Hacker in a Hoodie™ Index
On the Government Record · complete ledger
Cyber incidents on the public government record: SEC 8-K filings, and state-regulator breach and enforcement notifications, approved to this index. Each entry is a primary government record, graded Verified. This is the complete record for this feed, uncapped.
189 approved government-record incidents, most recent first. The complete record, nothing hidden, never summed.
How each figure is graded
VVerifiedthe linked primary document states it
AAttesteda published report credits a named source
IInferredno direct confirmation; a lead, not a figure
The full standard →
The revision trail
A cost figure arrives after an incident is disclosed, and it moves as stronger sources report it. Early estimates run below the figure a company eventually discloses. The amount shown for each incident is its most recent claim; the trail beneath it is every claim in order, each with its date, its source, and its grade, from an Inferred early estimate to a higher Verified filing figure.
Corrections
Every figure on this ledger is read from a primary SEC filing and links to it. If we have read one wrong, tell us: info@hackerinahoodie.com.
Fishbrain ABJul 2026
Fishbrain doesn't say what let attackers into its user database on August 19, only that a vulnerability existed and was later patched; the entry point stays unnamed. The haul was names, birth dates, emails, phone numbers, usernames, country data, and password hashes with salts, for a count the company won't state. Hashed isn't the same as safe: Fishbrain admits some of those hashes may be crackable. Patching the hole after 20 million anglers' credentials were already in reach isn't security, it was bait for the bad guys.
California AG breach notification
Not yet quantified
VVerifiedTechnology and SoftwareHumanEdge, Inc.Mar 2026
HumanEdge doesn't say how intruders got in; the filing gives a date, March 18, 2026, and nothing else. What exited the building were Social Security numbers, driver's license numbers, financial account data, medical records, and health insurance information, for at least 2,222 people across three states. A staffing firm had quietly become a records bureau for identity and health data. That concentration, not the unnamed intruder, is the actual finding.
California AG breach notification
Not yet quantified
VVerifiedProfessional and Business ServicesYouLend US LLCJun 2026
Unauthorized access sat inside YouLend's network for four days in June 2026, pulling full names, Social Security numbers, dates of birth, addresses, and financial or credit card account details. The filing names no entry point and no attacker; whatever let someone in for those four days goes unexplained in the very document meant to explain it. That omission is not modesty; it is architecture kept off the record. Like many mandatory filings with State AG offices, there are no media reports of this breach. Just letters to customers and flashing "was your personal data stolen?" law firm recruitment pages for civil litigation.
California AG breach notification
Not yet quantified
VVerifiedFinancial ServicesKnowledge Research CenterJul 2026
Knowledge Research Center's filing confirms a breach and stops there: no vector, no data type, no record count, no date. No media reports, no coverage, no information. That's the disclosure system working exactly as designed, built to satisfy a statute rather than inform anyone.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesNovoCure LtdSep 2026
Novocure's SEC filing names no vector and no actor for the unauthorized access it discovered in mid-August 2026, only the aftermath. More than 1,400 U.S. patients had ID numbers exposed without names, while fewer than 50 in the western U.S. lost both identity and provider contact details, a split that reads like several systems failing on different terms, not one breach. Employee names, job titles, and phone numbers leaked from the same event, which the filing still frames as a story about untouched treatment devices. No devices were breached, they say; the record of who these patients are was.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedHealthcare and Life SciencesPark Dental Partners, Inc.Aug 2026
Park Dental Research's systems got tied up in ransomware by the Interlock group. Employee Social Security numbers, driver's license numbers, bank account details, passports, and I-9 forms were accessed by an unauthorized party in April 2026; the notification letters never say how the door opened. Interlock claims it exfiltrated 260 gigabytes and says so plainly; yet the company's own letter and 8k filing never mentions ransomware at all.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedHealthcare and Life SciencesKaniksu Community HealthDec 2025
breach at Aesto
Kaniksu Community Health's December 2025 breach ran through Aesto, the same vendor turning up again and again across this index as a single point of failure for multiple health systems. The filing names only "personal information": names, dates of birth, addresses, phone numbers, no Social Security numbers, no financial data, and no entry point stated. The notice suggests this is good news because nothing there opens a new account in anyone's name. Good news is relative: a name and a birthdate can't be reissued, and they don't expire.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesBerkeley Research Group, LLCFeb 2025
Berkeley Research Group found an intruder inside its own network between February 28 and March 2, 2025, copying files before anyone caught the motion. The notice never says how the actor got in, what was taken, or how many people it belonged to, which is its own kind of disclosure. A firm built on producing precise findings for other people's disputes can't produce one for its own breach. Eighteen months later, the silence is still the headline, not the incident.
California AG breach notification
Not yet quantified
VVerifiedProfessional and Business ServicesVirta Health's compromised repository sat apart from its production platform, but unauthorized access still ran from March 19 to 22, 2026, exposing Social Security numbers, diagnoses, physician information, and medical record numbers for 14,636 people. The filing does not say how Lapsus$, the group that claimed the breach, got in. Separation from production is not isolation; the side repository still holds the whole clinical record. Lapsus$ posted Virta to its leak site on March 23, a full day before anyone at Virta noticed, which says more about who was watching than about who broke in.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesMCKESSON CORPAug 2026
ShinyHunters claims it vished several McKesson employees' Okta credentials, then walked those single sign-on logins straight into Salesforce and Snowflake. McKesson has not confirmed the entry point or the data taken; only the extortion group has spoken. Single sign-on was built to make log-ins easy, but when secured incorrectly (or not at all) it is just the easy button to own an entire company. The group claims roughly 284 million patient records, the kind of data no reset can undo.
SEC 8-K, Item 7.01
Not yet quantified
VVerifiedWholesale and DistributionBennett CollegeAug 2026
Bennett College calls it a network disruption, the polite word for three weeks of unaccounted access between October 27 and November 15, 2025. The filing never names how anyone got in or who they were; it only names what sat exposed: Social Security numbers, driver's license and passport numbers, financial accounts, medical and health insurance information. A network with no stated entry point is not a mystery; it is an admission that nobody was watching the door closely enough to say which one opened. Credit monitoring 10 months after the breach will not touch the medical history or the passport number, now loose in the world.
California AG breach notification
Not yet quantified
VVerifiedPublic Sector and EducationIndico Data SolutionsMay 2026
Indico Data Solutions lost names, addresses, and Social Security numbers out of online file stores in May 2026; the filing does not say how someone got in, only that access was unauthorized. The company that touched this data was never the insurer a customer chose, but a back-office AI vendor that the insurer quietly handed the file to. Consent stopped at the front door; the data kept moving through vendors, and nobody was asked to approve.
California AG breach notification
Not yet quantified
VVerifiedInsurancebreach at “ISC”
An unauthorized third party sat inside a limited part of ISC's environment for four days in February 2025, and the filing never says how it got in. What it took reads like a full identity kit: Social Security numbers, driver's license and government ID numbers, biometric data, and medical details tied to insurance claims. ISC administers other companies' insurance programs.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesBOSTON SCIENTIFIC CORPAug 2026
A cybersecurity incident on August 25, 2026, knocked out Boston Scientific's order processing and shipping worldwide. The filing names no entry point, no actor, no data type, because the investigation hasn't reached that far yet. When core operations can't survive one unnamed intrusion, the systemic fragility was built in long before the attacker showed up. Global disruption isn't the sign of a sophisticated adversary; it's the sign of a single point of failure wearing a lot of hats.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedHealthcare and Life SciencesMurfreesboro Medical ClinicApr 2026
BianLian, a ransomware group, claims it pulled records for 559,000 patients and employees off Murfreesboro Medical Clinic's network on or around April 22, 2023; the filing never says how the door opened. What exited? Names, Social Security numbers, driver's license copies, dependent data, full diagnostic and prescription histories. Bascially the entire archive of a person's medical life, sitting behind one network boundary. That is not a sophisticated breach; that is a single failure domain holding everything a person has ever told a doctor. A settlement can pay a claim; it cannot reissue a diagnosis.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life Sciencesbreach at Aesto
SpineZone's patient records were exposed not on its own network but inside Aesto Health, the Birmingham vendor it paid to migrate and archive data into Amazon Web Services. The breach window ran from December 2 to December 18, 2025, and it took Aesto until May 2026 to confirm what protected health information had actually been taken. Names, Social Security numbers, driver's license numbers, financial account details, and full medical and billing histories moved through that one AWS account, along with the records of more than two dozen other providers' patients. SpineZone outsourced the archive; it did not outsource the liability for losing it.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesTogether Women's Health LLCDec 2025
breach at Aesto
Together Women's Health filed its breach notice under Aesto, the same vendor whose AWS environment has already surfaced in other patients' notifications this year. The letter names Social Security numbers and two dates in December 2025, and stops there: no stated entry point, no actor, no count of people affected. A filing this thin is its own kind of disclosure. When a vendor keeps reappearing as the common thread across unrelated clinics, the failure isn't in any one exam room; it's in the shared filing cabinet everyone quietly outsourced to.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesNutex Health Inc.Aug 2026
Nutex Health's servers were accessed and drained by an unnamed third party sometime before the August 24, 2026 filing. The entry point unstated, the count unstated, the haul spanning patient, employee, provider, and financial records in one undifferentiated pull. A vague reference to "unauthorized activity involving data stored" on their network. Data didn't steal your data, the adversary did.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedProfessional and Business ServicesCorroborating records
VVerifiedSEC 8-K, Item 1.05 ↗
breach at LACMA
Los Angeles County Museum of Art (LACMA) discovered a breach on Monday, July 7, 2025. Then it took them until February of 2026 to figure out what go stolen (LACMA, Louvre much?). Then it took them until August 24, 2026 to post the incident with the California AG and on their on website. What's missing in the AG report? All the sensitive data types that were stolen.
California AG breach notification
Not yet quantified
VVerifiedPublic Sector and EducationAestoAug 2026
Aesto Health's AWS infrastructure was breached, exposing the PII and PHI of 9,540,683 people across up to 29 provider clients, from VillageMD to Monroe Health Center. The filing names no entry point and no actor, only the aggregate count. Aesto was hired to migrate and archive records; instead, it became the single failure domain for dozens of practices that never touched its cloud. One vendor's infrastructure was the perimeter for an entire health system's worth of patients.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesZeroStack Corp.Aug 2026
ZeroStack Corp. disclosed a material cybersecurity incident under Item 8.01 (other events), not as a 1.05 (material incident), and the filing states nothing further: no entry point, no actor, no data type, no scope. That silence is itself the finding, since a disclosure obligation triggered by materiality has been met while the architecture that produced the exposure remains hidden. A filing can satisfy the law without telling anyone what actually failed.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedWholesale and Distributionbreach at Genesis Healthcare Management
Kern Psychiatric Health and Wellness Center's patient data was exposed not on its own systems but on the network of Genesis Healthcare Management, the outsourced management company that discovered unauthorized file access on June 22, 2026. The data was among the most sensitive a person holds, Social Security numbers alongside diagnoses, prescriptions, and treatment records. Outsourcing the back office moved those records to a network the practice did not run.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesASOS US Sales LLCJul 2026
ASOS traced unauthorized account access to credentials stolen in a different company's breach and reused against it. Nothing in ASOS's systems was breached; a valid credential was just presented by the adversary. Password-only authentication inherits every leak that credential ever appeared in, and the system just works as designed after it is leveraged.
