-a796-755ac5c54e33",
          "slug": null,
          "is_primary": true,
          "detail": "Lee Enterprises ran its 72 newspapers on shared core systems, so when ransomware encrypted them on February 3, 2025, distribution, billing, collections, and vendor payments stopped at once. The 350GB that left, by the attackers' count, held Social Security numbers and health details belonging mostly to Lee's own current and former employees, not its readers. Qilin claimed the theft and recovery ran about $2 million: one intrusion, and no internal boundary anywhere to slow it.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/58361/000162828025005855/lee-20250212.htm",
          "enforcement": null,
          "amount": "$10.5M",
          "grade": "V",
          "money": {
            "case": "single",
            "amount": "$10.5M",
            "amount_usd": 10500000,
            "category": "business_interruption",
            "grade": "A",
            "state": "realized",
            "source_url": "https://www.sec.gov/Archives/edgar/data/58361/000005836125000040/lee-20250928.htm",
            "source_label": "SEC 10-K",
            "caveat": null,
            "figures": []
          },
          "sector": "Media and Entertainment",
          "needs_grading": false,
          "lag_days": 444,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$10.5M",
              "amount_usd": "10500000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/58361/000005836126000041/lee-20260329.htm",
              "disclosed": "2026-05-08",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "NIOCORP DEVELOPMENTS LTD  (NB, NIOBW)",
          "breached_entity": null,
          "date": "Feb 2025",
          "disclosed": "2025-02-19",
          "group": "56fbc132-f488-4ccc-938e-1055214f07f0",
          "slug": null,
          "is_primary": true,
          "detail": "NioCorp's intruders needed no exploit, just a foothold in its email, because the mining company's vendor payment process trusted whatever the inbox told it. About $500,000 walked out to a fraudulent account before anyone caught the reroute: an invoice redirected by a plausible message, not a breached network. No group has been named and no personal records were said to leave; the whole loss was the price of letting email stand in for a signed authorization.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1512228/000153949725000735/n2574_x251-8k.htm",
          "enforcement": null,
          "amount": "$10K",
          "grade": "V",
          "money": {
            "case": "single",
            "amount": "$506K",
            "amount_usd": 506000,
            "category": null,
            "grade": "V",
            "state": "estimated",
            "source_url": "https://www.sec.gov/Archives/edgar/data/1512228/000153949725001285/n2574_x261-10q.htm",
            "source_label": "SEC 10-Q",
            "caveat": null,
            "figures": []
          },
          "sector": "Mining and Minerals",
          "needs_grading": false,
          "lag_days": 78,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$10K",
              "amount_usd": "10000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/1512228/000153949725001285/n2574_x261-10q.htm",
              "disclosed": "2025-05-08",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "NATIONAL PRESTO INDUSTRIES INC",
          "breached_entity": null,
          "date": "Mar 2025",
          "disclosed": "2025-03-06",
          "group": "107a71ed-7760-483c-aa56-9fea19ce6092",
          "slug": null,
          "is_primary": true,
          "detail": "National Presto's outage on March 1, 2025, halted manufacturing, shipping, and receiving together, the predictable result when a company making both pressure cookers and munitions runs them across one shared back office. The intrusion reached National Defense Corporation, its ordnance subsidiary, through that common spine; how the door opened was never disclosed. InterLock claimed the hit and roughly 3 million stolen files, then met a company that declined to pay on the theory a defense maker's data was worthless to anyone.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/80172/000143774925006475/npk20250306_8k.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Manufacturing",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Sensata Technologies Holding plc",
          "breached_entity": null,
          "date": "Apr 2025",
          "disclosed": "2025-04-09",
          "group": "a42494c3-508f-4117-8bf2-c54d26ca6de9",
          "slug": null,
          "is_primary": true,
          "detail": "Sensata's business is sensing and measurement, yet an intruder moved through its network for nine days before ransomware announced itself by freezing the shipping and production lines. What left was not customer telemetry but the workforce itself: Social Security numbers, passports, and medical records of roughly 15,630 current and former employees, pooled on the same reachable network as the machinery. No group ever claimed it and the files never surfaced on a leak site, which is theft you cannot negotiate back.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1477294/000147729425000047/st-20250406.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Manufacturing",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "CONDUENT Inc",
          "breached_entity": null,
          "date": "Apr 2025",
          "disclosed": "2025-04-14",
          "group": "889b18dc-fdb7-42ae-bc4f-5bd2d8cb06fa",
          "slug": null,
          "is_primary": true,
          "detail": "A threat actor sat inside Conduent's environment for nearly three months, from October 2024 until a January 2025 disruption gave it away, long enough to take what SafePay claims was roughly 8 terabytes. Conduent is the back office that governments and health plans outsource to, so one intrusion became a front door to their end-users, a count that has climbed from 10 million toward 60 million as the forensics catch up. When the processor is the perimeter, its dwell time becomes everyone's.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1677703/000167770325000067/cndt-20250409.htm",
          "enforcement": null,
          "amount": "$25M",
          "grade": "V",
          "money": {
            "case": "single",
            "amount": "$25M",
            "amount_usd": 25000000,
            "category": "direct_expense",
            "grade": "V",
            "state": "realized",
            "source_url": "https://www.sec.gov/Archives/edgar/data/1677703/000167770325000076/cndt-20250331.htm",
            "source_label": "SEC 10-Q",
            "caveat": null,
            "figures": []
          },
          "sector": "Professional and Business Services",
          "needs_grading": false,
          "lag_days": 23,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$25M",
              "amount_usd": "25000000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/1677703/000167770325000076/cndt-20250331.htm",
              "disclosed": "2025-05-07",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "DAVITA INC.",
          "breached_entity": null,
          "date": "Apr 2025",
          "disclosed": "2025-04-14",
          "group": "99376513-d35b-48ed-8d7d-a5018eea7a78",
          "slug": null,
          "is_primary": true,
          "detail": "DaVita's ransomware sat inside its dialysis labs for three weeks before discovery, and the encryption was the loud part; the quiet part was a labs database pooling 2.7 million people's Social Security numbers, dialysis results, and scanned images of their personal checks. A treatment provider had become a warehouse of financial identity, the fate of any database asked to hold everything. Interlock, which claimed the theft and leaked the files, needed no exploit, only the weeks the network gave it.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/927066/000119312525079593/d948299d8k.htm",
          "enforcement": null,
          "amount": "$13.5M",
          "grade": "V",
          "money": {
            "case": "total",
            "amount": "$25M",
            "amount_usd": 25000000,
            "category": "total_incident_cost",
            "grade": "V",
            "state": "realized",
            "source_url": "https://www.sec.gov/Archives/edgar/data/927066/000092706626000012/dva-20251231.htm",
            "source_label": "SEC 10-K",
            "caveat": "Company-stated total, of which: direct response costs $13.5M.",
            "figures": [
              {
                "amount": "$13.5M",
                "amount_usd": 13500000,
                "category": "direct_expense",
                "state": "realized",
                "grade": "V",
                "disclosure": null,
                "source_url": "https://www.sec.gov/Archives/edgar/data/927066/000092706625000124/dva-20250630.htm",
                "source_label": "SEC 10-Q"
              }
            ],
            "cumulative": null
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": 113,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$13.5M",
              "amount_usd": "13500000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/927066/000092706625000124/dva-20250630.htm",
              "disclosed": "2025-08-05",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "Global Crossing Airlines Group Inc.  (JETBF, JETMF)",
          "breached_entity": null,
          "date": "May 2025",
          "disclosed": "2025-05-09",
          "group": "f200fe95-e4ea-432d-ac60-3a5c8829e0d3",
          "slug": null,
          "is_primary": true,
          "detail": "The way in ran through a developer token that opened onto GlobalX's AWS keys, and from there the whole cloud: passenger manifests, the GitHub repo, even the NAVBLUE console used to message pilots. Hackers claiming affiliation with Anonymous copied months of that data, from January through early May, then defaced the homepage to say so. When one credential is the distance between a public website and every operational system, the perimeter was never the network; it was a token nobody thought to rotate.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1846084/000095017025068004/jetmf-20250505.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Transportation and Logistics",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "NUCOR CORP",
          "breached_entity": null,
          "date": "May 2025",
          "disclosed": "2025-05-14",
          "group": "05843d30-cac1-4927-9dc6-11b0fe4b7fb3",
          "slug": null,
          "is_primary": false,
          "detail": "Nucor took steel mills offline across multiple sites after a threat actor reached its corporate IT systems, the wall between office networks and the plant floor apparently thinner than the org chart suggested. The company calls the stolen data limited and the impact immaterial, though no one has said what left, how much, or who took it, and no group has claimed the attack. When an intrusion in the back office can idle a blast furnace, the boundary was never really there.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/73309/000119312525119311/d795264d8k.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Manufacturing",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Coinbase Global, Inc.",
          "breached_entity": "Coinbase, Inc.",
          "date": "May 2025",
          "disclosed": "2025-05-15",
          "group": "7238c368-6b42-4296-9a3e-458ed8129c62",
          "slug": null,
          "is_primary": true,
          "detail": "Coinbase's breach ran through its own support desk: overseas contractors with legitimate access to account-management tools, paid off by attackers who never needed an exploit because the credentials were already for sale. The stolen file held names, contact details, partial Social Security numbers, and government ID images for roughly 69,000 customers, the identity documents a regulated exchange is obliged to collect and then made someone else's job to guard. Coinbase refused the $20 million demand and posted a $20 million bounty instead, which does nothing to un-copy the data. The perimeter was never the network; it was a payroll, and someone made a better offer.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1679788/000167978825000094/coin-20250514.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "ERIE INDEMNITY CO",
          "breached_entity": null,
          "date": "Jun 2025",
          "disclosed": "2025-06-11",
          "group": "30301a7f-6dbd-46f3-b173-9ccc5e24b19d",
          "slug": null,
          "is_primary": true,
          "detail": "Erie Indemnity's website and business ran aground on June 7, 2025, after what the company called an information security event, with no ransomware found and no data theft confirmed. What it could not stop was the litigation: fourteen putative class actions landed within days, over an exposure still unproven. When the outage is public and the facts are not, the lawsuits arrive before the forensics do.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/922621/000092262125000023/erie-20250607.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Zoomcar Holdings, Inc.  (ZCAR, ZCARW)",
          "breached_entity": null,
          "date": "Jun 2025",
          "disclosed": "2025-06-13",
          "group": "f1067f4b-3bfe-4bbc-8bb9-dc07fa125237",
          "slug": null,
          "is_primary": true,
          "detail": "Zoomcar learned it had been breached the way too many companies do: an extortion note landed in its employees' inboxes announcing the data was already gone, roughly 8.4 million users' names, addresses, phone numbers, and car registrations. No monitoring caught the intrusion, no group has claimed it, and the vector stays unnamed. When the breach notification arrives from the intruder, the security program was never watching the systems, only the paperwork.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1854275/000121390025054319/ea0245724-8k_zoomcar.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Transportation and Logistics",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "AFLAC INC",
          "breached_entity": null,
          "date": "Jun 2025",
          "disclosed": "2025-06-20",
          "group": "69e692ee-e3bc-4141-8af2-21413cc0c704",
          "slug": null,
          "is_primary": true,
          "detail": "Aflac contained the intrusion within hours, and by then attackers had already talked their way into employee accounts and left with data on about 22.6 million people: Social Security numbers, claims, health details. The break-in was a phone call, not an exploit; reporting ties it to Scattered Spider, though the lever was social engineering, not any flaw in the network. Fast containment is worth little when the theft finishes before the alarm does.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/4977/000000497725000128/afl-20250620.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "ALASKA AIR GROUP, INC.",
          "breached_entity": "Hawaiian Airlines",
          "date": "Jun 2025",
          "disclosed": "2025-06-27",
          "group": "3ef65996-deed-4e7e-af84-812681a6b3a5",
          "slug": null,
          "is_primary": true,
          "detail": "Hawaiian Airlines lost ground on June 23, 2025, to intruders who did not break the perimeter so much as phone the IT help desk and get believed. Reporting ties it to Scattered Spider, though the mechanism is the story: an identity system where whoever resets passwords is the softest wall in the building. What left stays unstated, customer names and addresses possibly reached, payment data reportedly not, the affected count never surfaced. A help desk trained to be helpful is a perimeter trained to open.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/766421/000076642125000023/alk-20250627.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Transportation and Logistics",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Ingram Micro Holding Corp",
          "breached_entity": null,
          "date": "Jul 2025",
          "disclosed": "2025-07-07",
          "group": "0d4b2234-a5ac-4f31-b80f-4edc4612d031",
          "slug": null,
          "is_primary": true,
          "detail": "The intrusion came through Ingram Micro's GlobalProtect VPN, reached with valid credentials because a gateway that trusts a password is the entire perimeter, and SafePay moved from there across a distributor wired into thousands of vendors and resellers. About 42,521 people lost names, Social Security numbers, and passport data; the group claims 3.5 terabytes and published the files, which is what a refused ransom looks like. A VPN login is a front door, not a boundary.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1897762/000162828025034372/ingm-20250705.htm",
          "enforcement": null,
          "amount": "$6.17M",
          "grade": "V",
          "money": {
            "case": "single",
            "amount": "$6.17M",
            "amount_usd": 6168000,
            "category": "direct_expense",
            "grade": "V",
            "state": null,
            "source_url": "https://www.sec.gov/Archives/edgar/data/1897762/000162828026013588/ingm-20251227.htm",
            "source_label": "SEC 10-K",
            "caveat": null,
            "figures": []
          },
          "sector": "Wholesale and Distribution",
          "needs_grading": false,
          "lag_days": 239,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$6.17M",
              "amount_usd": "6168000",
              "grade": "V",
              "source": "SEC 10-K",
              "url": "https://www.sec.gov/Archives/edgar/data/1897762/000162828026013588/ingm-20251227.htm",
              "disclosed": "2026-03-03",
              "pre_tracking": false
            },
            {
              "amount": "$3.17M",
              "amount_usd": "3165000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/1897762/000162828026051053/ingm-20260627.htm",
              "disclosed": "2026-07-30",
              "pre_tracking": false
            },
            {
              "amount": "$1.12M",
              "amount_usd": "1122000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/1897762/000162828026051053/ingm-20260627.htm",
              "disclosed": "2026-07-30",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "WYTEC INTERNATIONAL INC",
          "breached_entity": null,
          "date": "Aug 2025",
          "disclosed": "2025-08-29",
          "group": "cb355ed4-3369-4ccd-8591-117838101249",
          "slug": null,
          "is_primary": true,
          "detail": "Wytec International's website was defaced, restored from backups, and defaced again, which is what a restore buys when it returns the content but not the hole the intruder came through. No group claimed the attack, no data theft surfaced, and no motive ever emerged, so the damage landed as operations rather than exfiltration, down to a canceled September seminar. A backup copies the site, not the way in.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1560143/000168316825006583/wytec_8k.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Telecommunications",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "EVERTEC, Inc.",
          "breached_entity": "Sinqia S.A.",
          "date": "Aug 2025",
          "disclosed": "2025-09-02",
          "group": "251c8666-1f4e-4dc8-9f1f-9b59a5d50a1d",
          "slug": null,
          "is_primary": true,
          "detail": "The money moved through Sinqia's Pix environment on credentials stolen from its own IT vendors, which is what happens once a payment connector treats a supplier's login as its trust boundary. Roughly R$710 million in unauthorized transactions cleared before processing halted, aimed mostly at HSBC, with about half later frozen. Sinqia is the third Brazilian firm wired between banks and the central rail to be looted this way in a year: the soft spot in real-time payments is not the bank but the plumbing that reaches it.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1559865/000155986525000043/evtc-20250829.htm",
          "enforcement": null,
          "amount": "$37.7M",
          "grade": "V",
          "money": {
            "case": "single",
            "amount": "$37.7M",
            "amount_usd": 37700000,
            "category": "direct_expense",
            "grade": "V",
            "state": null,
            "source_url": "https://www.sec.gov/Archives/edgar/data/1559865/000155986525000054/evtc-20250930.htm",
            "source_label": "SEC 10-Q",
            "caveat": null,
            "figures": []
          },
          "sector": "Technology and Software",
          "needs_grading": false,
          "lag_days": 66,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$37.7M",
              "amount_usd": "37700000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/1559865/000155986525000054/evtc-20250930.htm",
              "disclosed": "2025-11-07",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "PROSPER MARKETPLACE, INC",
          "breached_entity": null,
          "date": "Sep 2025",
          "disclosed": "2025-09-17",
          "group": "e1874b2e-f971-4032-ac89-06f616f76e05",
          "slug": null,
          "is_primary": true,
          "detail": "Prosper's breach was the database answering as designed: someone inside its systems queried the tables holding customer and applicant records and left with Social Security numbers, bank accounts, passports, and tax files on 17.6 million people. Network access was treated as permission to read the one warehouse where a lender keeps its most sensitive identity data, and months of quiet queries passed as ordinary traffic. No group has claimed the theft, leaving the adversary unnamed and the harvest complete.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1416265/000141626525000038/prosper-20250901.htm",
          "enforcement": null,
          "amount": "$600K",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": 57,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$600K",
              "amount_usd": "600000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/1416265/000141626525000043/prosper-20250930.htm",
              "disclosed": "2025-11-13",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "RTX Corp",
          "breached_entity": null,
          "date": "Sep 2025",
          "disclosed": "2025-09-24",
          "group": "479052ef-ed41-4c37-8248-5aa92c5f2ccf",
          "slug": null,
          "is_primary": true,
          "detail": "The ransomware hit Collins Aerospace's MUSE platform, the shared check-in backbone that roughly 170 airports rent instead of running their own, so a single intrusion grounded Heathrow, Brussels, and Berlin at once. Access came through the vMUSE backend's FTP credentials, harvested by an earlier infostealer and never rotated: a legacy file transfer left standing as the door to the passenger layer. Everest claims a 50GB haul of more than 1.5 million passenger records; the airports had not built a hundred systems to breach, only one.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/101829/000010182925000036/rtx-20250919.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Manufacturing",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "BK Technologies Corp",
          "breached_entity": null,
          "date": "Oct 2025",
          "disclosed": "2025-10-06",
          "group": "c658daa6-a3d8-406b-9401-bd1355a2892a",
          "slug": null,
          "is_primary": true,
          "detail": "BK Technologies builds the radios police and the military carry, yet its military contracts, NDAs, and employee records sat in the same corporate custody a single intruder walked through in September. Akira claims 25 gigabytes of it, though the company confirms neither the haul nor how the door was opened. When the crown jewels and the payroll sit behind one lock, the breach is not a radio problem; it is an architecture that never separated what it could not afford to lose.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/2186/000143774925030540/bkti20251006_8k.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Manufacturing",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "JEWETT CAMERON TRADING CO LTD",
          "breached_entity": null,
          "date": "Oct 2025",
          "disclosed": "2025-10-21",
          "group": "02a5a7fc-a73e-4e16-9d9a-5a53136b5455",
          "slug": null,
          "is_primary": true,
          "detail": "Jewett-Cameron woke on October 15 to intruders that had settled into its corporate IT, running their own encryption and monitoring software to watch the fencing and pet-supply maker's meetings and screens from the inside. What they carried off was the financial detail being assembled for the company's annual report, the disclosure stolen before it could be disclosed. No known ransomware crew has claimed it or listed the company on a leak site, which leaves the extortion loud and its author blank.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/885307/000107997325001631/jctc_8k.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "BayFirst Financial Corp.",
