SQ Magazine The Threat Index Tracker

Data Breach Tracker

This tracker records every major breach disclosed since January 2024. Each row gives the organization, the disclosure date, how many people were affected, and the attack vector, with a link to the primary source.

21 records updated through 2 Jul 2026

Latest change Every new row verified against SEC filings, the HHS OCR portal, or the company's own notice; counts publish only where a primary source states one (24 Jul 2026) All changes

Breaches tracked
21
At least affected · 7 disclosed counts
59,531,667
Sectors
7
Re-verify cycle
30day
Every row links our own report where we have one; the primary source is always in the record detail. Counts are as stated at disclosure and are often revised later.
Organization Disclosed Records (as disclosed) Sector Vector Our report Record detail
AdaptHealth 2 Jul 2026 Undisclosed Healthcare Phishing SEC EDGAR (Form 8-K, Item 1.05) ↗
What was exposed
Medical records Credentials / passwords
Country
United States
Last confirmed
23 Jul 2026

Record count revised. Verified 2026-07-23 via primary sources (AdaptHealth SEC 8-K). Threat actor contacted the company 2026-06-15; materiality determined 2026-06-27. Attacker compromised a third-party contractor user session via social engineering and accessed cloud-based patient-management systems and document storage, exfiltrating stored password files tied to insurance-billing and external EHR portals containing patient PHI. Volume at risk not quantified. Large US home-medical-equipment provider. Originally ingested from SEC EDGAR Item 1.05.

Navient 2 Jul 2026 Undisclosed Finance & banking Ransomware SEC EDGAR (Form 8-K, Item 1.05) ↗
Xsolis 5 Jun 2026 1,396,519 Healthcare Phishing HHS Office for Civil Rights breach portal ↗
What was exposed
Names Dates of birth Social Security numbers Medical records
Occurred → disclosed
20 Jan 2026 → 5 Jun 2026
136-day gap
Country
United States
Last confirmed
23 Jul 2026

Record count revised. Verified 2026-07-23 via HHS OCR (1,396,519) plus multiple outlets citing the Xsolis notice. Tennessee healthcare-AI vendor (HIPAA business associate) breached via a targeted phishing email to a single employee; unauthorized access 2026-01-20 to 2026-01-22. Exposed names, dates of birth, Social Security numbers, health-insurance and medical-treatment information for 1,396,519 individuals across seven-to-eight hospital systems including Mayo Clinic. HHS OCR posted the figure 2026-06-22; breach report dated 2026-06-05. One of the largest US healthcare incidents of the year. Originally ingested from the HHS OCR breach portal.

West Pharmaceutical Services 11 May 2026 Undisclosed Healthcare Ransomware SEC EDGAR (Form 8-K, Item 1.05) ↗
Country
United States
Last confirmed
23 Jul 2026

Record count revised. Verified 2026-07-23 via primary sources (West SEC 8-K and 8-K/A). Detected a compromise 2026-05-04; determined material 2026-05-07. Ransomware: data exfiltrated and systems encrypted; company took systems offline globally and engaged Palo Alto Unit 42. Scope of affected data still under investigation; individual count not disclosed. S&P 500 pharmaceutical-packaging and drug-delivery supplier. Fold of 8-K/A 27890 (2026-05-20, operations restored). Originally ingested from SEC EDGAR Item 1.05.

Stryker 9 Apr 2026 Undisclosed Healthcare Unknown Iran Linked Hackers Claim Massive Attack on Stryker →
Occurred → disclosed
11 Mar 2026 → 9 Apr 2026
29-day gap
Country
United States
Attributed to
Handala (Iran-linked hacktivist group)
Last confirmed
23 Jul 2026

Record count revised. Verified 2026-07-23 via primary sources (Stryker SEC 8-K/A + company customer notice). Identified 2026-03-11. Attributed to Handala, an Iran-linked hacktivist group, which weaponized Stryker Microsoft Intune device-management platform to wipe data from thousands of devices (destructive/wiper attack). Disrupted order processing, manufacturing and shipping; material impact to Q1 2026 results, no material impact to full-year guidance. 8-K/A filed 2026-04-09. SQ covered as post 19568. Originally ingested from SEC EDGAR Item 1.05. PII exfiltration unconfirmed as of Jul 2026: attackers claim data theft, the company has not confirmed it, and class-action litigation is ongoing. Listed with an Undisclosed count on that basis; owner call 2026-07-24 to include; update when the record clarifies.