California AG breach notification
Not yet quantified
VVerifiedRetail and ConsumerPOLAM Federal Credit UnionMay 2025
POLAM Federal Credit Union's filing to the California Attorney General names a May 2025 breach and nothing else - no entry point, no actor, no data type, no count. Fifteen months between incident and disclosure is itself a problem. Providing zero details but offering every impact customer yet another round of free credit monitoring suggest that transparency isn't a requirement anyone is holding POLAM accontable for.
California AG breach notification
Not yet quantified
VVerifiedFinancial ServicesApollo Management Holdings, L.P.Jul 2026
A social-engineering attack gave an unauthorized party access to Apollo cloud platforms for several days. Personal data, including Social Security numbers, was potentially exposed. A cloud trust model was defeated with one single successful call or message.
California AG breach notification
Not yet quantified
VVerifiedFinancial Servicesbreach at Aesto
Nebraska Orthopaedic Center was exposed through Aesto, the vendor holding its patient data in Amazon Web Services. An unauthorized actor copied protected health information, including identifiers that may include Social Security numbers. The trust boundary sat with the vendor, but the consequences fell right on top of the patients and the provider.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesSouthern Illinois UniversitySep 2025
breach at Oracle
Southern Illinois University tied a data exposure to its Oracle E-Business Suite environment, with files open to unauthorized access for five weeks in mid-2025 and confirmed only in July 2026. The flaw was Oracle's; the exposure was SIU's. You can outsource the software, but not the risk it carries into your own data.
California AG breach notification
Not yet quantified
VVerifiedPublic Sector and Educationbreach at Aesto
Northern Inyo Hospital was exposed through Aesto, the vendor holding its patient records in AWS, where a network incident ran two weeks in December 2025. The hospital handed Aesto the job of holding the records; it could not hand off the duty to protect them. Outsourcing proved the work can move, the risk stayed where the patients are.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesSilver Summit Medical Corporation was pulled into a breach through a vendor that held its patient information. Data was acquired from the vendor's systems without authorization, although the notice does not name the vendor or explain the access path. Outsourcing the system moved the control point, not the exposure. The specific vendor was not named.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesTurner Construction CompanyJul 2026
Turner Construction found unauthorized access to its systems over nearly two weeks and confirmed that files containing payroll, banking, identity, and address information were reached. The exposure crossed data categories that should not have needed to share one compromise path. Credit monitoring deals with downstream risk; segmentation and constrained authority would have dealt with the cause.
California AG breach notification
Not yet quantified
VVerifiedReal Estate and ConstructionApple American Group LLCApr 2026
Apple American Group, parent group of Applebee's, found that an unknown actor accessed company servers and employee files during a two-day window in April. The notice does not explain the entry point. Monitoring services address the aftermath; they do not explain why one server compromise could reach the files. Clearly, Apple American Group would like the data back in its neighborhood.
California AG breach notification
Not yet quantified
VVerifiedRetail and ConsumerLangwasser & Company CPAsMay 2026
Langwasser & Company learned that unauthorized tax returns had been filed for some clients, and its investigation found that an unauthorized actor may have accessed personal information. The notice cannot establish the full extent of access. The incident shows identity data doing double duty as both a record and an authentication mechanism: once exposed, it could be used to impersonate the taxpayer.
California AG breach notification
Not yet quantified
VVerifiedProfessional and Business ServicesForrestall CPAs LLCDec 2025
A tax firm is an identity warehouse by design, and Forrestall CPAs left an intruder inside its network for roughly a week, from December 22 to 30, reading and taking files that nothing inside kept apart. What left was the full identity kit: Social Security numbers, driver's licenses, financial accounts, dates of birth. The firm has confirmed 218 residents in Massachusetts and left the national count blank. How the door opened, and why a week passed before anyone noticed, the notice does not say.
California AG breach notification
Not yet quantified
VVerifiedProfessional and Business ServicesQuantum Health, Inc.May 2026
A vishing call caused a Quantum Health user to open the door to the network, followed by several days of access, a service outage, and file acquisition. The exposed data included insurance, medical, and other personal information. The call was the trigger; the larger failure was letting one user interaction carry enough authority access the systems and records at that scale.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesPaylogix, LLCNov 2025
Unauthorized actors accessed Paylogix systems and copied files from its network during a multi-day intrusion. Paylogix itself calls it a cyber event, saving the time needed to translate "we believe that our systems were accessed but don't think anything was taken".
California AG breach notification
Not yet quantified
VVerifiedFinancial ServicesBaylor GeneticsAug 2026
Baylor Genetics found an unauthorized third party inside part of its network for about a week with access to stored data. The breach exposed the sensitive personal and medical data of over 248,430 individuals. Clearly, a genetics company can't make a patient whole if their genetic information was stolen. ts a 1-of-1 kind of thing. The notice confirms the access but leaves the entry path and exact acquisition uncertain.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesLennar Mortgage, LLCMay 2026
Lennar Corporation and Lennar Mortgage, LLC were each breached through social engineering within two months, March 24 to 30 and May 26 to June 1, 2026; Lennar reported at least 61,295 people affected, their names, Social Security numbers, government IDs, and financial data exposed. One tricked employee is not an anomaly; it is the actual perimeter, and nothing closed it between the two hits. Notice went out in August, nearly four months after the first intrusion began. That gap is its own design failure, not an oversight.
Washington AG breach notification
Not yet quantified
VVerifiedReal Estate and ConstructionSee’s Candies, Inc.Apr 2026
See's Candies says an unauthorized user accessed its network, encrypted files, and took data that later appeared on the dark web. The compromise reached both operations and personal information, turning one network foothold into disruption and disclosure. Encryption was the visible event; broad access to the underlying files was the structural failure.
California AG breach notification
Not yet quantified
VVerifiedRetail and ConsumerUniversal Plant Services, LLCJun 2026
Universal Plant Services found an unauthorized individual inside its network for several days with access to identity, license, and financial-account information. The notice says passwords were reset and accounts secured after discovery, but does not explain the entry path. The control question is why access to one network segment could reach several forms of high-value identity data.
California AG breach notification
Not yet quantified
VVerifiedManufacturingKovack Financial, LLCAug 2025
Kovack reported unauthorized access involving email and sensitive personal information. Kovack took almost a full year to determine that it was necessary to contact their customers, even though they clearly acknowledge in their filing that they discovered the breach on 8/28/2025. The customer comes first, right?
California AG breach notification
Not yet quantified
VVerifiedFinancial ServicesLEVI STRAUSS & COAug 2026
Levi Strauss disclosed that social engineering led to unauthorized access to three employee computers and the exfiltration of corporate files. The attacker did not need to defeat the whole enterprise; a few trusted endpoints were enough to turn legitimate access paths into a data-extraction path. When trust follows the user and device automatically, compromising either can inherit far more authority than the attacker ever earned.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedRetail and ConsumerCushman & WakefieldApr 2026
Cushman & Wakefield says a vishing attack opened the door to unauthorized activity in its environment. The incident was described as limited, but social engineering that produces unauthorized system access is still a cyber incident and the event was significant enough to trigger mandatory reporting to the California AG.
California AG breach notification
Not yet quantified
VVerifiedReal Estate and ConstructionBoston Health Care for the Homeless Program disclosed that patient information was affected through a cybersecurity incident at a third-party provider. The infrastructure may have belonged to someone else, but the risk did not. Third-party architecture is still an attack surface when your data and your patients absorb the consequences.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesAmerican Addiction CentersMay 2026
breach at Salesforce
American Addiction Centers lost data through its Salesforce environment, not its health-records application or internal network. Names, Social Security numbers, and brief health descriptions were still reachable because the outreach system had become another sensitive-data store. The boundary held around the clinical system and failed around the SaaS platform that the business trusted beside it.
Washington AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesIEH CorpAug 2026
The entire compromise was one employee's Microsoft 365 mailbox, opened by a phishing page that harvested a password because credentials were the only lock on the door. Inside sat purchase orders, engineering documentation, and potentially export-controlled technical data tied to the THAAD and Patriot programs: defense secrets kept in an ordinary inbox. No actor has been named and no theft confirmed, but the exposure was set long before the phishing page loaded. A missile-parts maker had filed regulated engineering where a single stolen login could reach it.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedManufacturingStation Casinos, LLCMar 2026
Station Casinos reported an external system breach involving unauthorized access and sensitive personal information. The interesting security question is not whether the company offered identity protection afterward; it is why unauthorized access was able to reach data worth protecting in the first place. Breach response happens after the architecture has already made its most important decision about trust.
California AG breach notification
Not yet quantified
VVerifiedRetail and ConsumerNew York City Regional Center confirms a cybersecurity incident involving personal information, but says Massachusetts law prevents it from describing the nature of the event. That is enough to classify the event as cyber, but not enough to explain the failed control or the scope of access. The uncertainty belongs in the record rather than being filled with attack-story assumptions.
California AG breach notification
Not yet quantified
VVerifiedPublic Sector and Educationbreach at Aesto
Grant County's patient data lived inside Aesto Health's AWS infrastructure, one vendor holding records for at least two dozen hospital clients at once. Hackers moved through that shared environment for sixteen days in December 2025, pulling names, Social Security numbers, driver's license numbers, financial accounts, and medical and insurance details, all told, touching 9.5 million people. The source names no entry point and no attacker; what it names instead is the design, one cloud tenancy standing in as the perimeter for two dozen separate hospitals. Concentration isn't efficiency when a single vendor breach becomes two dozen hospital breaches wearing one name.
Washington AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesAMGEN INCJul 2026
The files that left Amgen never sat on Amgen's network: patient health records, research, and intellectual property lived in third-party cloud storage, and that is where the theft happened. The company has named no vendor, no access path, and no count of the people exposed, the standard silence of a breach whose front door belongs to someone else. When the perimeter is a contract with a cloud provider, the forensics begin on property the victim never controlled.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedHealthcare and Life Sciencesbreach at Aesto
Stanislaus County Health Services Agency was exposed through Aesto, the vendor that stored healthcare data in Amazon Web Services. An unauthorized actor may have accessed or acquired protected health information during the vendor's network incident. The county did not need to be breached directly; inherited access through the vendor was enough.
California AG breach notification
Not yet quantified
VVerifiedPublic Sector and EducationMicrocode, Inc.Jan 2026
breach at CommonSpirit Health
MicroCode experienced ransomware on a server that hosted CommonSpirit Health's tracking database and documents. Unauthorized access lasted for months, but the investigation could not confirm whether the data was viewed or taken. The uncertainty should be preserved: this is a confirmed system compromise with sensitive data in scope, not a confirmed exfiltration.