          "breached_entity": null,
          "date": "Oct 2025",
          "disclosed": "2025-10-30",
          "group": "c9f78b4b-e57f-4d66-91fa-785509eb3864",
          "slug": null,
          "is_primary": true,
          "detail": "BayFirst's customer data left through Marquis Software Solutions, the marketing vendor whose SonicWall firewall opened to a ransomware crew. Names, dates of birth, and Social Security numbers sat there because one contractor holds them for more than 700 banks and credit unions: a single breach reached 74 institutions and over 780,000 people. How many banked at BayFirst the filing does not say. A bank can lock every system it owns and still lose its customers through a vendor's front door.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1649739/000164973925000246/bafn-20251028.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Phoenix Education Partners, Inc.",
          "breached_entity": "The University of Phoenix, Inc.",
          "date": "Dec 2025",
          "disclosed": "2025-12-02",
          "group": "9d4a879c-5a41-45a3-9687-1a21868a9650",
          "slug": null,
          "is_primary": true,
          "detail": "The break-in came through Oracle's E-Business Suite, the back-office platform Phoenix shared with a hundred other victims, where a single zero-day in the reporting engine handed the Cl0p group the run of the place. Over ten days in August the attackers left with names, Social Security numbers, and bank routing numbers for roughly 3.5 million students, alumni, and staff; the university noticed in November. A shared enterprise platform is not infrastructure; it is one lock that opens a hundred doors.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1600222/000095014225003098/eh250711375_8k.htm",
          "enforcement": null,
          "amount": "$5.1M",
          "grade": "V",
          "money": {
            "case": "single",
            "amount": "$5.1M",
            "amount_usd": 5100000,
            "category": "direct_expense",
            "grade": "V",
            "state": "realized",
            "source_url": "https://www.sec.gov/Archives/edgar/data/1600222/000119312526303175/pxed-20260531.htm",
            "source_label": "SEC 10-Q",
            "caveat": null,
            "figures": []
          },
          "sector": "Public Sector and Education",
          "needs_grading": false,
          "lag_days": 224,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$5.1M",
              "amount_usd": "5100000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/1600222/000119312526303175/pxed-20260531.htm",
              "disclosed": "2026-07-14",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "Coupang, Inc.",
          "breached_entity": null,
          "date": "Dec 2025",
          "disclosed": "2025-12-29",
          "group": "6da5e32d-4e78-40b9-a1c4-900bdf39166e",
          "slug": null,
          "is_primary": true,
          "detail": "The engineer who built Coupang's alternative authentication system left at the end of 2024 with the signing key that anchored it, then spent 2025 forging his own tokens. Investigators say he cycled through member IDs, hitting the delivery-address page some 148 million times to harvest names, phones, and addresses on roughly 37 million people, then mailed sample records back as extortion. A signing key the builder can still mint is not access control; it is a master key offboarding forgot to change.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1834584/000183458425000202/cpng-20251215.htm",
          "enforcement": {
            "amount_usd": 409300000,
            "original": "625 billion won",
            "source": "South Korean Personal Information Protection Commission",
            "url": "https://www.reuters.com/legal/litigation/south-korea-fines-coupang-409-mln-countrys-largest-data-breach-penalty-2026-06-11/?utm_source=chatgpt.com"
          },
          "amount": "$410M",
          "grade": "V",
          "money": {
            "case": "single",
            "amount": "$410M",
            "amount_usd": 410000000,
            "category": "direct_expense",
            "grade": "V",
            "state": null,
            "source_url": "https://www.sec.gov/Archives/edgar/data/1834584/000183458426000073/cpng-20260630.htm",
            "source_label": "SEC 10-Q",
            "caveat": null,
            "figures": []
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": 218,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$410M",
              "amount_usd": "410000000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/1834584/000183458426000073/cpng-20260630.htm",
              "disclosed": "2026-08-04",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "WYTEC INTERNATIONAL INC",
          "breached_entity": null,
          "date": "Aug 2025",
          "disclosed": "2026-02-03",
          "group": "cb355ed4-3369-4ccd-8591-117838101249",
          "slug": null,
          "is_primary": false,
          "detail": "Wytec International's website was defaced, restored from backups, and defaced again, which is what a restore buys when it returns the content but not the hole the intruder came through. No group claimed the attack, no data theft surfaced, and no motive ever emerged, so the damage landed as operations rather than exfiltration, down to a canceled September seminar. A backup copies the site, not the way in.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1560143/000168316826000732/wytec_8ka1.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Telecommunications",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "UFP TECHNOLOGIES INC",
          "breached_entity": null,
          "date": "Feb 2026",
          "disclosed": "2026-02-24",
          "group": "e60ad952-b67a-4b73-b6e8-70ef436700d3",
          "slug": null,
          "is_primary": true,
          "detail": "UFP Technologies runs a medical-device operation where the same IT plumbing prints invoices and product labels, so when ransomware arrived on February 14, 2026, billing and shipping stalled together. Payouts King, an outfit assembled from former Black Basta affiliates, claims it carried off 620 gigabytes; UFP has confirmed only that data left, not how anyone got in. When one flat network runs both the money and the labels, a single intrusion becomes a supply-chain event, and the door it used stays unnamed.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/914156/000162828026011152/ufpt-20260219.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "TRIO-TECH INTERNATIONAL",
          "breached_entity": null,
          "date": "Mar 2026",
          "disclosed": "2026-03-20",
          "group": "2fef0da6-a23e-4af1-83cd-82ca7d5f7290",
          "slug": null,
          "is_primary": true,
          "detail": "Trio-Tech International's Singapore subsidiary had its files encrypted on March 11, and management filed the ransomware away as immaterial, a judgment made while the attacker still held a copy of the data. A week later the Gunra group began publishing that data on its leak site, and the non-material call rewrote itself. Materiality is not a verdict the victim keeps when the extortionist owns the appeal. How the intruders got into a chip-testing network, and how much walked out, the company has not yet said.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/732026/000143774926009193/trt20260320_8k.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Manufacturing",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "HERITAGE FINANCIAL CORP",
          "breached_entity": null,
          "date": "Mar 2026",
          "disclosed": "2026-03-23",
          "group": "3c2e3527-5967-4a41-90a5-b03f5bf51a6c",
          "slug": null,
          "is_primary": true,
          "detail": "Heritage Bank kept the intrusion out of its customer systems, but customer data was never only there: it sat on an internal file share, the drive where employees pile names, Social Security numbers, and account details until 182,793 people live in one folder. An unnamed party copied those files, and how anyone reached a server marked internal, the bank has not said. A file share is not a filing cabinet; it is a database no one agreed to secure.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1046025/000162828026020261/hfwa-20260320.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "HASBRO, INC.",
          "breached_entity": null,
          "date": "Apr 2026",
          "disclosed": "2026-04-01",
          "group": "41025e05-6ea9-4c6c-b748-2d79f18c3180",
          "slug": "hasbro-inc-2026-04-01",
          "is_primary": true,
          "detail": "Hasbro spent weeks taking orders and shipping product by hand while it rebuilt the network an intruder walked into on March 28, and the $10.8 million cleanup measures the recovery, not the loss. What got in, how, and whether anything left stays unnamed: no vector, no actor, no record count, just \"unauthorized access to the Company's network\" and a consumer-products operation limping along on business-continuity workarounds. A breach described only by its cost is one whose architecture nobody wants to draw.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/46080/000004608026000013/has-20260401.htm",
          "enforcement": null,
          "amount": "$10.8M",
          "grade": "V",
          "money": {
            "case": "single",
            "amount": "$10.8M",
            "amount_usd": 10800000,
            "category": "direct_expense",
            "grade": "V",
            "state": null,
            "source_url": "https://www.sec.gov/Archives/edgar/data/46080/000004608026000050/has-20260628.htm",
            "source_label": "SEC 10-Q",
            "caveat": null,
            "figures": []
          },
          "sector": "Manufacturing",
          "needs_grading": false,
          "lag_days": 120,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$10.8M",
              "amount_usd": "10800000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/46080/000004608026000050/has-20260628.htm",
              "disclosed": "2026-07-30",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "STRYKER CORP",
          "breached_entity": null,
          "date": "Mar 2026",
          "disclosed": "2026-04-09",
          "group": "42ef78b4-8083-4e0e-8014-0e43305a5ea3",
          "slug": "stryker-corp-2026-04-09",
          "is_primary": true,
          "detail": "Stryker went dark in a single night, its machines factory-reset not by malware but through Microsoft Intune, the platform built to manage them, after an infostealer lifted an employee's credentials and attackers climbed them into Global Administrator. Handala, an Iran-aligned group, needed no exploit: the console that pushes software to every device can also wipe every device, gated by one login. The group claims more than 200,000 devices erased and 50 terabytes taken before the reset.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/310764/000119312526149607/d112875d8ka.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "RCI HOSPITALITY HOLDINGS, INC.",
          "breached_entity": "RCI Internet Services, Inc.",
          "date": "Apr 2026",
          "disclosed": "2026-04-13",
          "group": "16c967c3-8184-4b99-a79d-0f373814325e",
          "slug": null,
          "is_primary": true,
          "detail": "RCI Internet Services left an insecure direct object reference on its public-facing IIS web server, so the application checked who was logged in but never whether the record requested was actually theirs. Changing a number in the URL was enough to walk out with contractor files on about 40,178 people, Social Security and driver's license numbers included. Its remediation, adding multifactor authentication and cutting external access, names the wall that was never there. Authorization was not breached here; it was never enforced past the login screen.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/935419/000162828026024806/rick-20260407.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "ADT Inc.",
          "breached_entity": null,
          "date": "Apr 2026",
          "disclosed": "2026-04-24",
          "group": "c87dc644-f1de-4960-9c71-6c30c4088cbd",
          "slug": null,
          "is_primary": true,
          "detail": "The break-in ran through ADT's Salesforce instance, reached not by an exploit but by phoning an employee out of their Okta login: identity treated as the perimeter folds the moment someone answers politely. What left was names, phone numbers, and addresses, with dates of birth and partial Social Security numbers for some; ShinyHunters claims over 10 million records against the roughly 5.5 million accounts others counted. A home security firm can arm every door it sells and still leave its customer list open to a phone call.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1703056/000170305626000038/adt-20260420.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Professional and Business Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "ITRON, INC.",
          "breached_entity": null,
          "date": "Apr 2026",
          "disclosed": "2026-05-01",
          "group": "80c723a4-5dc0-4a73-ab5a-d2b56ca007a2",
          "slug": null,
          "is_primary": true,
          "detail": "Itron sits inside the grid itself: smart meters and the software behind them across more than 8,000 utilities, hundreds of millions of endpoints. On April 13, 2026, an unauthorized third party reached its internal IT network, and the account stops there, naming no actor, no vector, and no data confirmed taken. No ransomware crew has claimed it, which in this field reads less like safety than like an investigation that has not finished. When the vendor is this deep in the utilities' plumbing, silence about how the front door opened is not reassurance; it is the part worth watching.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/780571/000119312526199316/d151348d8ka.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Manufacturing",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "CB Financial Services, Inc.",
          "breached_entity": "Community Bank",
          "date": "May 2026",
          "disclosed": "2026-05-11",
          "group": "ad9e7575-9f70-461b-9d7d-6364dc247910",
          "slug": "community-bank-2026-05-11",
          "is_primary": true,
          "detail": "The customer data left through an unauthorized AI application, loaded in by an employee: names, Social Security numbers, and dates of birth, handed to a chatbot no one had cleared. No attacker forced the door because none had to; the exposure was a copy operation dressed as productivity. Community Bank reached the app's vendor before the records could train a model, though it has not said how many people were fed in, or which tool swallowed them.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1605301/000160530126000021/cbfv-20260507.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Inotiv, Inc.",
          "breached_entity": null,
          "date": "May 2026",
          "disclosed": "2026-05-18",
          "group": "af3de10f-5e32-4ff2-8d97-5e958f0d680d",
          "slug": null,
          "is_primary": true,
          "detail": "Inotiv's databases and internal applications went dark together in early August, because one ransomware intrusion sat close enough to both the lab work and the personnel files to take them at once. Qilin, a ransomware-as-a-service franchise rather than a lone genius, claims 176 gigabytes across roughly 162,000 files; the 9,542 people notified were mostly Inotiv's own employees and their families. How the door was first opened has gone unnamed. A firm that models drug safety could not partition its own blast radius.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/720154/000110465926063032/tm2614614d1_8k.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Professional and Business Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "WEST PHARMACEUTICAL SERVICES INC",
          "breached_entity": null,
          "date": "May 2026",
          "disclosed": "2026-05-20",
          "group": "14e78d82-1d78-4e19-887c-fb1aa52e961b",
          "slug": null,
          "is_primary": true,
          "detail": "West Pharmaceutical Services makes the stoppers, seals, and injectable components much of the drug industry cannot ship without, so encrypting its systems pulled operations offline across the globe at once. The intruders lifted the data before locking the files, the rehearsed two-step now standard in the trade. No group has claimed the hit, and West has named neither the vector nor how many people the stolen data covers; when nobody boasts about a ransomware attack, the silence usually means the invoice was paid.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/105770/000010577026000077/wst-20260507.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "single",
            "amount": "$7M",
            "amount_usd": 7000000,
            "category": "business_interruption",
            "grade": "V",
            "state": "estimated",
            "source_url": "https://www.sec.gov/Archives/edgar/data/105770/000010577026000099/wst-20260630.htm",
            "source_label": "SEC 10-Q",
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Oncology Institute, Inc.  (TOI, DFPH, TOIIW)",
          "breached_entity": null,
          "date": "May 2026",
          "disclosed": "2026-05-22",
          "group": "b82e0ad6-0d06-4db5-be8e-2a90ab8f73ab",
          "slug": null,
          "is_primary": true,
          "detail": "The Oncology Institute's patient data never lived only at the Oncology Institute; it sat inside a shared claims clearinghouse that reporting ties to Cognizant's TriZetto, where an intruder had been reading records since late 2024 before anyone noticed. Route a hundred clinics and two million patients through one vendor, and that vendor becomes the front door. TOI has not said how many were exposed or what left, only that Kroll is mailing the notices: the silence is now the disclosure.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1799191/000107997326000721/toi_8k.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Popular, Inc",
          "breached_entity": "Evertec",
          "date": "Jun 2026",
          "disclosed": "2026-06-09",
          "group": "86f9b037-f2d9-4e4e-a239-b061b7b2bd73",
          "slug": "evertec-2026-06-09",
          "is_primary": true,
          "detail": "Popular, Inc. was pulled into a cybersecurity incident through Evertec, the third-party provider it relies on for core financial transaction processing and IT services. The compromise affected data belonging to Banco Popular de Puerto Rico, illustrating a familiar problem: outsourcing the technology does not outsource the exposure. The attack did not need to breach Popular directly; compromising a trusted provider was enough to reach the bank’s data.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/763901/000119312526263044/d46942d8k.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "EVERTEC, Inc.",
          "breached_entity": null,
          "date": "Jun 2026",
          "disclosed": "2026-06-09",
          "group": "81114a89-3627-4038-8e7f-bfeefbefd694",
          "slug": null,
          "is_primary": true,
          "detail": "Evertec reported potential unauthorized access to customer data. This is the second breach in less than 12 months for Evertec, this time impacting Puerto Rico and their respective customers instead of Brazil. Rather than reporting this as a 1.05 material incident, Evertec reported it as an 8.01 (other event), even though their Pixa breach just resulted in a 10Q financial disclosure of losses associated to the 2025 Pixa event.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1559865/000155986526000039/evtc-20260609.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Coca Cola Company",
          "breached_entity": "Fairlife",
          "date": "Jul 2026",
          "disclosed": "2026-07-16",
          "group": "c564e39e-a3b3-4d38-b83c-19ce4a49554d",
          "slug": "fairlife-2026-07-16",
          "is_primary": true,
          "detail": "The Coca-Cola Company disclosed that Fairlife, a dairy subsidiary, experienced a ransomware event. The filing does not establish when the attack occurred or what it may cost, so the incident is recorded against its July 16, 2026 disclosure date.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/21344/000162828026048466/ko-20260716.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Manufacturing",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "CLOVER HEALTH INVESTMENTS, CORP. /DE",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-07-17",
          "group": "61c58bfa-9636-4504-9243-3662f5b42281",
          "slug": null,
          "is_primary": true,
          "detail": "Clover Health says social engineering compromised three employee accounts with access to member PII and PHI, although claims and corporate financial systems were not accessed. Four putative class actions followed, and Clover says it cannot yet reasonably estimate the possible loss or range of loss. Three identities were enough to create a regulated-data event and litigation exposure; that is the problem with treating identity as proof of trust instead of something that has to be continuously verified.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1801170/000180117026000181/clov-20260704.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "UPBOUND GROUP, INC.",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-07-22",
          "group": "94c675ac-d04b-4d73-b654-8d9731bf9c90",
          "slug": null,
          "is_primary": true,
          "detail": "Upbound rated the stolen customer information non-sensitive, right up until it was enough to open roughly $13 million in fraudulent Acima leases and walk the merchandise out the door. The breach turned lease-to-own approval into a front door for anyone holding the right paperwork: identity verification that trusted data the company itself had graded as low value. No group has claimed it and no customer count has surfaced, leaving the theft measured only by the fraud it financed.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/933036/000119312526310605/upbd-20260721.htm",
          "enforcement": null,
          "amount": "$13M",
          "grade": "V",
          "money": {
            "case": "single",
            "amount": "$13M",
            "amount_usd": 13000000,
            "category": "direct_expense",
            "grade": "V",
            "state": null,
            "source_url": "https://www.sec.gov/Archives/edgar/data/933036/000119312526326420/upbd-20260630.htm",
            "source_label": "SEC 10-Q",
            "caveat": null,
            "figures": []
          },
          "sector": "Professional and Business Services",
          "needs_grading": false,
          "lag_days": 9,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$13M",
              "amount_usd": "13000000",
              "grade": "V",
              "source": "SEC 10-Q",
              "url": "https://www.sec.gov/Archives/edgar/data/933036/000119312526326420/upbd-20260630.htm",
              "disclosed": "2026-07-31",
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "FIVE BELOW, INC",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-07-22",
          "group": "da1c6834-bf7c-452e-9258-7af3eb13f44c",
          "slug": null,
          "is_primary": true,
          "detail": "Five Below traced the intrusion to a single employee's company laptop, reached not by an exploit but by a threat actor who talked the person into granting access, and files were exfiltrated before the anomaly was ever flagged. The company's comfort is the blast radius: one machine, no PII, nothing else touched, a tidy story about a perimeter that turned out to be one talked-past employee. Who took the files, and how many, the filing does not say.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1177609/000119312526312573/d19155d8k.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Coupang",
          "breached_entity": null,
          "date": "Jun 2026",
          "disclosed": null,
          "group": "6da5e32d-4e78-40b9-a1c4-900bdf39166e",
          "slug": null,
          "is_primary": false,
          "detail": "South ​Korea will fine e-commerce giant Coupang (CPNG.N), opens new tab 625 billion won ($409.30 million) over a massive leak of ‌customer information last year and illegal collection of personal information.",
          "detail_kind": "summary",
          "source": "South Korean Personal Information Protection Commission",
          "source_type": "regulatory_action",
          "source_url": "https://www.reuters.com/legal/litigation/south-korea-fines-coupang-409-mln-countrys-largest-data-breach-penalty-2026-06-11/?utm_source=chatgpt.com",
          "enforcement": {