Nacogdoches Memorial Hospital 30 Mar 2026 2,507,073 Healthcare HHS OCR Breach Portal (Cases Currently Under Investigation) ↗
What was exposed
Names Postal addresses Phone numbers Email addresses Social Security numbers Dates of birth Medical records
Occurred → disclosed
15 Jan 2026 → 30 Mar 2026
74-day gap
Country
United States
Last confirmed
24 Jul 2026

Record count revised. Verified 2026-07-24 against the HHS OCR Breach Portal. Listed as Nacogdoches Memorial Hospital, Healthcare Provider (TX), 2,507,073 individuals, Hacking/IT Incident, Network Server, breach submission date 03/30/2026. DISCREPANCY FLAG: the hospital's public messaging and early press (SecurityWeek, Paubox) cite roughly 250,000 / 257,073 individuals, but the HHS OCR filing states 2,507,073; per task instruction the OCR figure is used. An editor should confirm before publishing given the ~10x gap. Unauthorized access to the network 2026-01-15 to 2026-01-31; discovered 2026-01-31; consumer notifications began 2026-03-31. Data involved: names, addresses, phone numbers, email addresses, SSNs, dates of birth, medical record numbers, account numbers, health plan beneficiary numbers, and photographs. No known ransomware group claimed responsibility; threat actor not disclosed. Count authority: OCR portal.

NYC Health + Hospitals 24 Mar 2026 Undisclosed Healthcare Third-party / supply chain NYC Health + Hospitals - Notice of Data Breach (official) ↗
What was exposed
Names Postal addresses Medical records Financial account data Social Security numbers Government ID numbers Biometric data
Occurred → disclosed
25 Nov 2025 → 24 Mar 2026
119-day gap
Country
United States
Last confirmed
24 Jul 2026

Record count revised. Verified 2026-07-24. records left blank (Undisclosed) per task instruction: the OCR portal shows NO exact figure for this incident. Every source describes the count as approximately / up to / at least 1.8 million current and former patients and employees - never an exact posted number. NOTE: the OCR portal does list a SEPARATE, unrelated NYC Health + Hospitals entry of 5,728 individuals submitted 06/06/2025, which is a different and much smaller incident and NOT this breach; this mega-breach (reported to HHS 2026-03-24) was not yet individually posted on the public portal at time of verification. Per the official Notice of Data Breach: an unauthorized third party exploited a flaw in an unnamed third-party vendor (hence vector supply-chain), had access 2025-11-25 to 2026-02-11; NYC H+H discovered suspicious activity 2026-02-02. Data involved: demographic, medical, insurance and billing information, SSNs, government identification numbers, and biometric data including fingerprints and palm prints. Primary source: NYC Health + Hospitals official Notice of Data Breach. PUBLISH-READY only if the Undisclosed count is acceptable to the editor; otherwise hold for the exact OCR figure once posted.

Navia Benefit Solutions 18 Mar 2026 2,151,330 Healthcare 2.7 Million Affected in Navia Cyberattack Linked to API Flaw →
QualDerm Partners 22 Feb 2026 3,117,874 Healthcare HHS OCR Breach Portal (Cases Currently Under Investigation) ↗
What was exposed
Names Postal addresses Dates of birth Email addresses Medical records Government ID numbers
Occurred → disclosed
23 Dec 2025 → 22 Feb 2026
61-day gap
Country
United States
Last confirmed
24 Jul 2026

Record count revised. Verified 2026-07-24 against the HHS OCR Breach Portal. Listed as QualDerm Partners, LLC, Healthcare Provider (TN), 3,117,874 individuals, Hacking/IT Incident, Network Server, breach submission date 02/22/2026 - count matches the lead exactly. QualDerm is a dermatology practice group. Unauthorized actor accessed a limited number of systems 2025-12-23 to 2025-12-24 (about two days); incident discovered 2025-12-24; notification letters mailed from 2026-02-22. Data involved: names, addresses, dates of birth, email addresses, medical record numbers, treating-physician names, treatment/diagnosis information, health insurance information, dates of death, and in some cases government-issued ID information. No ransomware group claimed the attack; specific vector not disclosed. Count authority: OCR portal.