Washington AG breach notification
Not yet quantified
VVerifiedTechnology and SoftwareHEALTHSTREAM INCJul 2026
HealthStream's cloud platforms stayed up and intact, which was never where the data went missing. The intrusion landed on the corporate file servers, where copies of credentialing data for roughly 75 customers sat staged for conversion, troubleshooting, and analytics, alongside employee and billing records. No actor has surfaced and no files were encrypted; the exposure came not through the product but through the copies the product was never meant to spawn.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedTechnology and SoftwareANALOG DEVICES INCJun 2026
Analog Devices lost files from its systems on June 23, 2026, and disclosed neither the door the intruders came through nor the data they carried out. The only count belongs to the people who took it: the extortion group ExfilSquad claims about 570,000 records of customer names and home addresses, a figure the company holds at arm's length as a separate, unverified matter. A breach described only by its thieves is confirmed without being explained.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedTechnology and SoftwareClinical Registry SolutionsApr 2026
Clinical Registry Solutions confirmed unauthorized network access and acquisition of files containing St. Mary's patient information.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesSunrise CompanyApr 2026
Sunrise Company determined that an unauthorized actor acquired files from its network after suspicious activity was detected. Once an attacker can move from presence to acquisition, the system has failed at more than prevention; it has failed to constrain what unauthorized access can do. Good security assumes compromise happens and designs the blast radius accordingly.
California AG breach notification
Not yet quantified
VVerifiedReal Estate and ConstructionSPay Inc dba Stack SportsMay 2026
Stack Sports discovered unauthorized code inside its Sports Affinity payment platform that captured payment-card information entered during checkout. The company operates registration and payment systems used by youth and amateur sports leagues, meaning affected transactions may involve parents paying participation fees for children. The malicious code was reportedly present from May 8 until June 8, 2026, creating a month-long payment-card skimming window. The number of affected customers remains undisclosed, but the platform’s role across youth sports organizations gives the incident a potentially broad consumer impact.
California AG breach notification
Not yet quantified
VVerifiedTechnology and SoftwareJRK Property Holdings, Inc.Mar 2026
JRK Property Holdings reported unauthorized activity in its IT environment and potential access to sensitive files, with the event tied in public reporting to extortion activity. The extortion is the business model layered on top of the real failure: the attacker obtained enough access to make stolen data useful as leverage. Once unauthorized access can become durable access, the attacker gets to decide what the incident becomes next.
Washington AG breach notification
Not yet quantified
VVerifiedReal Estate and ConstructionEyemart Express, LLCFeb 2026
Eyemart Express confirmed a February cyberattack that exposed customer information ranging from identity data to vision and insurance records.
Washington AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesBridgeway traced the incident to a suspected employee email compromise that opened access to its systems from March to May. Benefit-plan participant data, including Social Security numbers for some people, may have been involved. Email identity was the security boundary. When that identity failed, the access lasted far longer than the initial deception.
Washington AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesDevereux FoundationNov 2025
Devereux Advanced Behavioral Health disclosed a ransomware attack involving information belonging to patients, employees, family members, donors and business partners. The potentially exposed data included combinations of Social Security numbers, financial information, government identification, medical information and health insurance information. Devereux provides behavioral health and developmental disability services across multiple states, giving the incident a broad geographic footprint. The attack highlights the impact ransomware is having on organizations serving vulnerable patient populations.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesUPBOUND GROUP, INC.Jul 2026
Upbound rated the stolen customer information non-sensitive, right up until it was enough to open roughly $13 million in fraudulent Acima leases and walk the merchandise out the door. The breach turned lease-to-own approval into a front door for anyone holding the right paperwork: identity verification that trusted data the company itself had graded as low value. No group has claimed it and no customer count has surfaced, leaving the theft measured only by the fraud it financed.
SEC 8-K, Item 8.01
Quantified 9 days after disclosure.
Losses on the record
$13M
Direct expense
VVerifiedVerified: the linked document states this figure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
FIVE BELOW, INCJul 2026
Five Below traced the intrusion to a single employee's company laptop, reached not by an exploit but by a threat actor who talked the person into granting access, and files were exfiltrated before the anomaly was ever flagged. The company's comfort is the blast radius: one machine, no PII, nothing else touched, a tidy story about a perimeter that turned out to be one talked-past employee. Who took the files, and how many, the filing does not say.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedRetail and ConsumerClover Health says social engineering compromised three employee accounts with access to member PII and PHI, although claims and corporate financial systems were not accessed. Four putative class actions followed, and Clover says it cannot yet reasonably estimate the possible loss or range of loss. Three identities were enough to create a regulated-data event and litigation exposure; that is the problem with treating identity as proof of trust instead of something that has to be continuously verified.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedFinancial ServicesThe Estée Lauder CompaniesAug 2025
breach at Oracle
Estée Lauder determined that an unauthorized third party gained access to its Oracle E-Business Suite environment and obtained employee-related personal information. The data set reportedly included the identity, financial, health and employment ingredients attackers leverage for future fraud and social engineering campaigns.
Washington AG breach notification
Not yet quantified
VVerifiedRetail and ConsumerZenPatient, Inc.Dec 2025
ZenPatient found that an unauthorized actor had access to or copied data over a period lasting more than two months. The notice does not explain how the actor entered or why the activity persisted that long. The important fact is not that an attacker was patient; it is that the environment allowed patience to work.
Washington AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesCoca Cola CompanyJul 2026
breach at Fairlife
The Coca-Cola Company disclosed that Fairlife, a dairy subsidiary, experienced a ransomware event. The filing does not establish when the attack occurred or what it may cost, so the incident is recorded against its July 16, 2026 disclosure date.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedManufacturingCorroborating records
DentaQuest LLCMay 2026
Between May 17 and May 20 attackers accessed and exfilitrated names, addresses, Social Security numbers, member identification numbers, Medicaid and Medicare numbers, diagnosis, treatment details and billing information for as many as 23.4 million patients. Notifications have been sent to at least 4.5 million people.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesCorroborating records
Madera Community HospitalMay 2025
Madera Community Hospital determined that an unauthorized party accessed its network and likely removed files containing patient personal and health information on May 28 and 29, 2025. The hospital completed its initial forensic determination in June 2025 but did not begin notifying patients until approximately one year later. The final number of affected patients has not been publicly established in the reporting reviewed.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesThe Washington PostJul 2025
breach at Oracle
The Washington Post was compromised through a previously unknown vulnerability in Oracle E-Business Suite, allowing data to be accessed and acquired over roughly six weeks. The software flaw was Oracle's, but the exposure came from the authority and data concentrated behind that application. A shared platform vulnerability became a direct path into each customer's retained records.
Washington AG breach notification
Not yet quantified
VVerifiedMedia and EntertainmentRiver Financial CorpJun 2026
River Financial said an unauthorized actor got into its network and ransomware was deployed across portions of the server environment. The later update added that data was removed, which pivots this from a disruption story into a theft story too. River Financial publicly stated that ue to the preliminary nature of the forensic investigation and the early stages of the legal proceedings, management is currently unable to predict the ultimate outcome of these matters or reasonably estimate the amount or range of potential financial loss, if any, that may result.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedFinancial ServicesSR Bancorp, Inc.Jul 2026
Other Events Mercadien, P.C. CPAs ("Mercadien"), which provides internal audit-related services to SR Bancorp, Inc (the "Company") and Somerset Regal Bank (the "Bank"), has discovered a data security incident in which an unauthorized actor accessed and acquired certain files on Mercadien's computer servers.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedFinancial ServicesColumbia Machine, Inc.Mar 2026
Columbia Machine confirmed unauthorized network access and file theft, then initially concluded that only non-confidential documents were involved. A later review found additional copied files containing personal information. The incident exposed a familiar weakness: the company could see files leave before it could reliably say what those files meant.
Washington AG breach notification
Not yet quantified
VVerifiedManufacturingUSA DeBusk LLCJul 2026
USA DeBusk says an unauthorized third party accessed its systems and obtained a broad mix of identity, financial, credential, and health information. The range of data suggests that compromise of the environment crossed several information boundaries at once. The notice confirms the result but provides little evidence that those data types were meaningfully segmented before the incident.
California AG breach notification
Not yet quantified
VVerifiedProfessional and Business ServicesOne Medical disclosed unauthorized access to a third-party file-storage system containing archived patient information from its legacy Seniors business. Archived data is still data and data is valuable to the adversary. Data outlives applications, vendors and acquisitions; security architectures need to assume that every retained copy remains part of the attack surface.
Washington AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesAdaptHealth Corp.Jun 2026
A social-engineering attack compromised a third-party contractor’s user session and gave the attacker access to AdaptHealth cloud applications, patient systems and external EHR portals. Data was exfiltrated, including patient PII/PHI and insurance-billing password data. This is a clean cyber incident: compromised identity, unauthorized access and confirmed data theft.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedHealthcare and Life SciencesMarkel InsuranceMar 2026
Markel Insurance disclosed a cybersecurity incident involving unauthorized access to portions of its environment, although the company has released limited information regarding the overall scope of the breach. Public disclosures have not established the total number of affected individuals or whether policyholder information was involved. As one of the world's largest specialty insurers, any compromise involving underwriting, claims or broker information could have broader implications than a typical employee data breach. Additional details will determine the long-term significance of this incident.
California AG breach notification
Not yet quantified
VVerifiedProfessional and Business ServicesChild Care Resource CenterOct 2016
The Child Care Resource Center disclosed that an employee allegedly forwarded organizational files to an external email account over a period spanning nearly nine years, from 2016 through 2025. The nonprofit serves thousands of children and families throughout Los Angeles County and administers childcare assistance and family support programs. While the total number of affected individuals has not been publicly established, the incident potentially involves highly sensitive information relating to children, parents, providers and employees. The duration of the unauthorized activity makes this disclosure particularly noteworthy.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesAFLAC INCJun 2026
breach at Aflac Life Insurance Japan Ltd.
Other Events. On June 30, 2026, Aflac Life Insurance Japan Ltd. ("Aflac Japan"), a wholly owned subsidiary of Aflac Incorporated, a Georgia corporation (the "Company"), issued a press release announcing that, on June 25, 2026, Aflac Japan discovered an unauthorized third-party had unlawfully accessed certain of Aflac Japan systems and data.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedHealthcare and Life SciencesMonmouth UniversityFeb 2026
Monmouth University disclosed a ransomware-related incident involving personal, financial and medical information belonging to students, employees and others connected with the institution. The PEAR ransomware group claimed that it removed approximately 16 terabytes of data, although that figure has not been independently confirmed by the university. The intrusion reportedly occurred in February 2026, with the university later facing multiple lawsuits over the exposure. The combination of student records, health information and a potentially enormous volume of stolen data makes this more significant than a routine university breach notice.