            "amount_usd": 409300000,
            "original": "625 billion won",
            "source": "South Korean Personal Information Protection Commission",
            "url": "https://www.reuters.com/legal/litigation/south-korea-fines-coupang-409-mln-countrys-largest-data-breach-penalty-2026-06-11/?utm_source=chatgpt.com"
          },
          "amount": "$410M",
          "grade": "V",
          "money": {
            "case": "single",
            "amount": "$410M",
            "amount_usd": 410000000,
            "category": "direct_expense",
            "grade": "V",
            "state": null,
            "source_url": "https://www.sec.gov/Archives/edgar/data/1834584/000183458426000073/cpng-20260630.htm",
            "source_label": "SEC 10-Q",
            "caveat": null,
            "figures": []
          },
          "sector": null,
          "needs_grading": false,
          "lag_days": 218,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "SPay Inc dba Stack Sports",
          "breached_entity": null,
          "date": "May 2026",
          "disclosed": "2026-07-27",
          "group": "1ab3ed68-831a-4185-8bb2-889e86c37764",
          "slug": null,
          "is_primary": true,
          "detail": "Stack Sports discovered unauthorized code inside its Sports Affinity payment platform that captured payment-card information entered during checkout. The company operates registration and payment systems used by youth and amateur sports leagues, meaning affected transactions may involve parents paying participation fees for children. The malicious code was reportedly present from May 8 until June 8, 2026, creating a month-long payment-card skimming window. The number of affected customers remains undisclosed, but the platform’s role across youth sports organizations gives the incident a potentially broad consumer impact.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-627175",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Technology and Software",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Devereux Foundation",
          "breached_entity": null,
          "date": "Nov 2025",
          "disclosed": "2026-07-23",
          "group": "92009995-89d6-448a-8818-fa91f3742830",
          "slug": null,
          "is_primary": true,
          "detail": "Devereux Advanced Behavioral Health disclosed a ransomware attack involving information belonging to patients, employees, family members, donors and business partners. The potentially exposed data included combinations of Social Security numbers, financial information, government identification, medical information and health insurance information. Devereux provides behavioral health and developmental disability services across multiple states, giving the incident a broad geographic footprint. The attack highlights the impact ransomware is having on organizations serving vulnerable patient populations.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-626965",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "DentaQuest LLC",
          "breached_entity": null,
          "date": "May 2026",
          "disclosed": "2026-07-16",
          "group": "f2970448-8460-4d97-bbb8-ce4fcc474221",
          "slug": null,
          "is_primary": true,
          "detail": "Between May 17 and May 20 attackers accessed and exfilitrated names, addresses, Social Security numbers, member identification numbers, Medicaid and Medicare numbers, diagnosis, treatment details and billing information for as many as 23.4 million patients. Notifications have been sent to at least 4.5 million people.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-626583",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Madera Community Hospital",
          "breached_entity": null,
          "date": "May 2025",
          "disclosed": "2026-07-14",
          "group": "f3d2305d-fe0f-49d3-9cdd-5f2b35990b88",
          "slug": null,
          "is_primary": true,
          "detail": "Madera Community Hospital determined that an unauthorized party accessed its network and likely removed files containing patient personal and health information on May 28 and 29, 2025. The hospital completed its initial forensic determination in June 2025 but did not begin notifying patients until approximately one year later. The final number of affected patients has not been publicly established in the reporting reviewed.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-626464",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Markel Insurance",
          "breached_entity": null,
          "date": "Mar 2026",
          "disclosed": "2026-07-02",
          "group": "9cf953c4-0979-4a05-80d7-fd95bc43c125",
          "slug": null,
          "is_primary": true,
          "detail": "Markel Insurance disclosed a cybersecurity incident involving unauthorized access to portions of its environment, although the company has released limited information regarding the overall scope of the breach. Public disclosures have not established the total number of affected individuals or whether policyholder information was involved. As one of the world's largest specialty insurers, any compromise involving underwriting, claims or broker information could have broader implications than a typical employee data breach. Additional details will determine the long-term significance of this incident.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-625932",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Professional and Business Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Child Care Resource Center",
          "breached_entity": null,
          "date": "Oct 2016",
          "disclosed": "2026-07-02",
          "group": "61b9b3f9-556c-4fbd-9b31-775f50927928",
          "slug": null,
          "is_primary": true,
          "detail": "The Child Care Resource Center disclosed that an employee allegedly forwarded organizational files to an external email account over a period spanning nearly nine years, from 2016 through 2025. The nonprofit serves thousands of children and families throughout Los Angeles County and administers childcare assistance and family support programs. While the total number of affected individuals has not been publicly established, the incident potentially involves highly sensitive information relating to children, parents, providers and employees. The duration of the unauthorized activity makes this disclosure particularly noteworthy.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-625925",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Monmouth University",
          "breached_entity": null,
          "date": "Feb 2026",
          "disclosed": "2026-06-30",
          "group": "f5db8120-32d5-4998-803d-da8335756acd",
          "slug": null,
          "is_primary": true,
          "detail": "Monmouth University disclosed a ransomware-related incident involving personal, financial and medical information belonging to students, employees and others connected with the institution. The PEAR ransomware group claimed that it removed approximately 16 terabytes of data, although that figure has not been independently confirmed by the university. The intrusion reportedly occurred in February 2026, with the university later facing multiple lawsuits over the exposure. The combination of student records, health information and a potentially enormous volume of stolen data makes this more significant than a routine university breach notice.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-625770",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Public Sector and Education",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "North Los Angeles County Regional Center",
          "breached_entity": null,
          "date": "Nov 2024",
          "disclosed": "2026-06-30",
          "group": "3061b4c6-6c83-4a97-8f6c-b5c5184bcd5f",
          "slug": null,
          "is_primary": true,
          "detail": "The North Los Angeles County Regional Center disclosed a ransomware attack affecting approximately 298,600 individuals. The compromised information reportedly included combinations of names, Social Security numbers, medical information, health insurance information and other personal data relating to individuals receiving developmental disability services. The organization stated that attackers accessed and copied files before encrypting systems. Given the size of the affected population and the sensitivity of the data, this represents one of the larger healthcare-related disclosures of the year.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-625748",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Kubota North America Corporation",
          "breached_entity": null,
          "date": "Mar 2026",
          "disclosed": "2026-06-30",
          "group": "8448380c-adbe-415f-9f0f-98df3b9a855e",
          "slug": null,
          "is_primary": true,
          "detail": "Kubota North America disclosed that attackers accessed portions of its network and obtained employee human resources information after maintaining access for several weeks. The compromised information reportedly included Social Security numbers, driver's license information, direct deposit details, benefits information and other employment records affecting employees and their dependents.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-625723",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Manufacturing",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Sierra Management Group",
          "breached_entity": null,
          "date": "Jun 2026",
          "disclosed": "2026-06-29",
          "group": "1b1704a2-46e4-41a6-afad-f486bf95b505",
          "slug": null,
          "is_primary": true,
          "detail": "Sierra Management Group, a healthcare practice management provider, disclosed a ransomware attack after attackers reportedly accessed its network for several months. Public reporting indicates the incident affected approximately 38,900 individuals, while the ransomware group claimed to have stolen roughly 100 GB of information. Because Sierra provides management services for medical practices, the breach may affect patients across multiple healthcare organizations. The full scope of the impacted practices has not yet been publicly detailed.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-625681",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Nissan North America Inc.",
          "breached_entity": null,
          "date": "May 2026",
          "disclosed": "2026-06-26",
          "group": "c02648b1-7679-4aca-b63c-c7e4a82f9e53",
          "slug": null,
          "is_primary": true,
          "detail": "Nissan North America disclosed a newer incident involving its Oracle PeopleSoft environment, which is used to maintain employee payroll and human-resources information. Potentially exposed records reportedly included Social Security numbers, banking information, tax information and other employment data belonging to current and former workers. This follows Nissan’s separate 2023 breach affecting more than 53,000 people, which resulted in a $1.5 million proposed class-action settlement in 2026.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-625558",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Manufacturing",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Yellow Corporation",
          "breached_entity": null,
          "date": "Mar 2025",
          "disclosed": "2026-06-26",
          "group": "5f0e26cf-765c-4f1c-98aa-15ef93d165b7",
          "slug": null,
          "is_primary": true,
          "detail": "Yellow Corporation disclosed a data breach affecting approximately 13,000 current and former employees and dependents after the company had already entered bankruptcy proceedings. The compromised information reportedly included Social Security numbers, financial account information, government identification and health insurance information. Although the incident is modest in size compared to other breaches, it raises unique challenges because victims are seeking assistance from a company that has largely ceased operations. The disclosure demonstrates that cybersecurity obligations continue even after a company's business has ended.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-625494",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Transportation and Logistics",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Mercor.io Corporation",
          "breached_entity": null,
          "date": "Mar 2026",
          "disclosed": "2026-06-25",
          "group": "31867e09-e37a-4c79-802a-3182617f5c82",
          "slug": null,
          "is_primary": true,
          "detail": "Mercor disclosed a breach tied to the compromise of its LiteLLM environment that reportedly exposed candidate records, interview videos, source code, API keys and internal communications. Public reporting has alleged that hundreds of gigabytes of applicant data and multiple terabytes of interview recordings and other company information were involved, although Mercor has not confirmed those figures. The incident is notable because it potentially impacts both job candidates and the AI supply chain supporting enterprise customers. Multiple class action lawsuits have already been filed.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-625431",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Technology and Software",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "AgelessRx",
          "breached_entity": null,
          "date": "Jun 2026",
          "disclosed": "2026-06-24",
          "group": "175d174e-08ca-4177-ae5a-d77a0180f35e",
          "slug": "agelessrx-2026-06-24",
          "is_primary": true,
          "detail": "Ageless RX experienced a data loss through their help desk system after bad actors gained access to it from April 17 to April 22, 2026. Ageless RX reported the breach in late June with no details on how many patient records were exposed. As with many of these incidents in healthcare, the only evidence of the incident beyond the filing are services being offered by the legal community to sue the breached healthcare company.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-625334",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Xsolis, Inc.",
          "breached_entity": null,
          "date": "Jan 2026",
          "disclosed": "2026-06-19",
          "group": "a1d82bc9-a9e4-4682-824a-b3a44ac4a8ca",
          "slug": null,
          "is_primary": true,
          "detail": "Healthcare technology provider Xsolis disclosed a phishing-related breach affecting approximately 1.4 million individuals, making it one of the largest healthcare data breaches reported in 2026. The company provides AI-powered utilization management and revenue cycle services to hospitals and health systems, meaning many affected patients had likely never heard of Xsolis despite their information being entrusted to the company by their healthcare providers. The compromised data reportedly included names, dates of birth, Social Security numbers, health insurance information and medical treatment information, impacting patients from organizations including Mayo Clinic, UW Medicine, VHC Health and numerous other healthcare systems.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-625166",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Lansing Community College",
          "breached_entity": null,
          "date": "Feb 2025",
          "disclosed": "2026-06-05",
          "group": "fcb4a8d6-e8c9-4e5d-9270-4a84970e0350",
          "slug": null,
          "is_primary": true,
          "detail": "Lansing Community College disclosed that hackers used compromised credentials to access systems containing information on approximately 174,307 people. The affected population included current and former students, prospective students, employees, vendors and others whose information had accumulated in college systems. Exposed data reportedly included names, addresses, dates of birth, Social Security numbers and driver’s-license information. The college discovered the incident in February 2025 but did not begin broad notification until more than a year later.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-624467",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Public Sector and Education",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Mariner Wealth Advisors, LLC",
          "breached_entity": null,
          "date": "Nov 2025",
          "disclosed": "2026-06-01",
          "group": "1ebe4a15-3c19-4bc9-902f-cd2b8b1ec585",
          "slug": null,
          "is_primary": true,
          "detail": "Mariner Wealth Advisors disclosed that approximately 8,995 individuals were affected after attackers gained access to cloud-based accounts used by several employees. The exposed information reportedly included names, Social Security numbers, dates of birth and certain financial account information, although the firm stated that its core investment platforms were not compromised. Notifications were issued several months after suspicious activity was first detected.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-624233",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Lumexa Imaging",
          "breached_entity": null,
          "date": "Mar 2026",
          "disclosed": "2026-06-12",
          "group": "a563a045-279a-48fc-ad45-fc685336f0d6",
          "slug": null,
          "is_primary": true,
          "detail": "Lumexa Imaging disclosed that unauthorized access to a third-party vendor environment resulted in patient information being exposed. Lumexa operates more than 180 imaging centers across 13 states, making the potential downstream impact significant even though the total number of affected patients has not yet been publicly confirmed. The compromised information reportedly included patient documents associated with diagnostic imaging services. The incident illustrates the continuing cybersecurity risks posed by third-party service providers in healthcare.",
          "detail_kind": "summary",
          "source": "Washington AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41314.pdf",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Columbia Pacific Advisors, LLC",
          "breached_entity": null,
          "date": "Nov 2025",
          "disclosed": "2026-06-12",
          "group": "19609ae2-a2ec-4f1f-98e7-880bfbfb28ad",
          "slug": null,
          "is_primary": true,
          "detail": "Columbia Pacific Advisors experienced a breach and data exfiltration event that may include a combination of certain individuals’\r\nnames, Social Security number, date of birth, driver’s license, passport number, US alien registration number, financial account information, taxpayer identification, number, system access information, health insurance information, and medical information. The numbers of patient records and the methods through which Columbia Pacific Advisors were breached have not been disclosed.",
          "detail_kind": "summary",
          "source": "Washington AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41309.pdf",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Healthplex",
          "breached_entity": null,
          "date": "Mar 2023",
          "disclosed": "2023-03-26",
          "group": "d3e834ef-b467-48ac-8371-e5675f76cb9f",
          "slug": null,
          "is_primary": true,
          "detail": "Healthplex’s phishing incident exposed the personal and health information of approximately 89,955 people, including nearly 64,000 New York residents. The attacker gained access to an employee mailbox containing more than 100,000 emails accumulated over roughly 20 years, while the company lacked both an effective retention policy and required multifactor authentication. Healthplex ultimately paid $400,000 to the New York attorney general and another $2 million to the New York Department of Financial Services. This is a useful impact example because the consequences are established: tens of thousands of victims, years of unnecessary data retention and $2.4 million in regulatory penalties.",
          "detail_kind": "summary",
          "source": "NYDFS cybersecurity enforcement action",
          "source_type": "state_ag",
          "source_url": "https://www.dfs.ny.gov/industry-guidance/enforcement-discipline/ea20250814-healthplex",
          "enforcement": {
            "amount_usd": 2000000,
            "original": "$2,000,000",
            "source": "New York Department of Financial Services",
            "url": "https://www.dfs.ny.gov/reports_and_publications/press_releases/pr20250814?utm_source=chatgpt.com"
          },
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "HealthPlex",
          "breached_entity": null,
          "date": "Jul 2023",
          "disclosed": null,
          "group": "d3e834ef-b467-48ac-8371-e5675f76cb9f",
          "slug": null,
          "is_primary": false,
          "detail": "NYDFS found Healthplex violated multiple provisions of its Cybersecurity Regulation (23 NYCRR Part 500), including failures to implement multifactor authentication, maintain an appropriate data retention policy, timely report the incident within 72 hours, and accurately certify regulatory compliance. The settlement also required Healthplex to retain an independent auditor to review its MFA controls.",
          "detail_kind": "summary",
          "source": "New York Department of Financial Services",
          "source_type": "regulatory_action",
          "source_url": "https://www.dfs.ny.gov/reports_and_publications/press_releases/pr20250814?utm_source=chatgpt.com",
          "enforcement": {
            "amount_usd": 2000000,
            "original": "$2,000,000",
            "source": "New York Department of Financial Services",
            "url": "https://www.dfs.ny.gov/reports_and_publications/press_releases/pr20250814?utm_source=chatgpt.com"
          },
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": null,
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "HEALTHSTREAM INC",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-07-29",
          "group": "f022df0f-535f-4fea-a8b5-ce273b8516ce",
          "slug": null,
          "is_primary": true,
          "detail": "HealthStream's cloud platforms stayed up and intact, which was never where the data went missing. The intrusion landed on the corporate file servers, where copies of credentialing data for roughly 75 customers sat staged for conversion, troubleshooting, and analytics, alongside employee and billing records. No actor has surfaced and no files were encrypted; the exposure came not through the product but through the copies the product was never meant to spawn.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1095565/000143774926024890/hstm20260729_8k.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Technology and Software",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "ANALOG DEVICES INC",
          "breached_entity": null,
          "date": "Jun 2026",
          "disclosed": "2026-07-29",
          "group": "a32ca6e7-5158-4070-8596-d3aa36f64427",
          "slug": null,
          "is_primary": true,
          "detail": "Analog Devices lost files from its systems on June 23, 2026, and disclosed neither the door the intruders came through nor the data they carried out. The only count belongs to the people who took it: the extortion group ExfilSquad claims about 570,000 records of customer names and home addresses, a figure the company holds at arm's length as a separate, unverified matter. A breach described only by its thieves is confirmed without being explained.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/6281/000119312526324223/d158253d8k.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Technology and Software",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Clinical Registry Solutions",
          "breached_entity": null,
          "date": "Apr 2026",
          "disclosed": "2026-07-29",
          "group": "8bfebed2-6dfa-48c1-88e0-032ed687d5dc",
          "slug": null,
          "is_primary": true,
          "detail": "Clinical Registry Solutions confirmed unauthorized network access and acquisition of files containing St. Mary's patient information. ",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-627300",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Sunrise Company",
          "breached_entity": null,
          "date": "Apr 2026",
          "disclosed": "2026-07-28",
          "group": "fbe62d84-e76b-46f2-806a-612455013b80",
          "slug": null,
          "is_primary": true,
          "detail": "Sunrise Company determined that an unauthorized actor acquired files from its network after suspicious activity was detected. Once an attacker can move from presence to acquisition, the system has failed at more than prevention; it has failed to constrain what unauthorized access can do. Good security assumes compromise happens and designs the blast radius accordingly.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-627296",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Real Estate and Construction",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "DentaQuest, LLC",