TriZetto Provider Solutions 6 Feb 2026 3,433,965 Healthcare HHS OCR Breach Portal (Cases Currently Under Investigation) ↗
What was exposed
Names Postal addresses Dates of birth Social Security numbers Medical records
Country
United States
Last confirmed
24 Jul 2026

Record count revised. Verified 2026-07-24 against the HHS OCR Breach Portal. Listed there as TriZetto Provider Solutions, Business Associate (MO), 3,433,965 individuals, Hacking/IT Incident, Network Server, breach submission date 02/06/2026 - count matches the lead exactly. TriZetto is Cognizant's RCM/clearinghouse subsidiary. An unauthorized third party first accessed historical eligibility transaction reports in November 2024 (only the month is stated in the notice, so _brt_occurred left blank); suspicious activity was identified in a customer web portal on 2025-10-02; healthcare-client notifications began 2025-12-09 and consumer notifications early Feb 2026. Data involved: names, addresses, dates of birth, SSNs, health insurance numbers, Medicare beneficiary numbers, provider and insurer names, primary-insured details; the company states no financial information was involved. Specific intrusion vector not disclosed. Count authority: OCR portal; corroborated by the company notice as summarised by HIPAA Journal.

Coupang 16 Dec 2025 33,000,000 Retail & e-commerce Insider Coupang Faces Backlash Over $1.1 Billion Data Breach Payout in Vouchers →
What was exposed
Names Phone numbers Postal addresses Email addresses
Country
South Korea
Last confirmed
23 Jul 2026

Record count revised. Verified 2026-07-23 against the primary SEC 8-K (cpng-20251215). Coupang became aware 2025-11-18. A former employee may have obtained name, phone number, delivery address and email address associated with up to 33 million customer accounts, plus certain order histories for a subset. No banking, payment-card or login credentials were compromised. Records = up to 33M accounts as stated by the company (later Korean forensic reporting indicated data from roughly 3,000 accounts was actually stored). Fold of 8-K/A 27897 (2025-12-29). SQ covered as post 15744. Originally ingested from SEC EDGAR Item 1.05.

F5 15 Oct 2025 Undisclosed Technology Unknown SEC EDGAR (Form 8-K, Item 1.05) ↗
Country
United States
Attributed to
Nation-state threat actor (unnamed by F5; public reporting links to China)
Last confirmed
23 Jul 2026

Record count revised. Verified 2026-07-23 via primary sources (F5 SEC 8-K + CISA ED-26-01). Nation-state actor held persistent access for an extended period; F5 became aware 2025-08-09 and disclosed 2025-10-15 after a DOJ-authorized delay. Stolen: portions of BIG-IP source code, undisclosed vulnerability research, and limited customer configuration data. CISA issued Emergency Directive ED-26-01 ordering federal agencies to patch or disconnect F5 devices. No consumer PII record count stated. Systemic security-vendor supply-chain event. Originally ingested from SEC EDGAR Item 1.05.

Jaguar Land Rover 2 Sep 2025 Undisclosed Other Jaguar Land Rover Faces Massive £540 Million Blow from Unprecedented Cyberattack →
Occurred → disclosed
31 Aug 2025 → 2 Sep 2025
2-day gap
Country
United Kingdom
Attributed to
Scattered Lapsus$ Hunters / Scattered Spider (claimed)
Last confirmed
24 Jul 2026

Record count revised. Verified 2026-07-24 via Jaguar Land Rover official statements and UK official bodies. records left blank (Undisclosed): JLR confirmed data theft but never published an affected-individuals count; the stolen material was an internal/employee dataset plus source code and development logs, not a defined consumer PII set. Timeline: attack began 2025-08-31; JLR took IT systems offline and disclosed the incident publicly 2025-09-02 (initially stated no evidence of customer data theft); on 2025-09-10 it confirmed some data has been affected; it notified the ICO and the NCSC. exposed left empty because JLR did not enumerate personal-data categories; attacker-claimed data (per third-party analysis) includes employee usernames, email addresses, display names and time zones plus source code and dev logs. CLASSIFICATION: the UK Cyber Monitoring Centre (CMC) rated this a Category 3 systemic event on its five-point scale, estimating UK financial impact at 1.9 billion pounds (modelled range 1.6 to 2.1 billion pounds) and 5,000+ affected UK organisations - the most economically damaging cyber event to hit the UK (CMC statement 2025-10-22, https://cybermonitoringcentre.com/2025/10/22/cyber-monitoring-centre-statement-on-the-jaguar-land-rovercyber-incident-october-2025/ ; NCSC https://www.ncsc.gov.uk/news/jlr-incident). Sector set to other (automotive manufacturing). Attribution recorded in _brt_attributed. Existing SQ coverage set as _brt_coverage (post 12324).