California AG breach notification
Not yet quantified
VVerifiedPublic Sector and EducationThe North Los Angeles County Regional Center disclosed a ransomware attack affecting approximately 298,600 individuals. The compromised information reportedly included combinations of names, Social Security numbers, medical information, health insurance information and other personal data relating to individuals receiving developmental disability services. The organization stated that attackers accessed and copied files before encrypting systems. Given the size of the affected population and the sensitivity of the data, this represents one of the larger healthcare-related disclosures of the year.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesKubota North America CorporationMar 2026
Kubota North America disclosed that attackers accessed portions of its network and obtained employee human resources information after maintaining access for several weeks. The compromised information reportedly included Social Security numbers, driver's license information, direct deposit details, benefits information and other employment records affecting employees and their dependents.
California AG breach notification
Not yet quantified
VVerifiedManufacturingSierra Management GroupJun 2026
Sierra Management Group, a healthcare practice management provider, disclosed a ransomware attack after attackers reportedly accessed its network for several months. Public reporting indicates the incident affected approximately 38,900 individuals, while the ransomware group claimed to have stolen roughly 100 GB of information. Because Sierra provides management services for medical practices, the breach may affect patients across multiple healthcare organizations. The full scope of the impacted practices has not yet been publicly detailed.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesNissan North America Inc.May 2026
Nissan North America disclosed a newer incident involving its Oracle PeopleSoft environment, which is used to maintain employee payroll and human-resources information. Potentially exposed records reportedly included Social Security numbers, banking information, tax information and other employment data belonging to current and former workers. This follows Nissan’s separate 2023 breach affecting more than 53,000 people, which resulted in a $1.5 million proposed class-action settlement in 2026.
California AG breach notification
Not yet quantified
VVerifiedManufacturingYellow CorporationMar 2025
Yellow Corporation disclosed a data breach affecting approximately 13,000 current and former employees and dependents after the company had already entered bankruptcy proceedings. The compromised information reportedly included Social Security numbers, financial account information, government identification and health insurance information. Although the incident is modest in size compared to other breaches, it raises unique challenges because victims are seeking assistance from a company that has largely ceased operations. The disclosure demonstrates that cybersecurity obligations continue even after a company's business has ended.
California AG breach notification
Not yet quantified
VVerifiedTransportation and LogisticsMercor.io CorporationMar 2026
Mercor disclosed a breach tied to the compromise of its LiteLLM environment that reportedly exposed candidate records, interview videos, source code, API keys and internal communications. Public reporting has alleged that hundreds of gigabytes of applicant data and multiple terabytes of interview recordings and other company information were involved, although Mercor has not confirmed those figures. The incident is notable because it potentially impacts both job candidates and the AI supply chain supporting enterprise customers. Multiple class action lawsuits have already been filed.
California AG breach notification
Not yet quantified
VVerifiedTechnology and SoftwareAgelessRxJun 2026
Ageless RX experienced a data loss through their help desk system after bad actors gained access to it from April 17 to April 22, 2026. Ageless RX reported the breach in late June with no details on how many patient records were exposed. As with many of these incidents in healthcare, the only evidence of the incident beyond the filing are services being offered by the legal community to sue the breached healthcare company.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life Sciences8X8 INCJun 2026
breach at Klue
8x8 learned on June 13, 2026, that a threat actor exploited the Klue Labs application programming interface plugged into its Salesforce CRM. The filing names the vendor and the integration; it says nothing about what data moved through that connection or how many records. Klue has not said how many of its hundreds of customers are affected. Several companies have come forward to confirm they had data stolen during the attack, including Gong, Jamf, HackerOne, Insurity, OneTrust, Recorded Future, Snyk, Sprout Social, and Tanium.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedTechnology and SoftwareXsolis, Inc.Jan 2026
Healthcare technology provider Xsolis disclosed a phishing-related breach affecting approximately 1.4 million individuals, making it one of the largest healthcare data breaches reported in 2026. The company provides AI-powered utilization management and revenue cycle services to hospitals and health systems, meaning many affected patients had likely never heard of Xsolis despite their information being entrusted to the company by their healthcare providers. The compromised data reportedly included names, dates of birth, Social Security numbers, health insurance information and medical treatment information, impacting patients from organizations including Mayo Clinic, UW Medicine, VHC Health and numerous other healthcare systems.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesiRhythm Holdings, Inc.Jun 2026
Unauthorized activity struck iRhythm Holdings' data inside 'certain third-party-hosted business applications' on June 8, 2026, a phrase that names no vendor, no entry point, and no data type. The filing quantifies the damage at $700K before it quantifies what was actually taken. Outsourcing the application does not outsource the exposure; the perimeter is wherever the vendor's login page sits. A breach description this vague is not discretion; it is a structural admission that nobody yet knows the shape of the failure.
SEC 8-K, Item 1.05
Quantified 52 days after disclosure.
Losses on the record
$700K
Direct expense
VVerifiedVerified: the linked document states this figure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
Nelson UniversityMar 2025
Nelson University determined that an unauthorized actor had access to its systems for roughly two weeks, with sensitive identity and financial information implicated and later reporting connecting the event to ransomware. The lesson is not that universities need another awareness campaign; it is that unauthorized access was able to persist long enough to become consequential. Systems built around static trust are always giving attackers time they did not earn.
Washington AG breach notification
Not yet quantified
VVerifiedPublic Sector and EducationLumexa ImagingMar 2026
Lumexa Imaging disclosed that unauthorized access to a third-party vendor environment resulted in patient information being exposed. Lumexa operates more than 180 imaging centers across 13 states, making the potential downstream impact significant even though the total number of affected patients has not yet been publicly confirmed. The compromised information reportedly included patient documents associated with diagnostic imaging services. The incident illustrates the continuing cybersecurity risks posed by third-party service providers in healthcare.
Washington AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesColumbia Pacific Advisors, LLCNov 2025
Columbia Pacific Advisors experienced a breach and data exfiltration event that may include a combination of certain individuals’
names, Social Security number, date of birth, driver’s license, passport number, US alien registration number, financial account information, taxpayer identification, number, system access information, health insurance information, and medical information. The numbers of patient records and the methods through which Columbia Pacific Advisors were breached have not been disclosed.
Washington AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesPopular, IncJun 2026
breach at Evertec
Popular, Inc. was pulled into a cybersecurity incident through Evertec, the third-party provider it relies on for core financial transaction processing and IT services. The compromise affected data belonging to Banco Popular de Puerto Rico, illustrating a familiar problem: outsourcing the technology does not outsource the exposure. The attack did not need to breach Popular directly; compromising a trusted provider was enough to reach the bank’s data.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedFinancial ServicesEVERTEC, Inc.Jun 2026
Evertec reported potential unauthorized access to customer data. This is the second breach in less than 12 months for Evertec, this time impacting Puerto Rico and their respective customers instead of Brazil. Rather than reporting this as a 1.05 material incident, Evertec reported it as an 8.01 (other event), even though their Pixa breach just resulted in a 10Q financial disclosure of losses associated to the 2025 Pixa event.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedFinancial ServicesLansing Community CollegeFeb 2025
Lansing Community College disclosed that hackers used compromised credentials to access systems containing information on approximately 174,307 people. The affected population included current and former students, prospective students, employees, vendors and others whose information had accumulated in college systems. Exposed data reportedly included names, addresses, dates of birth, Social Security numbers and driver’s-license information. The college discovered the incident in February 2025 but did not begin broad notification until more than a year later.
California AG breach notification
Not yet quantified
VVerifiedPublic Sector and EducationMariner Wealth Advisors, LLCNov 2025
Mariner Wealth Advisors disclosed that approximately 8,995 individuals were affected after attackers gained access to cloud-based accounts used by several employees. The exposed information reportedly included names, Social Security numbers, dates of birth and certain financial account information, although the firm stated that its core investment platforms were not compromised. Notifications were issued several months after suspicious activity was first detected.
California AG breach notification
Not yet quantified
VVerifiedFinancial ServicesThe Oncology Institute's patient data never lived only at the Oncology Institute; it sat inside a shared claims clearinghouse that reporting ties to Cognizant's TriZetto, where an intruder had been reading records since late 2024 before anyone noticed. Route a hundred clinics and two million patients through one vendor, and that vendor becomes the front door. TOI has not said how many were exposed or what left, only that Kroll is mailing the notices: the silence is now the disclosure.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedHealthcare and Life SciencesWEST PHARMACEUTICAL SERVICES INCMay 2026
West Pharmaceutical Services makes the stoppers, seals, and injectable components much of the drug industry cannot ship without, so encrypting its systems pulled operations offline across the globe at once. The intruders lifted the data before locking the files, the rehearsed two-step now standard in the trade. No group has claimed the hit, and West has named neither the vector nor how many people the stolen data covers; when nobody boasts about a ransomware attack, the silence usually means the invoice was paid.
SEC 8-K, Item 1.05
Losses on the record
$7M
Business interruption
VVerifiedVerified: the linked document states this figure.
What the company has said it cost
The company has not disclosed a figure. The losses on the record come from other sources.
Corroborating records
Inotiv, Inc.May 2026
Inotiv's databases and internal applications went dark together in early August, because one ransomware intrusion sat close enough to both the lab work and the personnel files to take them at once. Qilin, a ransomware-as-a-service franchise rather than a lone genius, claims 176 gigabytes across roughly 162,000 files; the 9,542 people notified were mostly Inotiv's own employees and their families. How the door was first opened has gone unnamed. A firm that models drug safety could not partition its own blast radius.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedProfessional and Business ServicesCB Financial Services, Inc.May 2026
breach at Community Bank
The customer data left through an unauthorized AI application, loaded in by an employee: names, Social Security numbers, and dates of birth, handed to a chatbot no one had cleared. No attacker forced the door because none had to; the exposure was a copy operation dressed as productivity. Community Bank reached the app's vendor before the records could train a model, though it has not said how many people were fed in, or which tool swallowed them.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedFinancial ServicesCorroborating records
ITRON, INC.Apr 2026
Itron sits inside the grid itself: smart meters and the software behind them across more than 8,000 utilities, hundreds of millions of endpoints. On April 13, 2026, an unauthorized third party reached its internal IT network, and the account stops there, naming no actor, no vector, and no data confirmed taken. No ransomware crew has claimed it, which in this field reads less like safety than like an investigation that has not finished. When the vendor is this deep in the utilities' plumbing, silence about how the front door opened is not reassurance; it is the part worth watching.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedManufacturingADT Inc.Apr 2026
The break-in ran through ADT's Salesforce instance, reached not by an exploit but by phoning an employee out of their Okta login: identity treated as the perimeter folds the moment someone answers politely. What left was names, phone numbers, and addresses, with dates of birth and partial Social Security numbers for some; ShinyHunters claims over 10 million records against the roughly 5.5 million accounts others counted. A home security firm can arm every door it sells and still leave its customer list open to a phone call.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedProfessional and Business ServicesRCI HOSPITALITY HOLDINGS, INC.Apr 2026
breach at RCI Internet Services, Inc.