          "breached_entity": null,
          "date": "May 2026",
          "disclosed": "2026-07-16",
          "group": "f2970448-8460-4d97-bbb8-ce4fcc474221",
          "slug": null,
          "is_primary": false,
          "detail": "Washington AG notification: a social-engineering attack that tricked a single DentaQuest employee into surrendering network credentials and an MFA code let a threat actor access and exfiltrate data from a DentaQuest file share between May 17 and May 19, 2026; the data was posted to the dark web on May 29. Exposed information included names, dates of birth, Social Security numbers, Medicare and Medicaid ID numbers, health-plan numbers, and dental/vision diagnosis, treatment, and billing details. DentaQuest reports at least 91,700 Washington residents affected and more than 15 million individuals nationwide, with two years of credit monitoring offered.",
          "detail_kind": "summary",
          "source": "Washington AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41829.pdf",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": null,
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "1Life Healthcare, Inc. (One Medical, Iora Health)",
          "breached_entity": null,
          "date": "Jun 2026",
          "disclosed": "2026-07-03",
          "group": "75cc249a-3479-43d2-8b6d-377bda1104e0",
          "slug": null,
          "is_primary": true,
          "detail": "One Medical disclosed unauthorized access to a third-party file-storage system containing archived patient information from its legacy Seniors business. Archived data is still data and data is valuable to the adversary. Data outlives applications, vendors and acquisitions; security architectures need to assume that every retained copy remains part of the attack surface.",
          "detail_kind": "summary",
          "source": "Washington AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41592.pdf",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "AMGEN INC",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-07-31",
          "group": "afb9d2b3-676e-4e88-a43f-d77b6d016d5c",
          "slug": null,
          "is_primary": true,
          "detail": "The files that left Amgen never sat on Amgen's network: patient health records, research, and intellectual property lived in third-party cloud storage, and that is where the theft happened. The company has named no vendor, no access path, and no count of the people exposed, the standard silence of a breach whose front door belongs to someone else. When the perimeter is a contract with a cloud provider, the forensics begin on property the victim never controlled.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/318154/000031815426000119/amgn-20260729.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Stanislaus County Health Services Agency",
          "breached_entity": "Aesto",
          "date": "Dec 2025",
          "disclosed": "2026-07-31",
          "group": "dec3ccef-a051-4e08-bcf8-c3f8a8ce7e38",
          "slug": "aesto-2026-07-31",
          "is_primary": true,
          "detail": "Stanislaus County Health Services Agency was exposed through Aesto, the vendor that stored healthcare data in Amazon Web Services. An unauthorized actor may have accessed or acquired protected health information during the vendor's network incident. The county did not need to be breached directly; inherited access through the vendor was enough.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-627513",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Public Sector and Education",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "JRK Property Holdings, Inc.",
          "breached_entity": null,
          "date": "Mar 2026",
          "disclosed": "2026-07-27",
          "group": "9931ea13-780d-45b6-90a3-9dec9d5f6894",
          "slug": null,
          "is_primary": true,
          "detail": "JRK Property Holdings reported unauthorized activity in its IT environment and potential access to sensitive files, with the event tied in public reporting to extortion activity. The extortion is the business model layered on top of the real failure: the attacker obtained enough access to make stolen data useful as leverage. Once unauthorized access can become durable access, the attacker gets to decide what the incident becomes next.",
          "detail_kind": "summary",
          "source": "Washington AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42008.pdf",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Real Estate and Construction",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Nelson University",
          "breached_entity": null,
          "date": "Mar 2025",
          "disclosed": "2026-06-15",
          "group": "ff72324b-4ea7-4e7e-b4c0-da6369954c68",
          "slug": null,
          "is_primary": true,
          "detail": "Nelson University determined that an unauthorized actor had access to its systems for roughly two weeks, with sensitive identity and financial information implicated and later reporting connecting the event to ransomware. The lesson is not that universities need another awareness campaign; it is that unauthorized access was able to persist long enough to become consequential. Systems built around static trust are always giving attackers time they did not earn.",
          "detail_kind": "summary",
          "source": "Washington AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41330.pdf",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Public Sector and Education",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "IEH Corp",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-06",
          "group": "862393e6-f516-4f8b-80b1-da765159877d",
          "slug": null,
          "is_primary": true,
          "detail": "The entire compromise was one employee's Microsoft 365 mailbox, opened by a phishing page that harvested a password because credentials were the only lock on the door. Inside sat purchase orders, engineering documentation, and potentially export-controlled technical data tied to the THAAD and Patriot programs: defense secrets kept in an ordinary inbox. No actor has been named and no theft confirmed, but the exposure was set long before the phishing page loaded. A missile-parts maker had filed regulated engineering where a single stolen login could reach it.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/50292/000117494726000761/form8k-36187_iehc.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Manufacturing",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Station Casinos, LLC",
          "breached_entity": null,
          "date": "Mar 2026",
          "disclosed": "2026-08-05",
          "group": "e3c0443d-93e4-4e68-a51d-ab24ff90eb38",
          "slug": null,
          "is_primary": true,
          "detail": "Station Casinos reported an external system breach involving unauthorized access and sensitive personal information. The interesting security question is not whether the company offered identity protection afterward; it is why unauthorized access was able to reach data worth protecting in the first place. Breach response happens after the architecture has already made its most important decision about trust.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-627764",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "New York City Regional Center, LLC",
          "breached_entity": null,
          "date": "Mar 2026",
          "disclosed": "2026-08-05",
          "group": "dc28265a-7375-4717-b68a-cf9162ab783e",
          "slug": "new-york-city-regional-center-llc-2026-08-05",
          "is_primary": true,
          "detail": "New York City Regional Center confirms a cybersecurity incident involving personal information, but says Massachusetts law prevents it from describing the nature of the event. That is enough to classify the event as cyber, but not enough to explain the failed control or the scope of access. The uncertainty belongs in the record rather than being filled with attack-story assumptions.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-627755",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Public Sector and Education",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "LEVI STRAUSS & CO",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-07",
          "group": "f13b70a4-64d3-479c-9c2a-1854f6e2e3b8",
          "slug": null,
          "is_primary": true,
          "detail": "Levi Strauss disclosed that social engineering led to unauthorized access to three employee computers and the exfiltration of corporate files. The attacker did not need to defeat the whole enterprise; a few trusted endpoints were enough to turn legitimate access paths into a data-extraction path. When trust follows the user and device automatically, compromising either can inherit far more authority than the attacker ever earned.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/94845/000199937126017264/levi-8k_080726.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Cushman & Wakefield",
          "breached_entity": null,
          "date": "Apr 2026",
          "disclosed": "2026-08-07",
          "group": "5c5d980b-776d-4e09-b0bd-b24ac60b938e",
          "slug": null,
          "is_primary": true,
          "detail": "Cushman & Wakefield says a vishing attack opened the door to unauthorized activity in its environment. The incident was described as limited, but social engineering that produces unauthorized system access is still a cyber incident and the event was significant enough to trigger mandatory reporting to the California AG. ",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-627946",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Real Estate and Construction",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Eyemart Express, LLC",
          "breached_entity": null,
          "date": "Feb 2026",
          "disclosed": "2026-07-24",
          "group": "3a6cf45c-fcdb-47ec-bb19-73009b240b9e",
          "slug": null,
          "is_primary": true,
          "detail": "Eyemart Express confirmed a February cyberattack that exposed customer information ranging from identity data to vision and insurance records. ",
          "detail_kind": "summary",
          "source": "Washington AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41958.pdf",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "The Estée Lauder Companies",
          "breached_entity": "Oracle",
          "date": "Aug 2025",
          "disclosed": "2026-07-17",
          "group": "653ff9a5-93b3-4b26-af8c-455e7c02a9bf",
          "slug": null,
          "is_primary": true,
          "detail": "Estée Lauder determined that an unauthorized third party gained access to its Oracle E-Business Suite environment and obtained employee-related personal information. The data set reportedly included the identity, financial, health and employment ingredients attackers leverage for future fraud and social engineering campaigns. ",
          "detail_kind": "summary",
          "source": "Washington AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41847.pdf",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "USA DeBusk LLC",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-07-07",
          "group": "8d799193-b869-4b59-985e-c56bb6b40606",
          "slug": "usa-debusk-llc-2026-07-07",
          "is_primary": true,
          "detail": "USA DeBusk says an unauthorized third party accessed its systems and obtained a broad mix of identity, financial, credential, and health information. The range of data suggests that compromise of the environment crossed several information boundaries at once. The notice confirms the result but provides little evidence that those data types were meaningfully segmented before the incident.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-628082",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Professional and Business Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Kovack Financial, LLC",
          "breached_entity": null,
          "date": "Aug 2025",
          "disclosed": "2026-08-10",
          "group": "6fcf3b27-3324-48e0-97c9-a0ab0a0f0998",
          "slug": null,
          "is_primary": true,
          "detail": "Kovack reported unauthorized access involving email and sensitive personal information. Kovack took almost a full year to determine that it was necessary to contact their customers, even though they clearly acknowledge in their filing that they discovered the breach on 8/28/2025. The customer comes first, right?",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-628054",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Boston Healthcare for the Homeless Program",
          "breached_entity": null,
          "date": "Oct 2025",
          "disclosed": "2026-08-07",
          "group": "679288a7-463f-4016-a911-90c1bbb68029",
          "slug": null,
          "is_primary": true,
          "detail": "Boston Health Care for the Homeless Program disclosed that patient information was affected through a cybersecurity incident at a third-party provider. The infrastructure may have belonged to someone else, but the risk did not. Third-party architecture is still an attack surface when your data and your patients absorb the consequences.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-627990",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Grant County Public Hospital District #2",
          "breached_entity": "Aesto",
          "date": "Dec 2025",
          "disclosed": "2026-08-04",
          "group": "6f6e44ad-5c6a-4a57-99b7-2959b66f8226",
          "slug": "grant-county-public-hospital-district-2-2026-08-04",
          "is_primary": true,
          "detail": "Grant County's patient data lived inside Aesto Health's AWS infrastructure, one vendor holding records for at least two dozen hospital clients at once. Hackers moved through that shared environment for sixteen days in December 2025, pulling names, Social Security numbers, driver's license numbers, financial accounts, and medical and insurance details, all told, touching 9.5 million people. The source names no entry point and no attacker; what it names instead is the design, one cloud tenancy standing in as the perimeter for two dozen separate hospitals. Concentration isn't efficiency when a single vendor breach becomes two dozen hospital breaches wearing one name.",
          "detail_kind": "summary",
          "source": "Washington AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42154.pdf",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Microcode, Inc.",
          "breached_entity": "CommonSpirit Health",
          "date": "Jan 2026",
          "disclosed": "2026-07-30",
          "group": "cdbff05b-d60e-403f-846b-c4483230eba0",
          "slug": "commonspirit-health-2026-07-30",
          "is_primary": true,
          "detail": "MicroCode experienced ransomware on a server that hosted CommonSpirit Health's tracking database and documents. Unauthorized access lasted for months, but the investigation could not confirm whether the data was viewed or taken. The uncertainty should be preserved: this is a confirmed system compromise with sensitive data in scope, not a confirmed exfiltration.",
          "detail_kind": "summary",
          "source": "Washington AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42069.pdf",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Technology and Software",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Universal Plant Services, LLC",
          "breached_entity": null,
          "date": "Jun 2026",
          "disclosed": "2026-08-12",
          "group": "ebde0944-5a77-424b-ae7b-eb8148cec266",
          "slug": "universal-plant-services-llc-2026-08-12",
          "is_primary": true,
          "detail": "Universal Plant Services found an unauthorized individual inside its network for several days with access to identity, license, and financial-account information. The notice says passwords were reset and accounts secured after discovery, but does not explain the entry path. The control question is why access to one network segment could reach several forms of high-value identity data.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-628163",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Manufacturing",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "American Addiction Centers",
          "breached_entity": "Salesforce",
          "date": "May 2026",
          "disclosed": "2026-08-07",
          "group": "a05cb47a-2e64-4c73-af60-44cb41fed395",
          "slug": "salesforce-2026-08-07",
          "is_primary": true,
          "detail": "American Addiction Centers lost data through its Salesforce environment, not its health-records application or internal network. Names, Social Security numbers, and brief health descriptions were still reachable because the outreach system had become another sensitive-data store. The boundary held around the clinical system and failed around the SaaS platform that the business trusted beside it.",
          "detail_kind": "summary",
          "source": "Washington AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42250.pdf",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Bridgeway Benefit Technologies LLC",
          "breached_entity": null,
          "date": "Mar 2026",
          "disclosed": "2026-07-24",
          "group": "697ae34d-eba5-4c96-abe0-bb31ec2d7d74",
          "slug": "bridgeway-benefit-technologies-llc-2026-07-24",
          "is_primary": true,
          "detail": "Bridgeway traced the incident to a suspected employee email compromise that opened access to its systems from March to May. Benefit-plan participant data, including Social Security numbers for some people, may have been involved. Email identity was the security boundary. When that identity failed, the access lasted far longer than the initial deception.",
          "detail_kind": "summary",
          "source": "Washington AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41982.pdf",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Columbia Machine, Inc.",
          "breached_entity": null,
          "date": "Mar 2026",
          "disclosed": "2026-07-09",
          "group": "cbb59e78-2815-4b84-902c-1ccf16c2c43e",
          "slug": "columbia-machine-inc-2026-07-09",
          "is_primary": true,
          "detail": "Columbia Machine confirmed unauthorized network access and file theft, then initially concluded that only non-confidential documents were involved. A later review found additional copied files containing personal information. The incident exposed a familiar weakness: the company could see files leave before it could reliably say what those files meant.",
          "detail_kind": "summary",
          "source": "Washington AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41690.pdf",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Manufacturing",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Quantum Health, Inc.",
          "breached_entity": null,
          "date": "May 2026",
          "disclosed": "2026-08-14",
          "group": "e5ef826e-5eeb-47a7-bd7f-b250e41ad4fe",
          "slug": "quantum-health-inc-2026-08-14",
          "is_primary": true,
          "detail": "A vishing call caused a Quantum Health user to open the door to the network, followed by several days of access, a service outage, and file acquisition. The exposed data included insurance, medical, and other personal information. The call was the trigger; the larger failure was letting one user interaction carry enough authority access the systems and records at that scale.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-628342",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Paylogix, LLC",
          "breached_entity": null,
          "date": "Nov 2025",
          "disclosed": "2026-08-14",
          "group": "6ccb9eed-e434-4053-9bef-b47df6408e87",
          "slug": null,
          "is_primary": true,
          "detail": "Unauthorized actors accessed Paylogix systems and copied files from its network during a multi-day intrusion. Paylogix itself calls it a cyber event, saving the time needed to translate \"we believe that our systems were accessed but don't think anything was taken\".",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-628329",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Baylor Genetics",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-14",
          "group": "b13e93c2-5646-459d-bfe1-8ef885fa28af",
          "slug": "baylor-genetics-2026-08-14",
          "is_primary": true,
          "detail": "Baylor Genetics found an unauthorized third party inside part of its network for about a week with access to stored data. The breach exposed the sensitive personal and medical data of over 248,430 individuals. Clearly, a genetics company can't make a patient whole if their genetic information was stolen. ts a 1-of-1 kind of thing. The notice confirms the access but leaves the entry path and exact acquisition uncertain.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-628324",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "See’s Candies, Inc.",
          "breached_entity": null,
          "date": "Apr 2026",
          "disclosed": "2026-08-13",
          "group": "ce3c35da-82a5-4086-b3f8-f555c1a44f2f",
          "slug": "see-s-candies-inc-2026-08-13",
          "is_primary": true,
          "detail": "See's Candies says an unauthorized user accessed its network, encrypted files, and took data that later appeared on the dark web. The compromise reached both operations and personal information, turning one network foothold into disruption and disclosure. Encryption was the visible event; broad access to the underlying files was the structural failure.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-628237",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Langwasser & Company CPAs",
          "breached_entity": null,
          "date": "May 2026",
          "disclosed": "2026-08-17",
          "group": "f7234da5-e8f4-4100-a219-c95bf0e24f11",
          "slug": "langwasser-company-cpas-2026-08-17",
          "is_primary": true,
          "detail": "Langwasser & Company learned that unauthorized tax returns had been filed for some clients, and its investigation found that an unauthorized actor may have accessed personal information. The notice cannot establish the full extent of access. The incident shows identity data doing double duty as both a record and an authentication mechanism: once exposed, it could be used to impersonate the taxpayer.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-628389",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Professional and Business Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Forrestall CPAs LLC",
          "breached_entity": null,
          "date": "Dec 2025",
          "disclosed": "2026-08-17",
          "group": "6590e51f-54fb-4588-87c7-e1ec63b191a7",
          "slug": "forrestall-cpas-llc-2026-08-17",
          "is_primary": true,
          "detail": "A tax firm is an identity warehouse by design, and Forrestall CPAs left an intruder inside its network for roughly a week, from December 22 to 30, reading and taking files that nothing inside kept apart. What left was the full identity kit: Social Security numbers, driver's licenses, financial accounts, dates of birth. The firm has confirmed 218 residents in Massachusetts and left the national count blank. How the door opened, and why a week passed before anyone noticed, the notice does not say.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-628368",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Professional and Business Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Turner Construction Company",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-08-18",
          "group": "a08397b2-2a62-4d6a-a1c0-92c638244bb6",
          "slug": "turner-construction-company-2026-08-18",
          "is_primary": true,
          "detail": "Turner Construction found unauthorized access to its systems over nearly two weeks and confirmed that files containing payroll, banking, identity, and address information were reached. The exposure crossed data categories that should not have needed to share one compromise path. Credit monitoring deals with downstream risk; segmentation and constrained authority would have dealt with the cause.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-628438",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Real Estate and Construction",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "ZenPatient, Inc.",
          "breached_entity": null,
          "date": "Dec 2025",
          "disclosed": "2026-07-17",
          "group": "b462649b-1eec-436b-85a5-ad42a5e2c7fd",