RCI Internet Services left an insecure direct object reference on its public-facing IIS web server, so the application checked who was logged in but never whether the record requested was actually theirs. Changing a number in the URL was enough to walk out with contractor files on about 40,178 people, Social Security and driver's license numbers included. Its remediation, adding multifactor authentication and cutting external access, names the wall that was never there. Authorization was not breached here; it was never enforced past the login screen.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedRetail and ConsumerSTRYKER CORPMar 2026
Stryker went dark in a single night, its machines factory-reset not by malware but through Microsoft Intune, the platform built to manage them, after an infostealer lifted an employee's credentials and attackers climbed them into Global Administrator. Handala, an Iran-aligned group, needed no exploit: the console that pushes software to every device can also wipe every device, gated by one login. The group claims more than 200,000 devices erased and 50 terabytes taken before the reset.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedHealthcare and Life SciencesCorroborating records
Bitcoin Depot Inc. (BTM, BTMWW)Mar 2026
Bitcoin Depot disclosed that attackers compromised internal systems and stole approximately $3.665 million in Bitcoin from company-controlled corporate wallets. The company stated that the incident involved its internal settlement accounts and, based on its investigation, did not impact customer wallets or customer cryptocurrency holdings.
SEC 8-K, Item 1.05
Quantified -2 days after disclosure.
Losses on the record
$3.665M
VVerifiedVerified: the linked document states this figure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
HASBRO, INC.Apr 2026
Hasbro spent weeks taking orders and shipping product by hand while it rebuilt the network an intruder walked into on March 28, and the $10.8 million cleanup measures the recovery, not the loss. What got in, how, and whether anything left stays unnamed: no vector, no actor, no record count, just "unauthorized access to the Company's network" and a consumer-products operation limping along on business-continuity workarounds. A breach described only by its cost is one whose architecture nobody wants to draw.
SEC 8-K, Item 8.01
Quantified 120 days after disclosure.
Losses on the record
$10.8M
Direct expense
VVerifiedVerified: the linked document states this figure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
Corroborating records
CareCloud, Inc. (CCLD, CCLDO)Mar 2026
CareCloud restored functionality within eight hours and called March 16 a temporary network disruption, but the outage was the symptom, not the breach. An unauthorized party had been inside one of its AWS environments since March 10, six days copying databases before anything showed. The count settled at 3.76 million people, Social Security numbers, financial and medical records, up from an initial 345,000. A cloud environment that registers a week of theft as an eight-hour outage was the front door all along.
SEC 8-K, Item 1.05
Quantified 132 days after disclosure.
The company's own complete incident total.
Losses on the record
$100K
Total incident cost
AAttestedAttested: a published report credits an identifiable source for this figure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
HERITAGE FINANCIAL CORPMar 2026
Heritage Bank kept the intrusion out of its customer systems, but customer data was never only there: it sat on an internal file share, the drive where employees pile names, Social Security numbers, and account details until 182,793 people live in one folder. An unnamed party copied those files, and how anyone reached a server marked internal, the bank has not said. A file share is not a filing cabinet; it is a database no one agreed to secure.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedFinancial ServicesTRIO-TECH INTERNATIONALMar 2026
Trio-Tech International's Singapore subsidiary had its files encrypted on March 11, and management filed the ransomware away as immaterial, a judgment made while the attacker still held a copy of the data. A week later the Gunra group began publishing that data on its leak site, and the non-material call rewrote itself. Materiality is not a verdict the victim keeps when the extortionist owns the appeal. How the intruders got into a chip-testing network, and how much walked out, the company has not yet said.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedManufacturingUFP TECHNOLOGIES INCFeb 2026
UFP Technologies runs a medical-device operation where the same IT plumbing prints invoices and product labels, so when ransomware arrived on February 14, 2026, billing and shipping stalled together. Payouts King, an outfit assembled from former Black Basta affiliates, claims it carried off 620 gigabytes; UFP has confirmed only that data left, not how anyone got in. When one flat network runs both the money and the labels, a single intrusion becomes a supply-chain event, and the door it used stays unnamed.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedHealthcare and Life SciencesCoupang, Inc.Dec 2025
The engineer who built Coupang's alternative authentication system left at the end of 2024 with the signing key that anchored it, then spent 2025 forging his own tokens. Investigators say he cycled through member IDs, hitting the delivery-address page some 148 million times to harvest names, phones, and addresses on roughly 37 million people, then mailed sample records back as extortion. A signing key the builder can still mint is not access control; it is a master key offboarding forgot to change.
SEC 8-K, Item 1.05
Regulatory penalty
Quantified 218 days after disclosure.
Losses on the record
$410M
Direct expense
VVerifiedVerified: the linked document states this figure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
Corroborating records
Phoenix Education Partners, Inc.Dec 2025
breach at The University of Phoenix, Inc.
The break-in came through Oracle's E-Business Suite, the back-office platform Phoenix shared with a hundred other victims, where a single zero-day in the reporting engine handed the Cl0p group the run of the place. Over ten days in August the attackers left with names, Social Security numbers, and bank routing numbers for roughly 3.5 million students, alumni, and staff; the university noticed in November. A shared enterprise platform is not infrastructure; it is one lock that opens a hundred doors.
SEC 8-K, Item 8.01
Quantified 224 days after disclosure.
Losses on the record
$5.1M
Direct expense
VVerifiedVerified: the linked document states this figure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
BayFirst Financial Corp.Oct 2025
BayFirst's customer data left through Marquis Software Solutions, the marketing vendor whose SonicWall firewall opened to a ransomware crew. Names, dates of birth, and Social Security numbers sat there because one contractor holds them for more than 700 banks and credit unions: a single breach reached 74 institutions and over 780,000 people. How many banked at BayFirst the filing does not say. A bank can lock every system it owns and still lose its customers through a vendor's front door.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedFinancial ServicesJEWETT CAMERON TRADING CO LTDOct 2025
Jewett-Cameron woke on October 15 to intruders that had settled into its corporate IT, running their own encryption and monitoring software to watch the fencing and pet-supply maker's meetings and screens from the inside. What they carried off was the financial detail being assembled for the company's annual report, the disclosure stolen before it could be disclosed. No known ransomware crew has claimed it or listed the company on a leak site, which leaves the extortion loud and its author blank.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedRetail and ConsumerF5, INC.Oct 2025
The stolen files were not customer records but F5's blueprints: BIG-IP source code and the vulnerabilities it had not yet patched, taken from the vendor whose appliances sit at the edge of 48 of the Fortune 50. Reporting ties the intrusion to a China-nexus group that held persistent access for at least a year before F5 noticed. When the vendor guarding everyone's front door keeps its unfixed flaws in one place, the perimeter and the arsenal are the same building.
SEC 8-K, Item 1.05
Quantified 113 days after disclosure.
Losses on the record
$26.5M
Direct expense
VVerifiedVerified: the linked document states this figure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record comes from other sources.
BK Technologies CorpOct 2025
BK Technologies builds the radios police and the military carry, yet its military contracts, NDAs, and employee records sat in the same corporate custody a single intruder walked through in September. Akira claims 25 gigabytes of it, though the company confirms neither the haul nor how the door was opened. When the crown jewels and the payroll sit behind one lock, the breach is not a radio problem; it is an architecture that never separated what it could not afford to lose.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedManufacturingRTX CorpSep 2025
The ransomware hit Collins Aerospace's MUSE platform, the shared check-in backbone that roughly 170 airports rent instead of running their own, so a single intrusion grounded Heathrow, Brussels, and Berlin at once. Access came through the vMUSE backend's FTP credentials, harvested by an earlier infostealer and never rotated: a legacy file transfer left standing as the door to the passenger layer. Everest claims a 50GB haul of more than 1.5 million passenger records; the airports had not built a hundred systems to breach, only one.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedManufacturingPROSPER MARKETPLACE, INCSep 2025
Prosper's breach was the database answering as designed: someone inside its systems queried the tables holding customer and applicant records and left with Social Security numbers, bank accounts, passports, and tax files on 17.6 million people. Network access was treated as permission to read the one warehouse where a lender keeps its most sensitive identity data, and months of quiet queries passed as ordinary traffic. No group has claimed the theft, leaving the adversary unnamed and the harvest complete.
SEC 8-K, Item 8.01
Quantified 57 days after disclosure.
$600K
VVerifiedFinancial ServicesWhat the company has said it cost
The company’s own disclosed figure, as it changed over time.
DATA I/O CORPSep 2025
Data I/O's intrusion came through the firewall itself, a vulnerability in a commercial third-party appliance, the box sold to be the perimeter serving instead as the door. The August 16 ransomware froze shipping, manufacturing, and communications at a company that programs chips for Apple and Bosch, and cost roughly $388,000 before systems returned by September 4. No group has claimed it and no customer data theft has surfaced, leaving the entry point named and the intruder anonymous.
SEC 8-K, Item 1.05
Quantified 218 days after disclosure.
Losses on the record
$388K
Direct expense
VVerifiedVerified: the linked document states this figure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
EVERTEC, Inc.Aug 2025
breach at Sinqia S.A.
The money moved through Sinqia's Pix environment on credentials stolen from its own IT vendors, which is what happens once a payment connector treats a supplier's login as its trust boundary. Roughly R$710 million in unauthorized transactions cleared before processing halted, aimed mostly at HSBC, with about half later frozen. Sinqia is the third Brazilian firm wired between banks and the central rail to be looted this way in a year: the soft spot in real-time payments is not the bank but the plumbing that reaches it.
SEC 8-K, Item 8.01
Quantified 66 days after disclosure.
Losses on the record
$37.7M
Direct expense
VVerifiedVerified: the linked document states this figure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
WYTEC INTERNATIONAL INCAug 2025
Wytec International's website was defaced, restored from backups, and defaced again, which is what a restore buys when it returns the content but not the hole the intruder came through. No group claimed the attack, no data theft surfaced, and no motive ever emerged, so the damage landed as operations rather than exfiltration, down to a canceled September seminar. A backup copies the site, not the way in.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedTelecommunicationsCorroborating records
VVerifiedSEC 8-K, Item 1.05 ↗
Ingram Micro Holding CorpJul 2025
The intrusion came through Ingram Micro's GlobalProtect VPN, reached with valid credentials because a gateway that trusts a password is the entire perimeter, and SafePay moved from there across a distributor wired into thousands of vendors and resellers. About 42,521 people lost names, Social Security numbers, and passport data; the group claims 3.5 terabytes and published the files, which is what a refused ransom looks like. A VPN login is a front door, not a boundary.
SEC 8-K, Item 8.01
Quantified 239 days after disclosure.
Losses on the record
$6.17M
Direct expense
VVerifiedVerified: the linked document states this figure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
ALASKA AIR GROUP, INC.Jun 2025
breach at Hawaiian Airlines
Hawaiian Airlines lost ground on June 23, 2025, to intruders who did not break the perimeter so much as phone the IT help desk and get believed. Reporting ties it to Scattered Spider, though the mechanism is the story: an identity system where whoever resets passwords is the softest wall in the building. What left stays unstated, customer names and addresses possibly reached, payment data reportedly not, the affected count never surfaced. A help desk trained to be helpful is a perimeter trained to open.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedTransportation and LogisticsUNITED NATURAL FOODS INCJun 2025
United Natural Foods pulled its own network offline to stop the June 5, 2025 intrusion, freezing the order and fulfillment systems that feed some 30,000 grocery stores, Whole Foods included. The company never named the attack or the actor, and no group claimed it; what mattered was not who got in but what a single intrusion could reach. When one distributor is the spine for a continent of shelves, the damage is counted not in stolen records but in the $350 to $400 million of orders that never shipped.
SEC 8-K, Item 1.05
Losses on the record
Separate losses, separate sources. We do not add them, because no source adds them.
Verified: the linked document states this figure.
What the company has said it cost
The company has not disclosed a figure. The losses on the record come from other sources.
NUCOR CORPMay 2025
Nucor took steel mills offline across multiple sites after a threat actor reached its corporate IT systems, the wall between office networks and the plant floor apparently thinner than the org chart suggested. The company calls the stolen data limited and the impact immaterial, though no one has said what left, how much, or who took it, and no group has claimed the attack. When an intrusion in the back office can idle a blast furnace, the boundary was never really there.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedManufacturingCorroborating records
VVerifiedSEC 8-K, Item 1.05 ↗
AFLAC INCJun 2025
Aflac contained the intrusion within hours, and by then attackers had already talked their way into employee accounts and left with data on about 22.6 million people: Social Security numbers, claims, health details. The break-in was a phone call, not an exploit; reporting ties it to Scattered Spider, though the lever was social engineering, not any flaw in the network. Fast containment is worth little when the theft finishes before the alarm does.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedHealthcare and Life SciencesZoomcar learned it had been breached the way too many companies do: an extortion note landed in its employees' inboxes announcing the data was already gone, roughly 8.4 million users' names, addresses, phone numbers, and car registrations. No monitoring caught the intrusion, no group has claimed it, and the vector stays unnamed. When the breach notification arrives from the intruder, the security program was never watching the systems, only the paperwork.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedTransportation and LogisticsERIE INDEMNITY COJun 2025
Erie Indemnity's website and business ran aground on June 7, 2025, after what the company called an information security event, with no ransomware found and no data theft confirmed. What it could not stop was the litigation: fourteen putative class actions landed within days, over an exposure still unproven. When the outage is public and the facts are not, the lawsuits arrive before the forensics do.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedFinancial ServicesCoinbase Global, Inc.May 2025
breach at Coinbase, Inc.
Coinbase's breach ran through its own support desk: overseas contractors with legitimate access to account-management tools, paid off by attackers who never needed an exploit because the credentials were already for sale. The stolen file held names, contact details, partial Social Security numbers, and government ID images for roughly 69,000 customers, the identity documents a regulated exchange is obliged to collect and then made someone else's job to guard. Coinbase refused the $20 million demand and posted a $20 million bounty instead, which does nothing to un-copy the data. The perimeter was never the network; it was a payroll, and someone made a better offer.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedFinancial ServicesThe way in ran through a developer token that opened onto GlobalX's AWS keys, and from there the whole cloud: passenger manifests, the GitHub repo, even the NAVBLUE console used to message pilots. Hackers claiming affiliation with Anonymous copied months of that data, from January through early May, then defaced the homepage to say so. When one credential is the distance between a public website and every operational system, the perimeter was never the network; it was a token nobody thought to rotate.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedTransportation and LogisticsCONDUENT IncApr 2025
A threat actor sat inside Conduent's environment for nearly three months, from October 2024 until a January 2025 disruption gave it away, long enough to take what SafePay claims was roughly 8 terabytes. Conduent is the back office that governments and health plans outsource to, so one intrusion became a front door to their end-users, a count that has climbed from 10 million toward 60 million as the forensics catch up. When the processor is the perimeter, its dwell time becomes everyone's.
SEC 8-K, Item 1.05
Quantified 23 days after disclosure.
Losses on the record
$25M
Direct expense
VVerifiedVerified: the linked document states this figure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
DAVITA INC.Apr 2025
DaVita's ransomware sat inside its dialysis labs for three weeks before discovery, and the encryption was the loud part; the quiet part was a labs database pooling 2.7 million people's Social Security numbers, dialysis results, and scanned images of their personal checks. A treatment provider had become a warehouse of financial identity, the fate of any database asked to hold everything. Interlock, which claimed the theft and leaked the files, needed no exploit, only the weeks the network gave it.
SEC 8-K, Item 8.01
Quantified 113 days after disclosure.
Company-stated total, of which: direct response costs $13.5M.
Losses on the record
$25M
Total incident cost
VVerified$13.5M
Direct expense
Verified: the linked document states this figure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. Some losses on the record come from this disclosure; others come from separate sources.
Sensata Technologies Holding plcApr 2025
Sensata's business is sensing and measurement, yet an intruder moved through its network for nine days before ransomware announced itself by freezing the shipping and production lines. What left was not customer telemetry but the workforce itself: Social Security numbers, passports, and medical records of roughly 15,630 current and former employees, pooled on the same reachable network as the machinery. No group ever claimed it and the files never surfaced on a leak site, which is theft you cannot negotiate back.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedManufacturingNATIONAL PRESTO INDUSTRIES INCMar 2025
National Presto's outage on March 1, 2025, halted manufacturing, shipping, and receiving together, the predictable result when a company making both pressure cookers and munitions runs them across one shared back office. The intrusion reached National Defense Corporation, its ordnance subsidiary, through that common spine; how the door opened was never disclosed. InterLock claimed the hit and roughly 3 million stolen files, then met a company that declined to pay on the theory a defense maker's data was worthless to anyone.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedManufacturingNioCorp's intruders needed no exploit, just a foothold in its email, because the mining company's vendor payment process trusted whatever the inbox told it. About $500,000 walked out to a fraudulent account before anyone caught the reroute: an invoice redirected by a plausible message, not a breached network. No group has been named and no personal records were said to leave; the whole loss was the price of letting email stand in for a signed authorization.
SEC 8-K, Item 8.01
Quantified 78 days after disclosure.
Losses on the record
$506K
VVerifiedVerified: the linked document states this figure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record comes from other sources.
LEE ENTERPRISES, IncFeb 2025
Lee Enterprises ran its 72 newspapers on shared core systems, so when ransomware encrypted them on February 3, 2025, distribution, billing, collections, and vendor payments stopped at once. The 350GB that left, by the attackers' count, held Social Security numbers and health details belonging mostly to Lee's own current and former employees, not its readers. Qilin claimed the theft and recovery ran about $2 million: one intrusion, and no internal boundary anywhere to slow it.
SEC 8-K, Item 1.05
Quantified 444 days after disclosure.
Losses on the record
$10.5M
Business interruption
AAttestedAttested: a published report credits an identifiable source for this figure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
ENGLOBAL CORPNov 2024
ENGlobal, a small engineering contractor woven into the energy sector and the federal supply chain, spent roughly six weeks locked out of its own financial systems after a threat actor encrypted its files and reached the personal data held in the same IT estate. Neither the entry vector nor the number of people exposed was ever named, and no ransomware group claimed the intrusion. For a firm whose product is trust across critical infrastructure, a flat internal network is not a footnote; it is the whole exposure.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedProfessional and Business ServicesLKQ CORPDec 2024
LKQ contained the November intrusion the only way a sprawling parts conglomerate can, by walling off the single Canadian business unit whose IT systems attackers had reached, and operations there stalled for weeks. No group claimed it and no tally of what left was ever offered, which is its own kind of disclosure. Containment by amputation is not resilience; it is an admission the segment was already standing alone.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedWholesale and DistributionKrispy Kreme, Inc.Dec 2024
The outage that halted online doughnut orders was the visible damage; the real loss was the identity file of roughly 161,000 people, almost all of them staff and their families, holding Social Security numbers, passports, biometrics, and military IDs. Play claimed the intrusion and leaked 184 gigabytes after the ransom went unpaid, though how the systems were first entered was never stated. A doughnut seller kept an HR intelligence dossier on the people who fry them, and that is the file the breach walked out with.
SEC 8-K, Item 1.05
Quantified 148 days after disclosure.
Losses on the record
Separate losses, separate sources. We do not add them, because no source adds them.
Verified: the linked document states this figure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The losses on the record come from other sources.
ARTIVION, INC.Dec 2024
Artivion, a maker of heart-surgery devices, was breached in a single day: an intruder copied files on November 20 and was gone by the 21st, ahead of the alarm. What left was not device blueprints but the back office, its own employees' Social Security numbers, passports, and direct deposit details, the HR store guarded like an afterthought. No group ever claimed the intrusion and the company never named the way in, so the tally surfaced one state at a time: 5,608 in Texas, thousands more counted elsewhere.
SEC 8-K, Item 8.01
Quantified 436 days after disclosure.
Company-stated total, of which: direct response costs $3.5M.
Losses on the record
$4.6M
Total incident cost
VVerified$3.5M
Direct expense
Verified: the linked document states this figure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. Some losses on the record come from this disclosure; others come from separate sources.
iLearningEngines lost $250,000 not to an exploit but to its own inbox: a threat actor moved through the company's email, redirected a wire, and deleted the messages that would have shown the switch. No ransomware crew claimed it and the company named no actor, which is business email compromise working as designed. When the mailbox is the authorization for a payment, the money goes wherever the mailbox says, and this money was never recovered.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedTechnology and SoftwareNEWPARK RESOURCES INCOct 2024
Newpark Resources kept its plants and rigs running on manual downtime procedures while ransomware took the internal systems that keep the books, a reminder that in an oilfield supplier the office network and the shop floor are two separate failure domains, wired as one. What never surfaced is the rest of it: no group claimed the intrusion, no files reached a leak site, no count of affected records was ever put on the record. The silence is not reassurance; it is the sound of no one having finished counting.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedProfessional and Business ServicesKarat Packaging Inc.Oct 2024
Karat Packaging activated its cybersecurity response plan on October 18, 2024, after unauthorized third-party access reached its information systems, and that is very nearly the whole of the public account. No vector, no named actor, no count of the people behind the records: the filing offers a plan and a contained threat and leaves the architecture unlit. A breach that can be closed out without ever explaining how the door opened is not a resolved incident; it is a disclosure that discloses nothing.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedManufacturingHEALTHCARE SERVICES GROUP INCOct 2024
Healthcare Services Group handles the dining, laundry, and housekeeping for healthcare facilities, yet it held the Social Security numbers, financial accounts, and insurance records of 624,496 patients and employees across 48 states. Intruders moved through its systems for a week before anyone noticed on October 7, and the company still has not said how they got in. The ransomware group Underground claims 1.1 terabytes, a figure HCSG has not confirmed. When a janitorial contractor becomes a warehouse of medical identity, the breach was in the org chart long before it was in the network.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedHealthcare and Life SciencesADT Inc.Oct 2024
ADT's network was reached not through ADT but through a third-party business partner, whose compromised credentials let an unauthorized actor walk in and leave with encrypted internal data on employee accounts. Customer alarm codes were spared this time, though it was ADT's second intrusion in two months. When the trust boundary is drawn to include every partner holding a valid login, the perimeter is only as sound as the weakest vendor's password. ADT named no attacker, and the silence is doing work.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedProfessional and Business ServicesAmerican Water pulled its MyWater portal and paused billing to wall off unauthorized activity inside its corporate networks, then reassured 14 million customers that the water itself was never touched. That reassurance is the tell: the intrusion lived in the customer-facing IT stack, while the operational technology that treats the water sat behind a trust boundary that actually held. Months on, the largest water utility in the country had named neither the actor nor the vector, certain of what stayed safe and silent on what got in.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedEnergy and UtilitiesHALLIBURTON COAug 2024
Halliburton pulled its own applications offline as a precaution, and in doing so showed how thin the wall was between corporate IT and oilfield operations: with production planning and shipment tracking down, customers could not cut a purchase order. Data left the building, though no count of the people behind the records ever followed. Reporting ties the intrusion to RansomHub, and the $35 million booked was the price of a boundary that lived mostly on paper.