          "slug": "zenpatient-inc-2026-07-17",
          "is_primary": true,
          "detail": "ZenPatient found that an unauthorized actor had access to or copied data over a period lasting more than two months. The notice does not explain how the actor entered or why the activity persisted that long. The important fact is not that an attacker was patient; it is that the environment allowed patience to work.",
          "detail_kind": "summary",
          "source": "Washington AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41853.pdf",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "The Washington Post",
          "breached_entity": "Oracle",
          "date": "Jul 2025",
          "disclosed": "2026-07-13",
          "group": "a9c5e014-a083-477d-b886-1beb1fba3d9a",
          "slug": "oracle-2026-07-13",
          "is_primary": true,
          "detail": "The Washington Post was compromised through a previously unknown vulnerability in Oracle E-Business Suite, allowing data to be accessed and acquired over roughly six weeks. The software flaw was Oracle's, but the exposure came from the authority and data concentrated behind that application. A shared platform vulnerability became a direct path into each customer's retained records.",
          "detail_kind": "summary",
          "source": "Washington AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41741.pdf",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Media and Entertainment",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Silver Summit Medical Corporation",
          "breached_entity": null,
          "date": "Nov 2025",
          "disclosed": "2026-08-19",
          "group": "6e3114d9-3417-4ed6-b8c9-68a6de5eb171",
          "slug": "silver-summit-medical-corporation-2026-08-19",
          "is_primary": true,
          "detail": "Silver Summit Medical Corporation was pulled into a breach through a vendor that held its patient information. Data was acquired from the vendor's systems without authorization, although the notice does not name the vendor or explain the access path. Outsourcing the system moved the control point, not the exposure. The specific vendor was not named.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-628483",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Apple American Group LLC",
          "breached_entity": null,
          "date": "Apr 2026",
          "disclosed": "2026-08-18",
          "group": "b694daa5-1a5a-42c2-803a-d0954323b7e4",
          "slug": "apple-american-group-llc-2026-08-18",
          "is_primary": true,
          "detail": "Apple American Group, parent group of Applebee's,  found that an unknown actor accessed company servers and employee files during a two-day window in April. The notice does not explain the entry point. Monitoring services address the aftermath; they do not explain why one server compromise could reach the files. Clearly, Apple American Group would like the data back in its neighborhood. ",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-628449",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Apollo Management Holdings, L.P.",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-08-20",
          "group": "5417b922-8f27-4ba9-b8dd-918edd1cc4b4",
          "slug": "apollo-management-holdings-l-p-2026-08-20",
          "is_primary": true,
          "detail": "A social-engineering attack gave an unauthorized party access to Apollo cloud platforms for several days. Personal data, including Social Security numbers, was potentially exposed. A cloud trust model was defeated with one single successful call or message.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-628551",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Nebraska Orthopaedic Center, P.C.",
          "breached_entity": "Aesto",
          "date": "Dec 2025",
          "disclosed": "2026-08-20",
          "group": "025c3e98-1dd5-442b-90ff-e0b4c41a3dae",
          "slug": "aesto-2026-08-20",
          "is_primary": true,
          "detail": "Nebraska Orthopaedic Center was exposed through Aesto, the vendor holding its patient data in Amazon Web Services. An unauthorized actor copied protected health information, including identifiers that may include Social Security numbers. The trust boundary sat with the vendor, but the consequences fell right on top of the patients and the provider.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-628538",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "ZeroStack Corp.",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-21",
          "group": "1dea64be-b128-4bc4-8cf2-faeb9ed72180",
          "slug": "zerostack-corp-2026-08-21",
          "is_primary": true,
          "detail": "ZeroStack Corp. disclosed a material cybersecurity incident under Item 8.01 (other events), not as a 1.05 (material incident), and the filing states nothing further: no entry point, no actor, no data type, no scope. That silence is itself the finding, since a disclosure obligation triggered by materiality has been met while the architecture that produced the exposure remains hidden. A filing can satisfy the law without telling anyone what actually failed.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1790169/000106299326004559/form8k.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Wholesale and Distribution",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Kern Psychiatric Health and Wellness Center, Inc",
          "breached_entity": "Genesis Healthcare Management",
          "date": "Apr 2026",
          "disclosed": "2026-08-21",
          "group": "a4d8d588-c96d-4b10-8f9e-d5cb3d8cbe10",
          "slug": "aetos-2026-08-21",
          "is_primary": true,
          "detail": "Kern Psychiatric Health and Wellness Center's patient data was exposed not on its own systems but on the network of Genesis Healthcare Management, the outsourced management company that discovered unauthorized file access on June 22, 2026. The data was among the most sensitive a person holds, Social Security numbers alongside diagnoses, prescriptions, and treatment records. Outsourcing the back office moved those records to a network the practice did not run.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-628704",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "ASOS US Sales LLC",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-08-21",
          "group": "efbffb99-38ac-48a0-939d-b327551fe718",
          "slug": "asos-us-sales-llc-2026-08-21",
          "is_primary": true,
          "detail": "ASOS traced unauthorized account access to credentials stolen in a different company's breach and reused against it. Nothing in ASOS's systems was breached; a valid credential was just presented by the adversary. Password-only authentication inherits every leak that credential ever appeared in, and the system just works as designed after it is leveraged.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-628646",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Southern Illinois University",
          "breached_entity": "Oracle",
          "date": "Sep 2025",
          "disclosed": "2026-08-20",
          "group": "9c93982a-b4b6-4b54-9e24-5a23346b6365",
          "slug": "oracle-2026-08-20",
          "is_primary": true,
          "detail": "Southern Illinois University tied a data exposure to its Oracle E-Business Suite environment, with files open to unauthorized access for five weeks in mid-2025 and confirmed only in July 2026. The flaw was Oracle's; the exposure was SIU's. You can outsource the software, but not the risk it carries into your own data.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-628638",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Public Sector and Education",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Northern Inyo Healthcare District d/b/a Northern Inyo Hospital",
          "breached_entity": "Aesto",
          "date": "Dec 2025",
          "disclosed": "2026-08-20",
          "group": "e28363a7-7460-45d9-bc01-84133fe6fbac",
          "slug": "aesto-2026-08-20-2",
          "is_primary": true,
          "detail": "Northern Inyo Hospital was exposed through Aesto, the vendor holding its patient records in AWS, where a network incident ran two weeks in December 2025. The hospital handed Aesto the job of holding the records; it could not hand off the duty to protect them. Outsourcing proved the work can move, the risk stayed where the patients are.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-628598",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "POLAM Federal Credit Union",
          "breached_entity": null,
          "date": "May 2025",
          "disclosed": "2026-08-21",
          "group": "0853bc06-e3da-4eb4-b3ea-86d219bb92c1",
          "slug": "polam-federal-credit-union-2026-08-21",
          "is_primary": true,
          "detail": "POLAM Federal Credit Union's filing to the California Attorney General names a May 2025 breach and nothing else - no entry point, no actor, no data type, no count. Fifteen months between incident and disclosure is itself a problem. Providing zero details but offering every impact customer yet another round of free credit monitoring suggest that transparency isn't a requirement anyone is holding POLAM accontable for.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-628736",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Nutex Health Inc.",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-24",
          "group": "754c1841-00e4-466d-9663-b1bcbcc92e6e",
          "slug": "nutex-health-inc-2026-08-24",
          "is_primary": true,
          "detail": "Nutex Health's servers were accessed and drained by an unnamed third party sometime before the August 24, 2026 filing.  The entry point unstated, the count unstated, the haul spanning patient, employee, provider, and financial records in one undifferentiated pull. A vague reference to \"unauthorized activity involving data stored\" on their network. Data didn't steal your data, the adversary did.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1479681/000162828026058606/nutx-20260824.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Professional and Business Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Museum Associates d/b/a Los Angeles Museum of Art",
          "breached_entity": "LACMA",
          "date": "Jul 2025",
          "disclosed": "2026-08-24",
          "group": "78836f03-1a98-45ac-a42e-57b8e0f90bab",
          "slug": "lacma-2026-08-24",
          "is_primary": true,
          "detail": "Los Angeles County Museum of Art (LACMA) discovered a breach on Monday, July 7, 2025. Then it took them until February of 2026 to figure out what go stolen (LACMA, Louvre much?). Then it took them until August 24, 2026 to post the incident with the California AG and on their on website. What's missing in the AG report? All the sensitive data types that were stolen.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-628808",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Public Sector and Education",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Livara Health Medical Group - dba SpineZone",
          "breached_entity": "Aesto",
          "date": "Dec 2025",
          "disclosed": "2026-08-25",
          "group": "8f527eac-e14e-4c60-8be1-aaf817fc1909",
          "slug": "aesto-2026-08-25-2",
          "is_primary": true,
          "detail": "SpineZone's patient records were exposed not on its own network but inside Aesto Health, the Birmingham vendor it paid to migrate and archive data into Amazon Web Services. The breach window ran from December 2 to December 18, 2025, and it took Aesto until May 2026 to confirm what protected health information had actually been taken. Names, Social Security numbers, driver's license numbers, financial account details, and full medical and billing histories moved through that one AWS account, along with the records of more than two dozen other providers' patients. SpineZone outsourced the archive; it did not outsource the liability for losing it.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-628844",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "BOSTON SCIENTIFIC CORP",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-26",
          "group": "1c652f01-27a1-44e4-ab69-4f57dd6e963f",
          "slug": "boston-scientific-corp-2026-08-26",
          "is_primary": true,
          "detail": "A cybersecurity incident on August 25, 2026, knocked out Boston Scientific's order processing and shipping worldwide. The filing names no entry point, no actor, no data type, because the investigation hasn't reached that far yet. When core operations can't survive one unnamed intrusion, the systemic fragility was built in long before the attacker showed up. Global disruption isn't the sign of a sophisticated adversary; it's the sign of a single point of failure wearing a lot of hats.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/885725/000088572526000056/bsx-20260826.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Together Women's Health LLC",
          "breached_entity": "Aesto",
          "date": "Dec 2025",
          "disclosed": "2026-08-25",
          "group": "c73d489d-486e-44a3-87c1-77e04a4723f6",
          "slug": "aesto-2026-08-25",
          "is_primary": true,
          "detail": "Together Women's Health filed its breach notice under Aesto, the same vendor whose AWS environment has already surfaced in other patients' notifications this year. The letter names Social Security numbers and two dates in December 2025, and stops there: no stated entry point, no actor, no count of people affected. A filing this thin is its own kind of disclosure. When a vendor keeps reappearing as the common thread across unrelated clinics, the failure isn't in any one exam room; it's in the shared filing cabinet everyone quietly outsourced to.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-628856",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Lennar Mortgage, LLC",
          "breached_entity": null,
          "date": "May 2026",
          "disclosed": "2026-08-14",
          "group": "4d0677c8-e182-45be-a828-f747430af3c9",
          "slug": "lennar-mortgage-llc-2026-08-14",
          "is_primary": true,
          "detail": "Lennar Corporation and Lennar Mortgage, LLC were each breached through social engineering within two months, March 24 to 30 and May 26 to June 1, 2026; Lennar reported at least 61,295 people affected, their names, Social Security numbers, government IDs, and financial data exposed. One tricked employee is not an anomaly; it is the actual perimeter, and nothing closed it between the two hits. Notice went out in August, nearly four months after the first intrusion began. That gap is its own design failure, not an oversight.",
          "detail_kind": "summary",
          "source": "Washington AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42347.pdf",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Real Estate and Construction",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "MCKESSON CORP",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-28",
          "group": "fc914792-d2b3-4d49-8e57-aae4cbb8cdc9",
          "slug": "mckesson-corp-2026-08-28",
          "is_primary": true,
          "detail": "ShinyHunters claims it vished several McKesson employees' Okta credentials, then walked those single sign-on logins straight into Salesforce and Snowflake. McKesson has not confirmed the entry point or the data taken; only the extortion group has spoken. Single sign-on was built to make log-ins easy, but when secured incorrectly (or not at all) it is just the easy button to own an entire company. The group claims roughly 284 million patient records, the kind of data no reset can undo.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 7.01",
          "source_type": "sec_8k_item_701",
          "source_url": "https://www.sec.gov/Archives/edgar/data/927653/000092765326000247/mck-20260825.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Wholesale and Distribution",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Nutex Health Inc.",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-31",
          "group": "754c1841-00e4-466d-9663-b1bcbcc92e6e",
          "slug": "nutex-health-inc-2026-08-24",
          "is_primary": false,
          "detail": "Nutex Health's own filing says only that it found unauthorized activity on its network, then points back to an earlier 8-K for the rest. No vector, no actor, no data type, no count: the filing discloses the fact of a breach while withholding the shape of one.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1479681/000162828026059602/nutx-20260831.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Professional and Business Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Bennett College",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-28",
          "group": "5b892ca8-a13f-4e7f-a094-779a9b2404d1",
          "slug": "bennett-college-2026-08-28",
          "is_primary": true,
          "detail": "Bennett College calls it a network disruption, the polite word for three weeks of unaccounted access between October 27 and November 15, 2025. The filing never names how anyone got in or who they were; it only names what sat exposed: Social Security numbers, driver's license and passport numbers, financial accounts, medical and health insurance information. A network with no stated entry point is not a mystery; it is an admission that nobody was watching the door closely enough to say which one opened. Credit monitoring 10 months after the breach will not touch the medical history or the passport number, now loose in the world.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-628990",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Public Sector and Education",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Indico Data Solutions",
          "breached_entity": null,
          "date": "May 2026",
          "disclosed": "2026-08-27",
          "group": "5bb13e2f-58a6-45b2-b28f-c29e69be7e10",
          "slug": "indico-data-solutions-2026-08-27",
          "is_primary": true,
          "detail": "Indico Data Solutions lost names, addresses, and Social Security numbers out of online file stores in May 2026; the filing does not say how someone got in, only that access was unauthorized. The company that touched this data was never the insurer a customer chose, but a back-office AI vendor that the insurer quietly handed the file to. Consent stopped at the front door; the data kept moving through vendors, and nobody was asked to approve. ",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-628947",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Insurance",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Integrated Specialty Coverages, LLC",
          "breached_entity": "“ISC”",
          "date": "Jun 2026",
          "disclosed": "2026-08-27",
          "group": "a0eca7f6-38c6-425b-9b58-45167bcf9e47",
          "slug": "isc-2026-08-27",
          "is_primary": true,
          "detail": "An unauthorized third party sat inside a limited part of ISC's environment for four days in February 2025, and the filing never says how it got in. What it took reads like a full identity kit: Social Security numbers, driver's license and government ID numbers, biometric data, and medical details tied to insurance claims. ISC administers other companies' insurance programs.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-628921",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Murfreesboro Medical Clinic",
          "breached_entity": null,
          "date": "Apr 2026",
          "disclosed": "2026-08-26",
          "group": "aec16728-53eb-496f-be0c-9485e68bb0a4",
          "slug": "murfreesboro-medical-clinic-2026-08-26",
          "is_primary": true,
          "detail": "BianLian, a ransomware group, claims it pulled records for 559,000 patients and employees off Murfreesboro Medical Clinic's network on or around April 22, 2023; the filing never says how the door opened. What exited? Names, Social Security numbers, driver's license copies, dependent data, full diagnostic and prescription histories. Bascially the entire archive of a person's medical life, sitting behind one network boundary. That is not a sophisticated breach; that is a single failure domain holding everything a person has ever told a doctor. A settlement can pay a claim; it cannot reissue a diagnosis.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-628900",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Aesto",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-24",
          "group": "9f4cfb4b-2688-495c-867c-934b31323986",
          "slug": "aesto-2026-08-24",
          "is_primary": true,
          "detail": "Aesto Health's AWS infrastructure was breached, exposing the PII and PHI of 9,540,683 people across up to 29 provider clients, from VillageMD to Monroe Health Center. The filing names no entry point and no actor, only the aggregate count. Aesto was hired to migrate and archive records; instead, it became the single failure domain for dozens of practices that never touched its cloud. One vendor's infrastructure was the perimeter for an entire health system's worth of patients.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-628809",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "NovoCure Ltd",
          "breached_entity": null,
          "date": "Sep 2026",
          "disclosed": "2026-09-01",
          "group": "86950f63-3e93-4e37-bd95-217a8139b5ba",
          "slug": "novocure-ltd-2026-09-01",
          "is_primary": true,
          "detail": "Novocure's SEC filing names no vector and no actor for the unauthorized access it discovered in mid-August 2026, only the aftermath. More than 1,400 U.S. patients had ID numbers exposed without names, while fewer than 50 in the western U.S. lost both identity and provider contact details, a split that reads like several systems failing on different terms, not one breach. Employee names, job titles, and phone numbers leaked from the same event, which the filing still frames as a story about untouched treatment devices. No devices were breached, they say; the record of who these patients are was.",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 8.01",
          "source_type": "sec_8k_item_801",
          "source_url": "https://www.sec.gov/Archives/edgar/data/1645113/000164511326000065/nvcr-20260901.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Park Dental Partners, Inc.",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-09-01",
          "group": "6f4fd5ba-bdf8-405c-be6b-908af330897a",
          "slug": "park-dental-partners-inc-2026-09-01",
          "is_primary": true,
          "detail": "Park Dental Research's systems got tied up in ransomware by the Interlock group. Employee Social Security numbers, driver's license numbers, bank account details, passports, and I-9 forms were accessed by an unauthorized party in April 2026; the notification letters never say how the door opened. Interlock claims it exfiltrated 260 gigabytes and says so plainly; yet the company's own letter and 8k filing never mentions ransomware at all. ",
          "detail_kind": "summary",
          "source": "SEC 8-K, Item 1.05",
          "source_type": "sec_8k_item_105",
          "source_url": "https://www.sec.gov/Archives/edgar/data/2069604/000110465926104300/park-20260828x8k.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Kaniksu Community Health",
          "breached_entity": "Aesto",
          "date": "Dec 2025",
          "disclosed": "2026-09-01",
          "group": "9f35d1b2-f953-46e8-a4f9-0f644e2b8a97",
          "slug": "aesto-2026-09-01",
          "is_primary": true,
          "detail": "Kaniksu Community Health's December 2025 breach ran through Aesto, the same vendor turning up again and again across this index as a single point of failure for multiple health systems. The filing names only \"personal information\": names, dates of birth, addresses, phone numbers, no Social Security numbers, no financial data, and no entry point stated. The notice suggests this is good news because nothing there opens a new account in anyone's name. Good news is relative: a name and a birthdate can't be reissued, and they don't expire.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-629145",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Berkeley Research Group, LLC",
          "breached_entity": null,
          "date": "Feb 2025",
          "disclosed": "2026-08-31",
          "group": "440cb748-6d32-41b7-ad12-c949ba1e0c86",
          "slug": "berkeley-research-group-llc-2026-08-31",
          "is_primary": true,