SEC 8-K, Item 1.05
Losses on the record
$35M
Direct expense
VVerifiedVerified: the linked document states this figure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
DICK'S SPORTING GOODS, INC.Aug 2024
Dick's Sporting Goods contained the intrusion by locking all of its roughly 55,500 employees out of their own accounts, restoring access only after IT verified identities one video call at a time. When credentials are the perimeter, containment means treating the entire workforce as a suspect. What was taken, who took it, and how many people it reached were never named: an intrusion acknowledged, and almost nothing around it.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedRetail and ConsumerMICROCHIP TECHNOLOGY INCAug 2024
Microchip Technology's fabs slowed below normal output after intruders disrupted the servers running its business, proof that a semiconductor plant is only as isolated as its weakest office network. The confirmed theft was modest, employee contact details and some hashed passwords, though the Play ransomware group, which claimed it, says it left with payroll, contracts, and IDs. How the access was gained went unnamed: when an IT breach can idle a factory floor, the boundary between the two was drawn as a wish.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedTechnology and SoftwareCorroborating records
VVerifiedSEC 8-K, Item 8.01 ↗
ENZO BIOCHEM INCAug 2024
Enzo Biochem lost the clinical records of roughly 2.47 million people through two employee logins, one left unchanged for a decade and shared among five staff, with no second factor standing between an email password and the lab's patient data. What walked out was names, test results, and about 600,000 Social Security numbers. A credential shared by five people and rotated once a decade is not authentication; it is a group password taped to the door.
SEC 8-K, Item 8.01
Quantified 76 days after disclosure.
Losses on the record
Separate losses, separate sources. We do not add them, because no source adds them.
Verified: the linked document states this figure.
Attested: a published report credits an identifiable source for this figure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The losses on the record come from other sources.
ADT Inc.Aug 2024
A company that sells perimeters for a living left its own customer order database reachable, and unauthorized actors walked out with the names, addresses, phone numbers, and purchase histories of roughly 30,000 people. How the door was opened, ADT never said; a forum poster called netnsher claimed the haul at 30,812 records before the filing caught up. The alarm company that watches everyone else's doors heard nothing until its customers were already listed for sale.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedProfessional and Business ServicesBASSETT FURNITURE INDUSTRIES INCJul 2024
Bassett Furniture ran its factories on the same IT estate as its back office, so when a ransomware crew encrypted a portion of its files, containment meant idling every manufacturing floor for four and a half days. No group claimed the attack, and the company named neither the vector nor the actor, leaving the entry point a blank. The plants did not fall to a genius adversary; the only firebreak between the corporate network and the production line was the power switch.
SEC 8-K, Item 1.05
Quantified 65 days after disclosure.
Losses on the record
Separate losses, separate sources. We do not add them, because no source adds them.
Verified: the linked document states this figure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. Some losses on the record come from this disclosure; others come from separate sources.
META MATERIALS INC.Jul 2024
Meta Materials lost its website and email for four days in July 2024, not to an outside intruder but to a former executive who still held the keys and cancelled the renewal on his way out. The company had wired its public presence and stakeholder mail to a single registration one departed insider could revoke, because offboarding never took the credential back. No data theft was claimed, and the executive went unnamed: the failure was an access list that never noticed he had left.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedManufacturingCencora, Inc.Feb 2024
Cencora distributes drugs, but through its Lash Group patient-support arm it had become the record-keeper for more than a dozen rival drugmakers, so one February intrusion emptied the patient files of Bayer, Novartis, and Bristol Myers Squibb at once. Names, diagnoses, and medications for at least 1.43 million people left through a single back-office unit no one filed as a front door. Reporting ties the theft to Dark Angels and puts the ransom near $75 million, the largest known, which only buys a promise the copy was deleted.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedWholesale and DistributionCadre Holdings, Inc.Jul 2024
Cadre Holdings arms police and bomb squads for a living, and its answer to an unauthorized third party inside certain technology systems in July 2024 was to take machines offline and wait. What data left, who took it, and how they got in all went unnamed, by the company and by any group that might have claimed it. A firm built to sell survivability could describe the threat to everyone but itself.
SEC 8-K, Item 8.01
Losses on the record
Separate losses, separate sources. We do not add them, because no source adds them.
Verified: the linked document states this figure.
What the company has said it cost
The company has not disclosed a figure. The losses on the record come from other sources.
AUTONATION, INC.Jul 2024
AutoNation lost no data of its own; it lost CDK Global, the dealer-management system 15,000 dealerships treat as the floor they stand on, taken down through a single phishing email by ransomware that reporting ties to BlackSuit. An always-on VPN had already seated the vendor inside every dealer's network, so one compromise closed an industry from a data center no dealer owned. The $1.50-a-share hit is what vendor concentration charges when the front door belongs to someone else.
SEC 8-K, Item 8.01
Quantified 17 days after disclosure.
Losses on the record
$43M
Direct expense
VVerifiedVerified: the linked document states this figure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
REPLIGEN CORPJul 2024
An unauthorized party reached certain files on Repligen's systems in July 2024, and the company's account stopped there: no count, no vector, no name. The scope surfaced elsewhere, on INC Ransom's leak site, where the group claimed roughly 500 gigabytes. When the most specific figure for a breach lives on the extortion group's directory and not in the filing, the accounting has been outsourced to the party that took the data.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedHealthcare and Life SciencesThe breach was in a Snowflake data warehouse, not AT&T's network, reached with stolen passwords because no second factor stood in the way, and it held the call and text records of nearly every AT&T customer. Not the words, just who contacted whom, how long, and roughly where: the shape of 110 million lives. AT&T reportedly paid about $370,000 to have the file deleted, which assumes a copy is a thing you can take back.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedTelecommunicationsCrimson Wine Group, LtdJun 2024
Crimson Wine Group pulled its own systems off the internet to stop the intrusion, which tells you the network was flat enough that containment and full shutdown were the same act. What a winery was doing holding Social Security numbers, driver's licenses, and medical records on 26,238 people goes unexplained, as does how the third party got in: no vector, no actor, no group was ever named. The data a business keeps is the data it eventually loses.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedManufacturingCorroborating records
VVerifiedSEC 8-K, Item 1.05 ↗
HEALTHEQUITY, INC.Jul 2024
A business partner's personal-use device carried the malware, and the account it compromised reached straight into a SharePoint repository holding data on about 4.3 million people: Social Security numbers, diagnoses, prescriptions. The vendor's laptop sat inside the trust boundary, and the member records sat in a shared drive rather than a guarded system. That access ran from March to late June before anyone noticed, which is less a break-in than a tenancy.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedProfessional and Business ServicesAffirm Holdings, Inc.Jun 2024
Affirm's systems were never touched; the breach was at Evolve Bank & Trust, the sponsor bank that issues the Affirm Card and holds the customer data a fintech front end never keeps. One malicious link inside Evolve exposed names, Social Security numbers, and account details across its fintech partners, and reporting credits LockBit, which leaked the file when the ransom went unpaid. When the ledger lives at the sponsor bank, a fintech's own security is beside the point: the bank is the single door everyone's data waits behind.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedFinancial ServicesLITHIA MOTORS INCJun 2024
Lithia Motors was not breached; the dealer management system it and thousands of other dealerships run sales, financing, and customer records through was. That platform belongs to CDK Global, one vendor that had quietly become the operational nervous system of American car retail, so a single ransomware intrusion, reported to be BlackSuit's, sent roughly 15,000 dealer locations back to pen and paper at once. Outsourcing the entire front office to one platform is efficient right up to the morning it stops answering.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedRetail and ConsumerGROUP 1 AUTOMOTIVE INCJun 2024
Group 1's U.S. dealerships ran sales, service, and back office through CDK, so when a ransomware crew took the vendor dark, thousands of storefronts went dark with it. The failure was not a breach of Group 1's network but a single point of dependence: the dealer management platform was the business, and someone else owned it. No records are believed to have left, only the uptime; the company booked $10 million in insurance for a spine it had outsourced.
SEC 8-K, Item 8.01
Quantified 235 days after disclosure.
Losses on the record
$5.9M
Direct expense
VVerifiedVerified: the linked document states this figure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
PENSKE AUTOMOTIVE GROUP, INC.Jun 2024
Penske's own network held; what went dark was CDK Global, the dealer management software running its Premier Truck Group back office, hit by ransomware that reporting ties to the BlackSuit group. When one vendor is the operating system for roughly 15,000 dealerships, its outage is your outage, and Premier Truck spent the shutdown selling heavy trucks on paper. Concentration is not a convenience here: it is a single point of failure with a logo.
SEC 8-K, Item 8.01
Quantified 496 days after disclosure.
The company's own complete incident total.
Losses on the record
$2.5M
Total incident cost
VVerifiedVerified: the linked document states this figure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
SONIC AUTOMOTIVE INCJun 2024
Sonic Automotive could not sell cars for the better part of two weeks, not because its own network fell but because CDK Global, the single vendor running its dealer management system, was ransomwared by a crew reporting ties to BlackSuit. When one SaaS provider is the floor beneath every franchise's sales, inventory, and accounting, its outage is the dealership's outage. Sonic booked a material hit to the quarter over software it did not run and could not bring back.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedRetail and ConsumerGLOBE LIFE INC. (GL, GL-PD)Jun 2024
Globe Life's agent web portal ran on access permissions and identity checks that could not tell a real user from an impostor, and that portal was the door out. Because the records sat in databases held by its independent agency owners rather than one hardened store, a single portal flaw reached roughly 850,000 people: names, Social Security numbers, health details. The company named the extortion note that followed, never the attacker behind it. When identity is the only lock, a broken check is the whole breach.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedFinancial ServicesKEY TRONIC CORPMay 2024
Key Tronic's plants in Washington and Mexico sat idle for two weeks in May 2024, not because a machine broke but because the office IT they run on was encrypted, one trust boundary shared between the business network and the factory floor. Black Basta claimed the intrusion and leaked roughly 530 gigabytes, employee passports and Social Security cards among it, while the company confirmed personal data had left the building. How the access first began was never named. The bill ran to about $17 million, most of it revenue that simply stopped when a breach reached the plant floor.
SEC 8-K, Item 1.05
Quantified 53 days after disclosure.
Losses on the record
Separate losses, separate sources. We do not add them, because no source adds them.
Verified: the linked document states this figure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. Some losses on the record come from this disclosure; others come from separate sources.
KULICKE & SOFFA INDUSTRIES INCMay 2024
Kulicke and Soffa caught unauthorized access on May 12, 2024, and first concluded no data had left; the group calling itself LockBit claimed it had been inside for months and walked out with roughly 12 million files, source code, engineering drawings, business partner records, and personal information among them. A network that treats detection as the whole of its defense learns the size of the intrusion only after the intruder publishes it. The alarm marked the end of the visit, not the start.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedTechnology and SoftwareBRANDYWINE REALTY TRUSTMay 2024
A third party encrypted part of Brandywine Realty Trust's corporate IT estate on May 1, 2024, the same one that ran financial reporting and held personal files, with nothing between the back office and the data. The encryption was the noise; the theft was the quiet part, files walked out before the locks went on. No group claimed it and no victim count surfaced, an unusual silence for a landlord that could not say who had been in the building.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedReal Estate and ConstructionDocGo Inc.May 2024
A threat actor spent four days inside DocGo's U.S. ambulance operation, long enough to copy names, Social Security numbers, insurance claims, and treatment records. The company called it a limited number of healthcare records; the notification list came to roughly 858,000 people. How the intruder got in was never named, which is its own architecture: a mobile-medical roll-up bolts ambulance services together faster than it maps where the trust boundaries sit.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedHealthcare and Life SciencesDROPBOX, INC.Apr 2024
Dropbox Sign's production environment was reached through a compromised service account, a non-human identity carrying broad standing privileges that nobody was watching, and from there the intruder reached the customer database. Every user's email and username left, and for a subset so did the API keys, OAuth tokens, and MFA material: at a signature company, the very proofs of identity walked out as loot. The actor was never named.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedTechnology and SoftwareUNITEDHEALTH GROUP INCFeb 2024
The intrusion reached Change Healthcare through a Citrix portal with no second factor, one stolen credential opening a clearinghouse that routes roughly a third of American medical claims. Nine quiet days later the records of about 192.7 million people were gone, the largest healthcare breach on record, because a country wired its billing through a single chokepoint and guarded it with a password. UnitedHealth paid $22 million to bury the files, then watched a second crew arrive to extort the same data again.
SEC 8-K, Item 1.05
Quantified 15 days after disclosure.
Company-stated total, of which: direct response costs $2.2B, business disruption $867M.
Losses on the record
$3.09B
Total incident cost
VVerified$2.2B
Direct expense
$867M
Business interruption
FY2024$3.09B
FY2025+ $799M
to date$3.89B
Our sum across non-overlapping fiscal periods; not a single company-stated figure.
Verified: the linked document states this figure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. Some losses on the record come from this disclosure; others come from separate sources.
Frontier pulled portions of its IT environment offline the day it detected the intruder, which is what containment looks like when one open door reaches the rest of the house. RansomHub, which claimed the theft, put it at more than two million people; Frontier's own notice came to roughly 751,000: names, Social Security numbers, dates of birth. How the access was gained was never stated. The count an extortion crew posts and the count a company files are rarely the same, and only one of them carries a penalty for being wrong.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedTelecommunicationsORASURE TECHNOLOGIES INCApr 2024
OraSure Technologies builds the tests that carry the most sensitive data a person has, HIV results and genetic samples through its DNA Genotek arm, and the intrusion it contained in late March 2024 was described only as files taken from certain systems. The company vouched for its core financial and operational machinery while the real question, whose health data left and how much, went unanswered. No count, no vector, no named data: a breach a company cannot describe is not contained, it is only quiet.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedHealthcare and Life SciencesTargus shut its own network down to stop the intrusion, a reflex that reveals where the sensitive data sat: not in a hardened vault but in ordinary file servers, where a single foothold reaches everything, Social Security numbers included. How the threat actor got in was never stated, and the count of people affected never arrived at all. Red Ransomware claimed the theft, and Targus took roughly six months to say what had actually left.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedFinancial ServicesMARINEMAX INCMar 2024
An intruder moved through MarineMax's systems for ten days before the boat retailer noticed, leaving with the personal data of roughly 123,000 customers and employees, driver's licenses and passports included. The company first assured regulators that nothing sensitive lived on the breached systems, then reversed itself two weeks later: it could not map what its own network held. Rhysida claimed the theft and posted a 225 gigabyte archive, and a firm that cannot inventory its data is in no position to dispute the count.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedRetail and ConsumerSouthState CorpFeb 2024
An intrusion reached SouthState's network on February 7, 2024, and the unauthorized party walked into folders holding more than 840,000 people's Social Security numbers and account details, which the class action alleges sat unencrypted. The exposure was not the break-in; it was a bank storing its most sensitive records in a shared drive and trusting the outer edge to hold. SouthState never named the actor or the vector, leaving the count as the only firm fact in the file.
SEC 8-K, Item 1.05
Quantified 35 days after disclosure.
Losses on the record
$8.3M
Direct expense
VVerifiedVerified: the linked document states this figure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
RADIANT LOGISTICS, INCMar 2024
Radiant Logistics contained the intrusion by cutting its Canadian operations loose from the rest of the network, a tidy way of admitting the boundary did not exist until the fire forced someone to draw it. Segmentation improvised mid-attack is not architecture; it is triage. What got in, whether data left, and how many people sat behind that suddenly necessary wall all went unsaid, and the only name attached to the breach surfaced later on Akira's leak site, not in Radiant's own telling.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedTransportation and LogisticsMICROSOFT CORPJan 2024
The intrusion ran through a legacy test tenant Microsoft had left standing with no multifactor authentication and a guessable password, which a password spray walked straight into. From there the attackers reached an old test OAuth app that still carried full access to corporate mailboxes, and read the email of senior leadership, cybersecurity, and legal. The perimeter that failed was not a network but a forgotten account the security giant never turned off; Microsoft named the actor as Midnight Blizzard, a Russian state group.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedTechnology and SoftwareThe fraud reached the Federal Home Loan Bank of New York through a fourth-party vendor, a supplier of one of its own suppliers, a party the Bank never contracted with yet left a path toward its funds. Its operational controls caught the attempt on February 21, 2024, and no money moved. Neither the compromised firm nor the people behind it was ever named: the trust boundary ran one vendor past anyone the Bank could actually see.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedFinancial ServicesloanDepot, Inc.Jan 2024
loanDepot ran origination, servicing, and its customer portal on ground flat enough that one phished login could encrypt the whole thing and reach roughly 16.6 million people's Social Security numbers, financial accounts, and loan files. ALPHV/BlackCat claimed the intrusion and demanded $10 million; the company refused, then spent three weeks and about $27 million rebuilding what a single email had unlocked. A network with no interior walls is not breached so much as opened.
SEC 8-K, Item 8.01
Quantified 380 days after disclosure.
Company-stated total, of which: direct response costs $1.8M.
Losses on the record
$24.6M
Total incident cost
VVerified$1.8M
Direct expense
Verified: the linked document states this figure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. Some losses on the record come from this disclosure; others come from separate sources.
The intruders walked in through employee and contractor accounts, the kind of access that treats a valid login as proof of belonging, and left with names, addresses, and driver's license numbers. Prudential first put the count at roughly 36,000; the final tally was 2,556,210, a blast radius it underestimated by close to seventy to one. ALPHV claimed the theft on its leak site, but the harder number is how long the company took to learn the size of its own breach.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedFinancial ServicesWILLIS LEASE FINANCE CORPFeb 2024
Willis Lease Finance took systems offline on January 31, 2024, after intruders reached the archive an aircraft-engine lessor quietly accumulates: employee Social Security numbers, passport scans, airline leasing agreements, the NDAs that bind them. How the intrusion happened was never stated; what left was, once Black Basta claimed the theft and posted roughly 910 GB to its leak site. A niche financier is still a warehouse of everyone else's secrets, which is why one break-in spills an entire industry's paperwork.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedFinancial ServicesHewlett Packard Enterprise CoJan 2024
Midnight Blizzard, the crew tied to Russia's SVR, sat inside HPE's cloud email environment for months before anyone noticed, reading the mailboxes of the cybersecurity, marketing, and business teams themselves. How the door opened HPE never said; what it left on the record is a mail tenant treated as the soft interior of the network, where a nation-state could browse the security team's own inbox at its leisure. Dwell time here was measured in seasons, not minutes.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedTechnology and SoftwareV F CORPDec 2023
VF Corporation runs Vans, The North Face, Timberland, and Supreme off one shared operational core, which is why a single December intrusion reached the personal data of about 35.5 million consumers. The company took its systems offline mid-holiday, then noted it retains no card numbers or Social Security numbers, as if the names, addresses, and order histories that did leave were a consolation prize. Reporting ties the attack to the ALPHV/BlackCat crew; how the access was gained VF never said.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedManufacturingFidelity National Financial locked its own systems to stop the intrusion and froze the title and escrow work sitting at the center of American home closings: hundreds of sales stalled because one title insurer went dark. Non-self-propagating malware still left with data on about 1.3 million people, names, Social Security numbers, loan numbers, from a network where one foothold reached far more than it should have. ALPHV/BlackCat claimed the attack and quietly pulled FNF from its leak site by mid-December, the usual tell of a ransom paid.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedFinancial ServicesFirst American Financial CorpDec 2023
First American took its website, email, and much of its network offline in late December 2023 after intruders reached certain non-production servers, copied their contents, and encrypted the rest. The company never named the group, the vector, or the ransom, so the architecture speaks for itself: the names and driver's license numbers of about 44,000 people sat on machines it classified as non-production. Non-production is a label about the server, not the people whose identities lived on it.
SEC 8-K, Item 1.05
Quantified 54 days after disclosure.
Losses on the record
$11M
Direct expense
VVerifiedVerified: the linked document states this figure.
What the company has said it cost
The company has not disclosed a figure. The losses on the record come from other sources.
Corroborating records
HealthplexMar 2023
Healthplex’s phishing incident exposed the personal and health information of approximately 89,955 people, including nearly 64,000 New York residents. The attacker gained access to an employee mailbox containing more than 100,000 emails accumulated over roughly 20 years, while the company lacked both an effective retention policy and required multifactor authentication. Healthplex ultimately paid $400,000 to the New York attorney general and another $2 million to the New York Department of Financial Services. This is a useful impact example because the consequences are established: tens of thousands of victims, years of unnecessary data retention and $2.4 million in regulatory penalties.
NYDFS cybersecurity enforcement action
Regulatory penalty
Not yet quantified
VVerifiedHealthcare and Life SciencesCorroborating records