          "detail": "Berkeley Research Group found an intruder inside its own network between February 28 and March 2, 2025, copying files before anyone caught the motion. The notice never says how the actor got in, what was taken, or how many people it belonged to, which is its own kind of disclosure. A firm built on producing precise findings for other people's disputes can't produce one for its own breach. Eighteen months later, the silence is still the headline, not the incident.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-629096",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Professional and Business Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Virta Health Corp. and Virta Medical, PC",
          "breached_entity": null,
          "date": "Mar 2026",
          "disclosed": "2026-08-31",
          "group": "1a06f188-3d70-4cd3-80e1-aabd50215afc",
          "slug": "virta-health-corp-and-virta-medical-pc-2026-08-31",
          "is_primary": true,
          "detail": "Virta Health's compromised repository sat apart from its production platform, but unauthorized access still ran from March 19 to 22, 2026, exposing Social Security numbers, diagnoses, physician information, and medical record numbers for 14,636 people. The filing does not say how Lapsus$, the group that claimed the breach, got in. Separation from production is not isolation; the side repository still holds the whole clinical record. Lapsus$ posted Virta to its leak site on March 23, a full day before anyone at Virta noticed, which says more about who was watching than about who broke in.",
          "detail_kind": "summary",
          "source": "California AG breach notification",
          "source_type": "state_ag",
          "source_url": "https://oag.ca.gov/ecrime/databreach/reports/sb24-629093",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "V",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        }
      ]
    },
    "beyond_8k": {
      "events": [
        {
          "org": "Medtronic",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-07-01",
          "group": "3141642b-e726-4949-973b-d101a3ebe7d8",
          "slug": null,
          "is_primary": true,
          "detail": "Medtronic Notifies 3.8M Individuals About April 2026 Cyberattack.",
          "detail_kind": "summary",
          "source": "News: The HIPAA Journal",
          "source_type": "news",
          "source_url": "https://news.google.com/rss/articles/CBMifEFVX3lxTE40c1poRHVNOHZIWW9ueVN4WnJSZ2FkWUQ4UUl3Nk1INmN4T0tfeWlicWxRV2tfUDlFNE9WWkRVdVpVX2VaU1pIazV1SkFKeHl6cl94Mm1taWNiZ0lFeEl4UmpKeG52OW5PeldIYlRsS0tqN0tRczFsMXBEbkE?oc=5",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "I",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Accenture",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-07-08",
          "group": "fb9921c8-dbe7-4fd0-8211-50c9bb5deabd",
          "slug": null,
          "is_primary": true,
          "detail": "Accenture faces massive data breach that could put clients at risk.",
          "detail_kind": "summary",
          "source": "News: Cybersecurity Dive",
          "source_type": "news",
          "source_url": "https://news.google.com/rss/articles/CBMilwFBVV95cUxNUmhvV0V4emV4UFdQVTFVdVBqdXZ0UW8wSmgtQ294NzZYSVJrdmRpOUpXVklzdnFGcjJZUDlORG5YTjNiY2NkVnJMTTVSV29tbTBzbE1pVmVDLU5YNTBYb3ZCNUVOR2htbm9NbTc0bWx0T0s1OVhKY2RBeTlkaklVR2VzSDZvSWtIZ0JkSjNSQ3BUOFJhNldr?oc=5",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "I",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Professional and Business Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Mount Royal University",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-07-09",
          "group": "1e3c3e60-8293-4af1-9d7f-94e6bab2fc4e",
          "slug": null,
          "is_primary": true,
          "detail": "Mount Royal University Confirms Data Stolen in Ransomware Attack.",
          "detail_kind": "summary",
          "source": "News: SecurityWeek",
          "source_type": "news",
          "source_url": "https://news.google.com/rss/articles/CBMimgFBVV95cUxPTDRTSDNteE5IREdkcUl3SHFZZ2ZsY0drYlRuNVMtOTI1OWpxR0tLOFJHdjIzOV9TbVNONVBmYnBNWTRfWWdYRnJSN0g0enV2RDdaWC1kcTBJQ2N3Y2pYdWhCaUNodGhpYkRfcHVPVE13NEtJa0N3WkZZel9HRjBwRE1menRVOTNyQXdUSEZDOS0zS1RsMC1kLV930gGfAUFVX3lxTE1sUTRsbUtiS1NGX2xGdkY0REJwcDF3ZnhPMkU2T2VnY0ZBVXNYTUY1QXJQZ0ZIYlJRb0hUZUF6Y2MzWEZOeVZQQWlYMFRkanBLN2N3alRqaHVqdlBmeFJJWHM5LUpfVDRqMUpybkd0QXFEWU5KTVBDUmRkRnB0WElpRWNzNGF5M2h4T1BuWUFQODJ6ZmR1dEdBYXJ6S3hwVQ?oc=5",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "I",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Public Sector and Education",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Centers Lab NJ LLC",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-07-13",
          "group": "392ad08b-b481-4a1e-9b3b-b5e3fa66a35d",
          "slug": null,
          "is_primary": true,
          "detail": "Healthcare diagnostics company Centers Laboratory (Centers Lab NJ LLC) has informed the US government that a data breach discovered nearly one year ago affects more than 540,000 individuals.",
          "detail_kind": "summary",
          "source": "News: SecurityWeek",
          "source_type": "news",
          "source_url": "https://news.google.com/rss/articles/CBMikAFBVV95cUxQZHVGQVVzWkY5RE5TaU1wS3V3M2xuZGJiMk5kaWZDOFFCSldkN3ZiMEFPR2NOMkRic1V0czYyN21lTTV4OEhrV2Jua1FUWElqdjZsVnhPRTBsNFRBWjhzZFQ3bGYzcUZDNmhwWWx6WHg0UkYxMGt2ZGo3c040a2pxUENGUlpiLWZCWnF5MUw3bWvSAZYBQVVfeXFMT1RTbnFpMXFrZV9zUExPZWFsaDI5cXE2NE5Rc1dGbjBxZTVwN2h2bThJS2tmazlqdWFTam9XckpZOVdlRUhWVFRFaEF3Ynh3WVVMTEtYUUxGVDlESGJXWFVVR1pjQVVLemlPamVBWmxURXdYOVk0Nkp6TEctbzhCd3FQbmVWakt2bmk2eE90OEYwZmxIaUtR?oc=5",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "I",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Coca-Cola",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-07-17",
          "group": "c564e39e-a3b3-4d38-b83c-19ce4a49554d",
          "slug": "fairlife-2026-07-16",
          "is_primary": false,
          "detail": "The Coca-Cola Co. said a cyberattack has forced it to temporarily halt its Fairlife milk operations in the U.S. \"The full scope, nature, and impacts of the incident are not yet known,\" Coca-Cola said in a statement. It added that the breach has not affected product quality or safety.",
          "detail_kind": "summary",
          "source": "News: CBS News",
          "source_type": "news",
          "source_url": "https://news.google.com/rss/articles/CBMic0FVX3lxTE8tY1RLN1RhdTVaMHB1LU5IRlYyRk9sZV9PYm9hU2pyT0Fnb3gxMEZFa2tWUHdkZVlfOUZNS1p0ZWJOLUhwWTdDNnY1Tk52S2JWdU5WUkxoWG92dWFtd2VtY3BoaUFRMDVhLVB3YkdKeHRNUVk?oc=5",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "I",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Abbott",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-07-17",
          "group": "8370bcac-a0e7-4858-811e-e25efffce602",
          "slug": null,
          "is_primary": true,
          "detail": "Abbott did not disclose what kind of information was accessed. The company declined to respond further to MedTech Dive’s request for comment regarding when the attack was discovered and what kind of information was accessed.",
          "detail_kind": "summary",
          "source": "News: MedTech Dive",
          "source_type": "news",
          "source_url": "https://news.google.com/rss/articles/CBMiogFBVV95cUxQNVR5WmliSUNCVTE2N08xckhCeG02YkRQWi1ubDJtVHpCYXk3NGNIWmxsdlIzd2Q5MUNqelNqd3ZNOWhTNUg1Y0VEcHZyek9zVXRlR01qd3MtemdSUGFvS1Rldkg1cWRQeWVrbU1TY3FEMXFYQTJ0ZE5Lb1VOUFN2bXlpNGZFdnZwa3FqTHRzU2JXMk1yVF9sRDFlN3doNEstNXc?oc=5",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "I",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Ecopetrol",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-07-18",
          "group": "eb25447d-325f-460a-b7df-a45f92b984c8",
          "slug": null,
          "is_primary": true,
          "detail": "The Colombian state-controlled ‌energy company Ecopetrol announced on Friday that a cyberattack resulted in the theft of data tied to about 3,300 user accounts ​and that it could not \"guarantee\" the breach would ​not have a \"material adverse\" financial impact.",
          "detail_kind": "summary",
          "source": "News: Reuters",
          "source_type": "news",
          "source_url": "https://news.google.com/rss/articles/CBMiuwFBVV95cUxNU0F1ZXlIX3EtVmMzRWVzaHNUY2J2U29JSS1Wd3JRV2xXZzVRMDNHd3FnSENVYzFkSUVvak1GSGZDN2FnamQ3eTF2UjMtTy1BNk9fWkU1dUw0R2ZFbldZbGhEUWh3cXlwX2FkbFVCMTR2SjN5NEN1X1JGdV9pVEpnYUZtWG13anZIYWdSU3pUS1dIZ29VaGVkdXVZeXhhUzVCODl4M1hIRzJTY3JYS1ozSDllMGhDWk9vTWZR?oc=5",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "I",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Energy and Utilities",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Ascension",
          "breached_entity": null,
          "date": "Dec 2024",
          "disclosed": "2024-05-09",
          "group": "f78029ce-270a-451d-8799-19c2bd82744f",
          "slug": "ascension-2024-05-09",
          "is_primary": true,
          "detail": "Ascension stated that an employee at one of its facilities accidentally downloaded a malicious file they believed was legitimate, which the company characterised as an honest mistake. Security reporting also linked the intrusion to the suspected exploitation of CVE-2024-1709, a vulnerability in ConnectWise's ScreenConnect remote-access software. The combination highlights how a single user action and unpatched third-party software can open the door to a major ransomware incident.",
          "detail_kind": "summary",
          "source": "Company PR statements",
          "source_type": "media",
          "source_url": "https://www.hipaajournal.com/ascension-data-breach-former-business-partner/",
          "enforcement": null,
          "amount": "$1.3B",
          "grade": "A",
          "money": {
            "case": "total",
            "amount": "$1.3B",
            "amount_usd": 1300000000,
            "category": "total_incident_cost",
            "grade": "A",
            "state": "realized",
            "source_url": "https://www.statnews.com/2024/09/18/ascension-financials-cyberattack-cost-losses/",
            "source_label": "Media Report",
            "caveat": "The company's own complete incident total.",
            "figures": [],
            "cumulative": null
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$1.3B",
              "amount_usd": "1300000000",
              "grade": "A",
              "source": "Company PR statements",
              "url": "https://www.hipaajournal.com/ascension-data-breach-former-business-partner/",
              "disclosed": null,
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "CDK",
          "breached_entity": null,
          "date": "Jun 2024",
          "disclosed": "2024-06-19",
          "group": "6dfe8e17-b4b2-4492-8b57-d7f563d6c11e",
          "slug": null,
          "is_primary": true,
          "detail": "CDK's ransomware event drove an immediate payment of $25mm in Bitcoin payments to the BlackSuit ransomware gang. A year before the incident CDK was acquired by a private equity organization, effectively turning it into a private company. Several public companies were impacted, resulting in 8k filings that show in excess of $1bn losses across the automotive industry.",
          "detail_kind": "summary",
          "source": "Company announcement",
          "source_type": "company_statement",
          "source_url": "https://www.cbsnews.com/news/cdk-attack-cyber-ransom-event/",
          "enforcement": null,
          "amount": "$25mm",
          "grade": "A",
          "money": {
            "case": "single",
            "amount": "$25M",
            "amount_usd": 25000000,
            "category": "direct_expense",
            "grade": "A",
            "state": "realized",
            "source_url": "https://cyberscoop.com/cdk-ransom-blacksuit-25-million/",
            "source_label": "Media Report",
            "caveat": null,
            "figures": []
          },
          "sector": "Technology and Software",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$25mm",
              "amount_usd": "25000000",
              "grade": "A",
              "source": "Company announcement",
              "url": "https://www.cbsnews.com/news/cdk-attack-cyber-ransom-event/",
              "disclosed": null,
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "Craneware",
          "breached_entity": null,
          "date": "Jul 2020",
          "disclosed": null,
          "group": "f7c3ea05-9181-4e3a-978f-7edbddd27981",
          "slug": "craneware",
          "is_primary": true,
          "detail": "Craneware sits inside the billing systems of more than 2,000 US hospitals and roughly 10,000 clinics and pharmacies, so an intrusion into a Scottish software vendor is really an intrusion into American healthcare's revenue plumbing. The company stressed that much of what left was non-sensitive or already public regulatory data, a reassurance that quietly conceded a significant volume had gone, employee records and a subset of customer and partner data among it. Contained is not the same as empty-handed when the files are already gone.",
          "detail_kind": "summary",
          "source": "Cybersecurity incident report",
          "source_type": "company_statement",
          "source_url": "https://www.londonstockexchange.com/news-article/CRW/notice-of-cyber-security-incident/17694735",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Suno",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-07-21",
          "group": "53d1c996-8dea-42f9-b1df-abb9e006a934",
          "slug": null,
          "is_primary": true,
          "detail": "404 Media disclosed that Suno was breached in Nov 2025, as confirmed by HaveIBeenPwnd. Suno has not yet publicly disclosed the cyberattack or notified individuals that their information was taken, and has refused to answer reporter questions on this matter.",
          "detail_kind": "summary",
          "source": "Security analyst report",
          "source_type": "third_party_estimate",
          "source_url": "https://techcrunch.com/2026/07/21/ai-music-generator-suno-breach-affects-55m-users-per-have-i-been-pwned/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "I",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Technology and Software",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Stadler",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-07-15",
          "group": "a589b3c9-2b54-4d54-a196-25f47eefc369",
          "slug": null,
          "is_primary": true,
          "detail": "Stadler refuses to pay ransom to the Everest hacking group, claims core IT systems were not hacked. ENISA warned that the railway sector’s growing strategic importance was outpacing its ability to manage cyber risks. Findings point to weaknesses highlighted by the Stadler breach. Only 35% of railway companies surveyed regularly assessed the effectiveness of their cybersecurity controls, while 50% did so on an ad hoc basis. Just 25% regularly tested business-continuity and disaster-recovery arrangements.",
          "detail_kind": "summary",
          "source": "Media report",
          "source_type": "media",
          "source_url": "https://www.railwaygazette.com/stadler/2026/07/21/stadler-refuses-to-pay-sfr10m-cyberattack-ransom/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "I",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Transportation and Logistics",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "TfL Transport for London",
          "breached_entity": null,
          "date": "Sep 2024",
          "disclosed": "2024-09-12",
          "group": "df4849a9-6eb0-4b36-a6d0-ba3399058e85",
          "slug": null,
          "is_primary": true,
          "detail": "Scattered Spider exfilitrated 15 million lines of user data and then exposed the user data of 10 mm customers. The stolen database included names, contact details, home addresses, and Oyster refund data containing banking details and sort codes for about 5,000 customers",
          "detail_kind": "summary",
          "source": "Company announcement",
          "source_type": "company_statement",
          "source_url": "https://tfl.gov.uk/fares/free-and-discounted-travel/cyber-security-incident",
          "enforcement": null,
          "amount": "$49mm",
          "grade": "A",
          "money": {
            "case": "set",
            "amount": null,
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": [
              {
                "amount": "£10M",
                "amount_usd": 13100000,
                "category": "business_interruption",
                "state": "realized",
                "grade": "A",
                "disclosure": null,
                "source_url": null,
                "source_label": "Company Statement"
              },
              {
                "amount": "£29M",
                "amount_usd": 37990000,
                "category": "direct_expense",
                "state": "realized",
                "grade": "A",
                "disclosure": null,
                "source_url": null,
                "source_label": "Company Statement"
              }
            ]
          },
          "sector": "Transportation and Logistics",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": [
            {
              "amount": "$49mm",
              "amount_usd": null,
              "grade": "A",
              "source": "Company announcement",
              "url": "https://tfl.gov.uk/fares/free-and-discounted-travel/cyber-security-incident",
              "disclosed": null,
              "pre_tracking": false
            }
          ]
        },
        {
          "org": "Medisecure",
          "breached_entity": null,
          "date": "Apr 2024",
          "disclosed": "2024-05-16",
          "group": "86fd1746-952d-48fb-8075-efe10499e3a2",
          "slug": null,
          "is_primary": true,
          "detail": "Medisecure experienced a massive ransomware and data exfiltration attack, exposing 6.5 TB of data included names, addresses, Medicare numbers, and sensitive prescription medication and healthcare card details. The costs of this attack in losses and recovery expenses were never disclosed, as Medisecure declared insolvency within weeks of the disclosure of the incident.",
          "detail_kind": "summary",
          "source": "Company announcements",
          "source_type": "company_statement",
          "source_url": "https://www.homeaffairs.gov.au/about-us/our-portfolios/cyber-security/cyber-coordinator/medisecure-cyber-security-incident",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Kawasaki Motors Europe",
          "breached_entity": null,
          "date": "Sep 2024",
          "disclosed": "2024-09-12",
          "group": "b4cbe4ef-5d85-4838-bbb3-5c2297a3df04",
          "slug": null,
          "is_primary": true,
          "detail": "Kawasaki originally stated that they experienced a cyber attack, but avoided an incident by shutting down and isolating their servers. The action had a direct impact on operations. Ransomhub later dumped 487 GB of data after Kawasaki refused to pay for a ransom, contradicting Kawasaki's initial representations of the breach and its consequences.",
          "detail_kind": "summary",
          "source": "Company statements to media",
          "source_type": "media",
          "source_url": "https://www.scworld.com/brief/operations-at-kawasaki-europe-mostly-restored-after-ransomhub-attack",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Qantas",
          "breached_entity": null,
          "date": "Jul 2025",
          "disclosed": "2025-07-02",
          "group": "28ae31c0-d2e0-4e90-8904-07704ddbc976",
          "slug": null,
          "is_primary": true,
          "detail": "An unnamed threat actor impersonating \"Qantas IT help\" contacted the airline's call centre. The agent was tricked into connecting a customised version of Salesforce's Data Loader tool to the customer relationship management platform used by Qantas, which enabled mass data extraction. 5.67 mm customer records were exposed. The cost of cyber losses and recovery has never been disclosed, with Qantas executives agreeing to forfeit $800k AUD in bonuses due to the incident.",
          "detail_kind": "summary",
          "source": "Company statement",
          "source_type": "company_statement",
          "source_url": "https://www.qantas.com/en-au/help/cyber-safety-scams/cyber-incident",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Transportation and Logistics",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Harrods",
          "breached_entity": null,
          "date": "Sep 2025",
          "disclosed": null,
          "group": "a63a422e-2076-43d0-bfc9-765d39a72a51",
          "slug": null,
          "is_primary": true,
          "detail": "Attackers gained access to approximately 430,000 customer records through one of Harrods' third-party provider systems. The stolen data included names and contact details such as email addresses and telephone numbers. Additional information relating to marketing preferences, loyalty tier levels and connections to Harrods co-branded cards was also caught up in the breach.",
          "detail_kind": "summary",
          "source": "Media reports",
          "source_type": "media",
          "source_url": "https://www.centraleyes.com/harrods-data-breach-explained/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Chick-Fil-A",
          "breached_entity": null,
          "date": "Jun 19",
          "disclosed": "2026-07-22",
          "group": "a8a3f7a0-363b-461c-9cb2-6f36f825c38f",
          "slug": null,
          "is_primary": true,
          "detail": "According to the notification letter sent to affected customers, hackers launched an automated attack against Chick-fil-A's website and mobile application between June 17 and June 19 using credentials obtained from a third-party source. Chik-Fil-A has not disclosed the number of customers impacted and has filed incident notifications with several State AG offices around the US.",
          "detail_kind": "summary",
          "source": "Newsweek",
          "source_type": "company_statement",
          "source_url": "https://www.newsweek.com/chick-fil-a-hit-with-data-breach-what-we-know-12226870",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Nichirei",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-07-22",
          "group": "0d2c8ac6-e236-4107-be58-c10598efaaa1",
          "slug": null,
          "is_primary": true,
          "detail": "The ransomware attack caused widespread chaos, directly impacting approximately 5,000 corporate clients. The breach paralyzed cold storage warehouse logistics and frozen food shipments nationwide, forcing major retailers to scramble.",
          "detail_kind": "summary",
          "source": "Company announcement",
          "source_type": "company_statement",
          "source_url": "https://www.tokyoreporter.com/japan-news/russian-hackers-claim-responsibility-for-cyberattack-on-nichirei/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Wholesale and Distribution",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "DentaQuest",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-07-17",
          "group": "f2970448-8460-4d97-bbb8-ce4fcc474221",
          "slug": null,
          "is_primary": false,
          "detail": "Wellesley, MA-based DentaQuest, a dental benefits administrator that manages the benefits for 32 million Americans, has announced it is actively managing a cybersecurity incident involving unauthorized access to a limited part of its network. According to its website notice, immediate action was taken to contain and mitigate the threat, and the company is working with a leading cybersecurity expert, forensic investigators, and law enforcement authorities. If the data breach is confirmed as affecting 2.6 million individuals, it will rank as one of the largest healthcare data breaches of the year to date.",
          "detail_kind": "summary",
          "source": "DentaQuest Starts Notifying 15 Million+ Individuals About May 2026 Cyber Incident",
          "source_type": "media",
          "source_url": "https://www.hipaajournal.com/dentaquest-data-breach/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Fiesta",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-07-13",
          "group": "c4058b35-1469-43ca-9e04-97d8fc7925c4",
          "slug": null,
          "is_primary": true,
          "detail": "The Las Vegas-based insurance and tax-services franchisor said it became aware on June 9, 2025, that systems within its network environment had been affected by a cyber incident. Following a forensic investigation and an \"extensive data review,\" it was determined on June 26, 2026, that potentially accessed or acquired files contained personal information. While it took a year for Fiesta to determine that customer data had been exposed, Fiesta violated no disclosure laws as written due to their efforts to notify customers within 17 days of the confirmation that customer data had been impacted.",
          "detail_kind": "summary",
          "source": "Fiesta Insurance took a year to identify breached customer data - report",
          "source_type": "company_statement",
          "source_url": "https://www.insurancebusinessmag.com/us/news/cyber/fiesta-insurance-took-a-year-to-identify-breached-customer-data--report-583647.aspx",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Tennessee Pathology Group",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-06-23",
          "group": "4557e94c-ea7b-4f4d-b503-daa999108838",
          "slug": null,
          "is_primary": true,
          "detail": "An investigation was launched on December 1, 2025, when anomalous activity was identified within its computer network. During the course of the investigation, unauthorized network access was confirmed. It is unclear from the breach notice when the unauthorized access occurred or for how long the network was compromised. The review of the exposed data was completed on April 27, 2026, when it was confirmed that personal and protected health information had been exposed. Notification letters were mailed to the affected individuals on June 23, 2026, and complimentary credit monitoring and identity theft protection services have been offered to certain individuals. Over 169,000 customer and patient records were exposed.",
          "detail_kind": "summary",
          "source": "Tennessee Pathology Group Announces 170K-record Data Breach",
          "source_type": "company_statement",
          "source_url": "https://www.hipaajournal.com/tennessee-pathology-group-data-breach/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Bank of Baroda",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-07-27",
          "group": "9314443a-4032-4994-8aa1-ca39d7b3d0f6",
          "slug": "bank-of-baroda-2026-07-27",
          "is_primary": true,
          "detail": "State-owned Bank of Baroda (BoB) on Monday, July 27, confirmed a security incident that led to unauthorised access to “certain data” by threat actors. The incident involved comprise of an employee’s email account, Bank of Baroda said. Reports suggest that the exfiltrator dumped 1TB on the internet, for free.",
          "detail_kind": "summary",
          "source": "Bank of Baroda confirms data breach, says employee email account compromised in hack",
          "source_type": "company_statement",
          "source_url": "https://indianexpress.com/article/technology/tech-news-technology/bank-of-baroda-confirms-security-incident-data-breach-hackers-10805797/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "MCBS",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-06-26",
          "group": "a5d7b603-c89c-46f0-89d4-f43ebb7a3d63",
          "slug": null,
          "is_primary": true,
          "detail": "MCBS confirmed that there had been unauthorized network access between September 22 and September 25, 2025, and files containing protected health information may have been viewed or exfiltrated from its network. The review of the affected data was completed on May 28, 2026, some 8 months after the network intrusion.",
          "detail_kind": "summary",
          "source": "MCBS Announces Cybersecurity Incident Impacting 1.26M Individuals",
          "source_type": "company_statement",
          "source_url": "https://www.hipaajournal.com/mcbs-cyberattack-data-breach/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Triple-A",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-07-27",
          "group": "f3be708d-21aa-4ff3-b556-2fc1365080d3",
          "slug": null,
          "is_primary": true,
          "detail": "Triple- A, a Singapore-based company said it unauthorized access on July 25th, 2026 and temporarily placed certain services into maintenance mode for about three hours while it secured the affected infrastructure.  Triple-A did not disclose the amount lost or explain how the wallets were compromised. Onchain investigator Specter previously estimated the losses at about $11.8 million.",
          "detail_kind": "summary",
          "source": "Triple-A Confirms Treasury Wallet Breach After Reported $11.8M Loss",
          "source_type": "company_statement",
          "source_url": "https://cointelegraph.com/news/triple-a-treasury-wallet-breach-11-8-million-loss",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Ernst & Young",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-07-15",
          "group": "f9d80ecc-f7c9-49e1-8e90-4e44d3c12fa9",
          "slug": null,
          "is_primary": true,
          "detail": "EY says it detected unusual activity on April 23 and determined that the attacker accessed the platform between March 28 and April 12, downloading multiple documents. The ShinyHunters extortion gang added Ernst & Young to its data leak site, claiming it conducted the attack and threatened to release the allegedly stolen data if the company does not contact the group by July 31, 2026. E&Y took more than 3 months to disclose the cyber incident.",
          "detail_kind": "summary",
          "source": "Ernst & Young data breach claimed by ShinyHunters extortion gang",
          "source_type": "media",
          "source_url": "https://www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Professional and Business Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Minnesota State Officials",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-07-28",
          "group": "64bbfbec-6960-4615-8a32-673d59f2b139",
          "slug": null,
          "is_primary": true,
          "detail": "Minnesota officials disclosed a coordinated cyberattack targeting more than 30 community water systems between July 26 and July 27, 2026. Several communities, including Braham, Plymouth, South St. Paul and Maple Plain, reported disruptions to operational technology supporting water treatment, although officials stated there was no impact to drinking water quality or public safety. In Braham, the attack temporarily shut down the city's water treatment plant until operators restored service using manual processes. The incident is one of the largest coordinated cyberattacks against U.S. municipal water systems publicly disclosed to date and underscores the continued targeting of critical infrastructure.",
          "detail_kind": "summary",
          "source": "Authorities investigating a coordinated cyberattack against Minnesota water systems",
          "source_type": "company_statement",
          "source_url": "https://www.cybersecuritydive.com/news/authorities-investigating-a-coordinated-cyberattack-against-minnesota-water/826427/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Public Sector and Education",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Unitel",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-07-28",
          "group": "7d1a7aa6-2305-48b0-a857-94fc90a12790",
          "slug": null,
          "is_primary": true,
          "detail": "Angola's largest telecommunications provider suffered a cyberattack that disrupted nationwide voice, mobile data, and internet services just one day before its planned stock market listing. The incident affected more than 21 million subscribers, forcing the company to activate incident response and recovery efforts while services remained degraded. Unitel has not disclosed the attack vector, threat actor, or whether customer data was compromised, but did proceed with their public offering.",
          "detail_kind": "summary",
          "source": "Angola's Unitel hit by cyberattack ahead of stock market debut",
          "source_type": "media",
          "source_url": "https://therecord.media/angola-unitel-cyberattack-outage",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Telecommunications",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Paidwork",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-07-19",
          "group": "4fba4888-6090-4afc-85cf-b4c38cb6ecba",
          "slug": null,
          "is_primary": true,
          "detail": "Gig-work platform Paidwork disclosed that a breach exposed the personal and financial information of approximately 23 million users after a stolen database surfaced publicly. The leaked data reportedly includes names, email addresses, phone numbers, physical addresses, dates of birth, banking and payout information, device details, IP addresses, and bcrypt-hashed passwords.",
          "detail_kind": "summary",
          "source": "Paidwork data breach reportedly exposes 23M accounts and bank data",
          "source_type": "company_statement",
          "source_url": "https://www.foxnews.com/tech/paidwork-breach-exposes-23m-user-records",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Technology and Software",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Shell and Philips",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-14",
          "group": "fd971519-01c7-42cb-8d58-29fbabdc785c",
          "slug": "shell-and-philips-2026-08-14",
          "is_primary": true,
          "detail": "Cl0p listed nearly fifty companies at once and walked off with 89GB of Shell's facility drawings and test reports. The hole was in PTC's Windchill, patched 17 June. Shell's security spend didn't include understanding the path from Windchill to their doorstep.",
          "detail_kind": "summary",
          "source": "Shell and Philips hit by Russian ransomware attack",
          "source_type": "company_statement",
          "source_url": "https://www.dutchnews.nl/2026/08/shell-and-philips-hit-by-russian-ransomware-attack/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Energy and Utilities",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "H&M",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-14",
          "group": "d264269a-7624-4bea-b7e4-ad1eb4951cfa",
          "slug": "h-m-2026-08-14",
          "is_primary": true,
          "detail": "H&M confirmed that an attack on a business system exposed Korean customers' email addresses, phone numbers, and order or return reference numbers. More sensitive payment and password data were reportedly not affected, but the company did not disclose the number of customers or the access path. The useful boundary held around payment data; disclosure and accountability around the breached business tool remain thin.",
          "detail_kind": "summary",
          "source": "H&M discloses customer data breach in South Korea",
          "source_type": "company_statement",
          "source_url": "https://www.koreaherald.com/article/10842119",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "RingCentral",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-14",
          "group": "3a65f1c0-1afb-404a-b486-ff7a3a865e5a",
          "slug": null,
          "is_primary": true,
          "detail": "623GB out the door, no ransom paid, 280GB published in response. RingCentral assured customers that silence meant safety, and Have I Been Pwned then counted 1.6 million email addresses sitting in the archive.",
          "detail_kind": "summary",
          "source": "RingCentral data breach exposed info of 1.6 million accounts",
          "source_type": "company_statement",
          "source_url": "https://www.bleepingcomputer.com/news/security/ringcentral-data-breach-exposed-info-of-16-million-accounts/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Technology and Software",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "French Tax Authority",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-14",
          "group": "a6ab13b6-9423-4bae-b4a1-a364aafb7c06",
          "slug": null,
          "is_primary": true,
          "detail": "A stolen identity got someone onto the French tax authority's VPN and into an internal lookup tool built for querying taxpayers. DGFiP cut the access in June, filed it under routine, and let the hacker break the news in August.",
          "detail_kind": "summary",
          "source": "French tax data stolen in cyberattack, ministry says",
          "source_type": "company_statement",
          "source_url": "https://www.thenews.com.pk/latest/1412241-french-tax-data-stolen-in-cyberattack-ministry-says",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Public Sector and Education",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Trezor",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-13",
          "group": "7ef1fb56-72cd-4ddd-b01d-ebc81899bc5d",
          "slug": null,
          "is_primary": true,
          "detail": "13,689 hardware wallet buyers had their home addresses taken from a fulfilment partner. What capped the damage was a 90-day deletion rule, not a security control. Data you have already deleted cannot be stolen, and nobody puts that on a compliance dashboard.",
          "detail_kind": "summary",
          "source": "Trezor discloses data breach affecting nearly 14,000 customers",
          "source_type": "company_statement",
          "source_url": "https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Columbia Justice Ministry",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-12",
          "group": "62565c83-3c73-4725-9b27-484044a9d6dd",
          "slug": null,
          "is_primary": true,
          "detail": "Ransomware hit Colombia's Justice Ministry five days before a presidential handover and one day after the national CERT warned this was coming. The warning was the control. It was issued, logged, and changed nothing.",
          "detail_kind": "summary",
          "source": "Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition",
          "source_type": "company_statement",
          "source_url": "https://www.darkreading.com/cyberattacks-data-breaches/ransomware-hits-colombian-justice-ministry-presidential-transition",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Public Sector and Education",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Unlimited Technology Systems",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-01",
          "group": "64a62530-ee00-47de-89de-fe609167e674",
          "slug": "unlimited-technology-systems-2026-08-01",
          "is_primary": true,
          "detail": "3.8 million patients, from five days in October 2025, took until July 2026 to size. UTS says an unauthorized actor copied patient data from its commercial data center during five days in October 2025. The scale came from concentration: a billing vendor that most patients never chose held identity, insurance, and medical data for many providers in one place.",
          "detail_kind": "summary",
          "source": "Unlimited Technology Systems breach impacts 3.8 million people",
          "source_type": "company_statement",
          "source_url": "https://www.bleepingcomputer.com/news/security/unlimited-technology-systems-breach-impacts-38-million-people/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "LawCare",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-12",
          "group": "39928d9c-5a2a-4666-a347-87d2b5e2878c",
          "slug": null,
          "is_primary": true,
          "detail": "Lawyers in crisis contacted LawCare in confidence, all of it lived in Beacon CRM, and all of it is now assumed gone. No vendor questionnaire in existence asks whether the supplier left an AWS key in a public JavaScript file. [LawCare]",
          "detail_kind": "summary",
          "source": "UK legal mental health charity LawCare confirms database was compromised in hacking incident",
          "source_type": "company_statement",
          "source_url": "https://www.thelawyermag.com/au/news/international/uk-legal-mental-health-charity-lawcare-confirms-database-was-compromised-in-hacking-incident/585772",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Professional and Business Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Liechtenstein Office of Justice",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-03",
          "group": "625042f7-8066-4c62-b51b-4f94580510f0",
          "slug": null,
          "is_primary": true,
          "detail": "EU anti-money-laundering rules require a single register naming the humans behind Liechtenstein's companies, foundations, and trusts. Overnight on 30 July, copies covering 31,000 entities left. The transparency measure worked exactly as designed, for the adversaries.",
          "detail_kind": "summary",
          "source": "Cyberattack hits Liechtenstein's anti-money laundering data register, Vaduz says",
          "source_type": "company_statement",
          "source_url": "https://www.euronews.com/my-europe/2026/08/03/cyberattack-hits-liechtensteins-anti-money-laundering-data-register-vaduz-says",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Public Sector and Education",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Health Sciences Centre",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-10",
          "group": "062f44af-7ffd-4e01-a601-babf34d34525",
          "slug": null,
          "is_primary": true,
          "detail": "Ransomware took the HVAC and the door locks at Manitoba's largest hospital. The provincial auditor general flagged Shared Health's cybersecurity in 2024. Somebody measured this, wrote it down, and filed it. [Health Sciences Centre, Winnipeg]",
          "detail_kind": "summary",
          "source": "Ransomware attack on Health Sciences Centre affects doors, ventilation and air-conditioning",
          "source_type": "media",
          "source_url": "https://www.cbc.ca/news/canada/manitoba/health-sciences-centre-ransomware-hack-9.7302058",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "SafePal",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-16",
          "group": "fc49a634-a8da-4f7f-a426-b7f2fee6d661",
          "slug": null,
          "is_primary": true,
          "detail": "SafePal disclosed a data breach affecting roughly 40,000 customers, exposing customer information associated with purchases while the company says wallet credentials, private keys, and recovery seeds were not compromised. This is high quality signal, cryptocurrrency relatedcustomer data that gives attackers a better map for phishing and social engineering. Exactly what adversaries want for conducting further identity based attacks.",
          "detail_kind": "summary",
          "source": "SafePal Data Breach Hits Tens of Thousands of Customers - Infosecurity Magazine",
          "source_type": "company_statement",
          "source_url": "https://www.infosecurity-magazine.com/news/safepal-data-breach-tens-thousands/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Pokemon Center",
          "breached_entity": "CEVA Logistics",
          "date": "Aug 2026",
          "disclosed": "2026-08-17",
          "group": "7132bf8f-6b6a-4e7a-82e6-bd445350f399",
          "slug": "ceva-logistics-2026-08-17",
          "is_primary": true,
          "detail": "Another CEVA Logistics supply chain victim. Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information. CEVA's reply? Gotta get 'em all. ",
          "detail_kind": "summary",
          "source": "Pokémon Center data breach exposes customer info, cancels some orders",
          "source_type": "media",
          "source_url": "https://www.bleepingcomputer.com/news/security/pokemon-center-data-breach-exposes-customer-info-cancels-some-orders/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Technology and Software",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Zenith Bank",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-05",
          "group": "06d46912-b614-4703-b9c3-39abe009dd0c",
          "slug": "zenith-bank-2026-08-05",
          "is_primary": true,
          "detail": "The notice for Zenith Bank's August 2026 incident contains no facts: no confirmed entry point, no named actor, no data types, no count of people affected. What remains is a disclosure obligation met with a placeholder, from an institution whose core function is holding other people's money and identity records. The duty to explain a breach is being treated as different from the duty to prevent one.",
          "detail_kind": "summary",
          "source": "Zenith Bank customers told to immediately check their deposits after data breach",
          "source_type": "company_statement",
          "source_url": "https://dailypost.ng/2026/08/05/zenith-bank-customers-told-to-immediately-check-their-deposits-after-data-breach/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Apollo Global",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-21",
          "group": "a341620c-c277-499c-8ef3-b97179334ad8",
          "slug": "apollo-global-2026-08-21",
          "is_primary": true,
          "detail": "The notice attached to this incident reads \"to review,\" which means the source confirms nothing beyond a name and a date: not the vector, not the actor, not what was reached, not how many were affected. Apollo Global sits in the Index with a placeholder where an accounting should be. An institution's disclosure obligation is itself a control point, and a statement that has not yet been given is not transperancy, especially for customers. .",
          "detail_kind": "summary",
          "source": "Apollo Global reveals data breach after hackers target financial firms",
          "source_type": "company_statement",
          "source_url": "https://www.businessinsurance.com/apollo-global-reveals-data-breach-after-hackers-target-financial-firms/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Sawyer Savings Bank",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-07",
          "group": "5507f26c-cbef-41b4-bed2-ab2da66e03b7",
          "slug": "sawyer-savings-bank-2026-08-07",
          "is_primary": true,
          "detail": "The notice names Sawyer Savings Bank and a disclosure date; it does not name an entry point, an actor, a record count, or the type of data reached.",
          "detail_kind": "summary",
          "source": "Sawyer Savings Bank Branches Closed After Security Incident",
          "source_type": "company_statement",
          "source_url": "https://cnynews.com/ixp/706/p/sawyer-savings-bank-branches-closed/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Cognizant",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-18",
          "group": "eb95bd1f-c93b-4c1c-9d57-dc216dead649",
          "slug": "cognizant-2026-08-18",
          "is_primary": true,
          "detail": "Cognizant notified individuals of a data breach and is offering one million dollars in identity theft coverage. The headline confirms notification and a remediation gesture but does not name the entry point, the actor, the number affected, or the data types involved. A company built on managing other organizations' systems and data has disclosed a breach of unspecified scope, and the insurance offer addresses downstream harm, but not the architecture that allowed the exposure. ",
          "detail_kind": "summary",
          "source": "Cognizant notifies individuals of data breach; offers $1 mn identity theft cover",
          "source_type": "company_statement",
          "source_url": "https://timesofindia.indiatimes.com/city/bengaluru/cognizant-notifies-individuals-of-data-breach-offers-1-mn-identity-theft-cover/articleshow/133407212.cms",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Professional and Business Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Alation",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-21",
          "group": "f73db472-a2f4-4a42-b7ba-69b385530306",
          "slug": "alation-2026-08-21",
          "is_primary": true,
          "detail": "AI data giant Alation confirmed a cyberattack, and the headline confirms nothing else: no entry point, no actor, no data type, no count of records or systems touched. That leaves a data-governance vendor built to sit inside other companies' data stacks, cataloging and connecting sensitive information as its core function, now acknowledging compromise without saying what that position exposed.",
          "detail_kind": "summary",
          "source": "Alation Confirms Cyberattack: What Security Teams Need to Know",
          "source_type": "media",
          "source_url": "https://www.esecurityplanet.com/threats/news-alation-cyberattack-customer-data-exposure/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Technology and Software",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Origin Energy",
          "breached_entity": null,
          "date": "Jul 2026",
          "disclosed": "2026-07-22",
          "group": "a8750015-7b3a-4760-85af-f459b1275b02",
          "slug": "origin-energy-2026-07-22",
          "is_primary": true,
          "detail": "Origin Energy confirmed that full bank account details belonging to 60 customers were accessed in a July breach. While 60 may seem small compared to the 900,000 Australian customers impacted by this massive breach, it isn't small for each one of those 60 people who took the hit for Origin Energy's lack of stewardship.",
          "detail_kind": "summary",
          "source": "Origin Energy says bank account details of 60 customers accessed in July data breach",
          "source_type": "company_statement",
          "source_url": "https://www.abc.net.au/news/2026-08-21/origin-energy-hack-update-60-customers-bank-account-access/107062636",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Energy and Utilities",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Brinks Home",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-03",
          "group": "eacf7a16-575f-4f8c-9ff3-c9a1c2008b7b",
          "slug": "brinks-home-2026-08-03",
          "is_primary": true,
          "detail": "Brinks Home's disclosure names a leak, not a cause: no entry point, no actor, no data type, no count. Just files surfacing after the fact. Announcing a leak isn't transparency. Brinks should know better than most that sounding an alarm isn't the same as responding to one. ",
          "detail_kind": "summary",
          "source": "Brinks Home Discloses Data Breach as Hackers Leak Files",
          "source_type": "company_statement",
          "source_url": "https://www.securityweek.com/brinks-home-discloses-data-breach-as-hackers-leak-files/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Framework",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-10",
          "group": "33595df3-06f0-4a83-b84a-3310b6141fe9",
          "slug": "framework-2026-08-10",
          "is_primary": true,
          "detail": "Framework confirms customer data were exposed, and the headline is pretty much all you get: no named vector, no timeline, no data type, no actor. A breach notice with no information is not a disclosure. It's a stall tactic.",
          "detail_kind": "summary",
          "source": "Framework Admits Customer Data Were Exposed in Latest Security Breach",
          "source_type": "company_statement",
          "source_url": "https://www.itechpost.com/articles/236979/20260809/framework-admits-customer-data-were-exposed-latest-security-breach-metabase-cloud-cause.htm",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Technology and Software",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Beacon",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-05",
          "group": "39e727b5-3c43-49cf-95c9-95be25d7d2e9",
          "slug": "beacon-2026-08-05",
          "is_primary": true,
          "detail": "Beacon CRM flared up as a news headline in the UK, and the headline is nearly all there is - no entry point, no actor, no data type, no count. What's confirmed is the scale: a single CRM widely used by charities, meaning one vendor's compromise fans out into every donor and beneficiary file it was trusted to hold. The platform was the perimeter for organizations that focused on the mission of helping other while depending on Beacon CRM to help them.",
          "detail_kind": "summary",
          "source": "Beacon CRM, Widely Used by Charities, Suffers Data Breach",
          "source_type": "company_statement",
          "source_url": "https://www.govinfosecurity.com/beacon-crm-widely-used-by-charities-suffers-data-breach-a-32420",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Public Sector and Education",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Conwy Mind",
          "breached_entity": "Beacon CRM",
          "date": "Aug 2026",
          "disclosed": "2026-08-24",
          "group": "338ce46d-2faa-4ab7-9a77-4ff08f10d968",
          "slug": "beacon-crm-2026-08-24",
          "is_primary": true,
          "detail": "A North Wales mental health charity confirms sensitive data was accessed, informing their clients that their trusted provider Beacon CRM had experienced a breach on 7/29/2026 that affected many of Beacon's non-profit clients.",
          "detail_kind": "summary",
          "source": "Cyber attack on North Wales mental health charity sees sensitive data accessed",
          "source_type": "company_statement",
          "source_url": "https://www.dailypost.co.uk/news/north-wales-news/cyber-attack-north-wales-mental-34507321",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Public Sector and Education",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "English National Ballet",
          "breached_entity": "Beacon CRM",
          "date": "Aug 2026",
          "disclosed": "2026-08-04",
          "group": "0d81cad9-3db9-4cb0-ad43-5b52d708f231",
          "slug": "beacon-crm-2026-08-04",
          "is_primary": true,
          "detail": "English National Ballet's headline confirms a cyber attack and a possible breach; entry point, actor, and what data may have been reached go unnamed in the source. The National Ballet finds itself unable to answer these questions because they don't have them. They are one of the many clients of Beacon CRM.",
          "detail_kind": "summary",
          "source": "English National Ballet suffers possible data breach following cyber attack",
          "source_type": "company_statement",
          "source_url": "https://www.standard.co.uk/news/london/english-national-ballet-arts-culture-beacon-crm-data-breach-cyber-attack-b1292366.html",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Public Sector and Education",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Access Bank",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-17",
          "group": "ec6b5903-1e3c-47d6-a12d-72f445e034f9",
          "slug": "access-bank-2026-08-17",
          "is_primary": true,
          "detail": "Access Bank lost N1.3bn to hackers in an expanding attack against Nigerian banks nationwide.  entry point, method, and timeline all unnamed. The breach notification is precise on the loss but skips, entirely, how the breach occurred. ",
          "detail_kind": "summary",
          "source": "Banks continue to battle hackers over deposits, as Access Bank loses N1.3bn",
          "source_type": "media",
          "source_url": "https://hallmarknews.com/banks-continue-to-battle-hackers-over-deposits-as-access-bank-loses-n1-3bn/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Connecticut Department of Social Services",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-21",
          "group": "d3444f8a-4bea-4765-9a5f-8b27b5474f5b",
          "slug": "connecticut-department-of-social-services-2026-08-21",
          "is_primary": true,
          "detail": "A state Medicaid portal exposed data on 41,000 members. Per usual, the state and their auditor declared that \"no social security numbers were taken\" but the laundry list of other data elements stolen suggest a ready-made-cookbook for use in other forms of targeted consumer attacks such as social engineering and financial scams.",
          "detail_kind": "summary",
          "source": "State says data from 41,000 Medicaid members exposed in portal breach",
          "source_type": "company_statement",
          "source_url": "https://www.wfsb.com/2026/08/21/state-says-data-41000-medicaid-members-exposed-portal-breach/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Public Sector and Education",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "SFR",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-21",
          "group": "32ffd2f7-4302-4b40-bddd-d52e63164ba7",
          "slug": "sfr-2026-08-21",
          "is_primary": true,
          "detail": "2.1 million SFR fiber customer records surfaced as exposed and SFR has confirmed that attackers compromised a legitimate user account to access an internal fiber connection management tool named NOVA. The data loss is a treasure trove of information for targeted scams and phishing against SFR customers.",
          "detail_kind": "summary",
          "source": "SFR data breach in France: 2.1 million fibre customer records exposed",
          "source_type": "company_statement",
          "source_url": "https://www.connexionfrance.com/news/more-than-21-million-customer-records-stolen-in-sfr-hack/809132",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Telecommunications",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Sakura Internet",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-19",
          "group": "110ee076-25e2-4d09-8974-5a260895c42b",
          "slug": "sakura-internet-2026-08-19",
          "is_primary": true,
          "detail": "Up to 1.36 million Sakura Internet accounts were exposed in a recently disclosed breach, which was only discovered when Sakura was investigating an entirely separate breach in one of its other business units. ",
          "detail_kind": "summary",
          "source": "Sakura Internet hack exposes data of up to 1.36 million accounts",
          "source_type": "company_statement",
          "source_url": "https://www.bleepingcomputer.com/news/security/sakura-internet-hack-exposes-data-of-up-to-136-million-accounts/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Telecommunications",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "North Carolina Ports",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-07",
          "group": "c026536f-eb1c-4824-b99c-a135291e6326",
          "slug": "north-carolina-ports-2026-08-07",
          "is_primary": true,
          "detail": "North Carolina Ports confirms operations disrupted by a cyberattack. Operations were disrupted and impacted by gate mechanisms being activated. No threat groups have been identified for this event but ports are critical infrastructure and a desirable target for many types of adversaries.",
          "detail_kind": "summary",
          "source": "North Carolina Ports confirms cyberattack disrupting operations",
          "source_type": "company_statement",
          "source_url": "https://www.bleepingcomputer.com/news/security/north-carolina-ports-confirms-cyberattack-disrupting-operations/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Transportation and Logistics",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Sunshine Health",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-11",
          "group": "933fa46f-5cd5-4347-acc8-569634c73662",
          "slug": "sunshine-health-2026-08-11",
          "is_primary": true,
          "detail": "No system was breached at Sunshine Health. A caller posing as someone trusted asked an employee to hand over health-plan files, and the employee did. About 41,569 people had their names, birth dates, and medical histories walk out through a phone call. The security boundary was a person's willingness to help, and it held only as long as the caller sounded familiar.",
          "detail_kind": "summary",
          "source": "Data Breaches Reported by Sunshine Health; Health Payment Systems",
          "source_type": "company_statement",
          "source_url": "https://www.hipaajournal.com/data-breaches-sunshine-health-health-payment-systems/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Healthcare and Life Sciences",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Canvas",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-20",
          "group": "0b8bdc8d-f412-4e8c-818c-6bfced22debc",
          "slug": "canvas-2026-08-20",
          "is_primary": true,
          "detail": "Vulnerabilities in Canvas, the third-party learning platform four Hong Kong institutions leaned on, exposed more than 153,000 student and staff accounts; names, IDs, emails, login credentials, course messages. The institutions' internal systems were in place but ended up being irrelevant, since Canvas was the actual perimeter, and one vendor's flaw became four campuses' breach.",
          "detail_kind": "summary",
          "source": "More than 153,000 students, staff affected in Canvas data breach: privacy watchdog",
          "source_type": "company_statement",
          "source_url": "https://www.scmp.com/news/hong-kong/education/article/3364668/more-153000-students-staff-affected-canvas-data-breach-privacy-watchdog",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Public Sector and Education",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Latvia's Road Traffic Safety Directorate CSDD",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-18",
          "group": "83b7487d-3d36-41d7-a346-8a70f05529d9",
          "slug": "latvia-s-road-traffic-safety-directorate-csdd-2026-08-18",
          "is_primary": true,
          "detail": "An unpatched, internet-facing hole in a CSDD system, one that was legally classed as critical, requiring multi-factor authentication and penetration testing it never got, gave attackers a path to eighteen years of payment records: 1.2 million people, 200,000 companies, IDs and addresses intact. The immediate result? The resignation of the entire safety advisory board.",
          "detail_kind": "summary",
          "source": "Data of 1.2 million people leaked in CSDD cyberattack in Latvia - including personal ID numbers and addresses",
          "source_type": "company_statement",
          "source_url": "https://bnn-news.com/data-of-1-2-million-people-leaked-in-csdd-cyberattack-in-latvia-including-personal-id-numbers-and-addresses-282949",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Public Sector and Education",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Sogang University",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-15",
          "group": "26afe699-e038-4d09-aa0f-631e473760e2",
          "slug": "sogang-university-2026-08-15",
          "is_primary": true,
          "detail": "About 180,000 students, alumni, and employees at Sogang University had their data exposed through the school's integrated login system. IDs, names, affiliations, emails, phone numbers, encrypted passwords. The entry point stays unnamed, the attacker unidentified; what's clear is one login system built to serve every population became one failure domain for all of them. Network separation arrived after detection, not before.",
          "detail_kind": "summary",
          "source": "Sogang University hit by personal information breach of 180,000",
          "source_type": "company_statement",
          "source_url": "https://www.koreaherald.com/article/10842345",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Public Sector and Education",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Sotheby's International",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-25",
          "group": "4463cde0-79b6-416d-bf8f-2c661932f083",
          "slug": "sotheby-s-international-2026-08-25",
          "is_primary": true,
          "detail": "Sotheby's International, a luxury real estate firm, reported it is investigating a cyber security incident involving unauthorized access to data held in a third-party software platform used to store marketing contact information. The company said the person who accessed the data claimed to have obtained 1.6 million contacts but it refuted that claim because it did not have that many on its database. Regardless of the number, given Sotheby's clientele, even marketing data seems to be a valuable haul from a valuable brand.",
          "detail_kind": "summary",
          "source": "Luxury real estate firm hit by cyber security attack",
          "source_type": "company_statement",
          "source_url": "https://www.rnz.co.nz/news/crime-and-justice/1118363/luxury-real-estate-firm-hit-by-cyber-security-attack",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Bits of Gold",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-17",
          "group": "686b58c2-e00d-468f-a6e3-e18b0687b5a8",
          "slug": "bits-of-gold-2026-08-17",
          "is_primary": true,
          "detail": "Bits of Gold, Israel's largest crypto broker, confirms a breach touching 200,000 customers. The Tel Aviv, Israel-based company reported the security breach on Sunday, saying a hacker gained unauthorized access to a third-party data analytics network and,gained access to customers’ names, national ID numbers, emails, phone numbers, IP addresses, bank account details, and public wallet addresses.",
          "detail_kind": "summary",
          "source": "Israel's largest crypto broker Bits of Gold hit by data breach affecting 200,000 customers",
          "source_type": "company_statement",
          "source_url": "https://www.coindesk.com/tech/2026/08/17/israel-s-largest-crypto-broker-bits-of-gold-hit-by-data-breach-affecting-200-000-customers",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Financial Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-27",
          "group": "a96b4323-511c-49ea-b2e7-f04bf01e68ce",
          "slug": "u-s-bureau-of-alcohol-tobacco-firearms-and-explosives-2026-08-27",
          "is_primary": true,
          "detail": "ATF confirmed a 'major incident' only after Qilin's ransomware gang posted the agency's name to its dark web leak site, not from its own monitoring. The bureau says the breach was confined to a standalone system, separate from its enterprise network and eForms. Qilin has not said whether it stole data or demanded a ransom, and ATF has not said what that system held. An agency that tracks explosives learned about its own breach from the people who lit the fuse. Or, it knew about it and didn't bother to disclose it.",
          "detail_kind": "summary",
          "source": "ATF confirms “major incident” after recent Qilin breach claims",
          "source_type": "company_statement",
          "source_url": "https://www.bleepingcomputer.com/news/security/atf-confirms-major-incident-after-recent-qilin-breach-claims/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Public Sector and Education",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Manchester Airports Group",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-27",
          "group": "620c5272-8b5b-4685-b9e7-15b5207c9431",
          "slug": "manchester-airports-group-2026-08-27",
          "is_primary": true,
          "detail": "MAG's breach note names neither the entry point nor the attacker, only the wreckage: 8.7 million customers' emails, phone numbers, vehicle registration numbers, and postcodes, pulled from the car park, lounge, and wifi sign-up systems shared across Manchester, Stansted, and East Midlands. Three airports ran their ancillary bookings through one common system, so a single hole became a three-airport hole. MAG points out that no bank details were held there, as if a name, a plate number, and a postcode were not already enough to track someone.",
          "detail_kind": "summary",
          "source": "UK airports operator hit by cyber-attack and customer data accessed",
          "source_type": "company_statement",
          "source_url": "https://www.theguardian.com/business/2026/aug/27/uk-airports-operator-cyber-attack-customer-data-accessed",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Transportation and Logistics",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Carhartt",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-27",
          "group": "a3be8ea6-d951-4baf-8874-9eda0e4e16c5",
          "slug": "carhartt-2026-08-27",
          "is_primary": true,
          "detail": "ShinyHunters says it pulled more than 50GB from Carhartt's Databricks analytics platform, claiming the intrusion on August 13 and later publishing the archive after Carhartt declined a $3.3 million ransom demand. How the platform was actually entered, credentials, misconfiguration, or something else, is not stated; Carhartt has not confirmed the breach at all. Troy Hunt's independent analysis puts the toll at 12.9 million accounts, names, emails, phones, addresses, and over 15,000 internal @carhartt.com employee addresses sitting in the same analytics warehouse as the customer file. An analytics platform became the record of the whole company, employees, and customers alike, and nobody built a wall between them.",
          "detail_kind": "summary",
          "source": "Carhartt data breach exposes information of 12.9 million accounts",
          "source_type": "company_statement",
          "source_url": "https://www.bleepingcomputer.com/news/security/carhartt-data-breach-exposes-information-of-129-million-accounts/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Hasbro",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-28",
          "group": "41025e05-6ea9-4c6c-b748-2d79f18c3180",
          "slug": "hasbro-inc-2026-04-01",
          "is_primary": false,
          "detail": "A single compromised employee account exposed Social Security numbers, financial account details, card numbers, and driver's license information for 436 Massachusetts employees. Hasbro has not said how the account was hijacked, when it was noticed, or how many employees beyond Massachusetts were affected. An account is not a perimeter; it is one point of failure wearing an employee badge. Hasbro calls this unrelated to March's outage, but two collapses in one year from the same company describe a design, not a coincidence.",
          "detail_kind": "summary",
          "source": "Toy-making giant Hasbro disclose data breach affecting employees",
          "source_type": "company_statement",
          "source_url": "https://www.bleepingcomputer.com/news/security/toy-making-giant-hasbro-disclose-data-breach-affecting-employees/",
          "enforcement": null,
          "amount": "$10.8M",
          "grade": "A",
          "money": {
            "case": "single",
            "amount": "$10.8M",
            "amount_usd": 10800000,
            "category": "direct_expense",
            "grade": "V",
            "state": null,
            "source_url": "https://www.sec.gov/Archives/edgar/data/46080/000004608026000050/has-20260628.htm",
            "source_label": "SEC 10-Q",
            "caveat": null,
            "figures": []
          },
          "sector": "Retail and Consumer",
          "needs_grading": false,
          "lag_days": 120,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Metro Atlanta city",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-29",
          "group": "e9ad0ebc-5788-4a8c-8e41-c9a3153b736f",
          "slug": "metro-atlanta-city-2026-08-29",
          "is_primary": true,
          "detail": "Norcross, Georgia, was hit by ransomware on August 1, with no vector named, no actor named, and no accounting of what data, if any, left the network. City officials notified police and cybersecurity professionals and kept most services running while restoration continued. Calling in digital fixers after the fact is incident response, not architecture. The filing never says what allowed the encryption in. An organization that cannot name the crack in its defenses has not yet found the boundary that failed.",
          "detail_kind": "summary",
          "source": "Metro Atlanta city hit by ransomware, working on full system restoration",
          "source_type": "company_statement",
          "source_url": "https://www.wsbtv.com/news/local/metro-atlanta-city-hit-by-ransomware-working-full-system-restoration/EZ4YRJJ63BD3HH7ETQT5HWQJ2Q/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Public Sector and Education",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        },
        {
          "org": "Troutman Pepper Locke",
          "breached_entity": null,
          "date": "Aug 2026",
          "disclosed": "2026-08-26",
          "group": "b652d94b-e2d1-4535-b01b-6abfea857444",
          "slug": "large-atlanta-law-firm-2026-08-26",
          "is_primary": true,
          "detail": "Troutman Pepper Locke's breach began when one employee, targeted by a social engineering attack, trusted communications that looked legitimate but were not, exposing information now claimed to affect roughly 37,000 people in an accompanying lawsuit. The account gives no vendor, no malware, no stolen credential chain: just a single inbox that functioned as the firm's whole perimeter. A law firm built on judgment left one employee's judgment as its only control point.",
          "detail_kind": "summary",
          "source": "Large Atlanta law firm hit with data breach and associated lawsuit",
          "source_type": "company_statement",
          "source_url": "https://www.ajc.com/news/2026/08/large-atlanta-law-firm-hit-with-data-breach-and-associated-lawsuit/",
          "enforcement": null,
          "amount": "Not yet quantified",
          "grade": "A",
          "money": {
            "case": "untyped",
            "amount": "Not yet quantified",
            "amount_usd": null,
            "category": null,
            "grade": null,
            "state": null,
            "caveat": null,
            "figures": []
          },
          "sector": "Professional and Business Services",
          "needs_grading": false,
          "lag_days": null,
          "lag_pre_tracking": false,
          "revisions": []
        }
      ]
    }
  },
  "market": {
    "_comment": "Written by the market cron job in production. Committed values are the last known close, used as a fallback so the page never renders empty.",
    "stamp": "01 SEP 2026 · CLOSE",
    "quotes": [
      {
        "name": "S&amp;P 500",
        "value": "7,631.47",
        "change": "0.71%",
        "direction": "down"
      },
      {
        "name": "DOW",
        "value": "52,766.88",
        "change": "0.79%",
        "direction": "down"
      },
      {
        "name": "NASDAQ",
        "value": "26,099.77",
        "change": "1.03%",
        "direction": "down"
      }
    ]
  },
  "generated": "2026-09-03T18:11:23.812Z"
}