Aflac 8 Aug 2025 13,924,906 Healthcare Unknown HHS Office for Civil Rights breach portal ↗
Country
United States

Record count revised. VERIFIED 2026-07-21: read directly from the HHS OCR portal — "Aflac Incorporated", 13,924,906 individuals affected, submitted 08/08/2025, Hacking/IT Incident, business associate not present. This is a national entity-submitted figure and is the only count in this batch confirmed from a primary source today. Date shown is the HHS submission date, not the public announcement date.

Columbia University 7 Aug 2025 Undisclosed Education Unknown Oregon Department of Justice breach registry ↗
Occurred → disclosed
16 May 2025 → 7 Aug 2025
83-day gap
Country
United States

Record count revised. VERIFIED 2026-07-21 from the Oregon DOJ breach registry: reported 08/07/2025, dates of breach 5/16/2025 and 6/24/2025, date of discovery 7/8/2025. `disclosed` holds Oregon's REPORTED date (a regulatory notification), not a press-announcement date — replace it if the university announced publicly on a different day. `occurred` is the earliest of the two breach dates. NEEDS SOURCING: records affected. ⚠️ Do NOT confuse with the HHS OCR entries for Columbia Eye Clinic, Columbia Orthopaedic Group or Columbia Medical Practice — all unrelated entities.

Ingram Micro 5 Jul 2025 Undisclosed Technology Ransomware SEC EDGAR (Form 8-K, Item 8.01 — company statement) ↗
Country
United States

Record count revised. VERIFIED 2026-07-21 by reading the filed press release in full. Ingram Micro Holding Corporation (NYSE: INGM) issued the statement dated July 5, 2025; the 8-K was filed 2025-07-07. Vector is set to ransomware because the company states it directly — "Ingram Micro recently identified ransomware on certain of its internal systems" — rather than being inferred. Filed under Item 8.01 (Other Events), NOT Item 1.05, which is why an Item 1.05 sweep does not surface it; a material-looking incident is not always filed as one. The statement gives no records-affected figure, so that stays undisclosed. `occurred` and `discovered` are empty: the release says only "recently identified" and gives no dates.

Fidelity Investments 9 Oct 2024 Undisclosed Finance & banking Unknown Oregon Department of Justice breach registry ↗
Occurred → disclosed
17 Aug 2024 → 9 Oct 2024
53-day gap
Country
United States

Record count revised. VERIFIED 2026-07-21 from the Oregon DOJ breach registry: reported 10/09/2024, dates of breach 8/17/2024 and 8/19/2024, date of discovery 8/19/2024, notice sent 10/9/2024. Replaces Comcast in Batch 1, whose own filing (reported 12/18/2023, breach October 2023) falls outside the 2024-to-July-2025 window. `disclosed` holds Oregon's regulatory reporting date, not a press-announcement date. NEEDS SOURCING: records affected. ⚠️ This is FIDELITY INVESTMENTS specifically. Oregon separately lists Fidelity National Information Services, Fidelity & Guaranty Life Insurance and Fidelity Life Association — all 2023 filings by unrelated companies. Do not merge or cite them.

National Public Data 5 Sep 2024 Undisclosed Other Unknown Oregon Department of Justice breach registry ↗
Country
United States

Record count revised. VERIFIED 2026-07-21 from the Oregon DOJ breach registry, filed as "JERICO PICTURES, INC. D/B/A NATIONAL PUBLIC DATA": reported 09/05/2024. Oregon lists NO dates of breach and NO date of discovery for this filing, so `occurred` and `discovered` stay empty rather than being inferred. `disclosed` holds the regulatory reporting date. NEEDS SOURCING: records affected.

AT&T 12 Jul 2024 Undisclosed Telecom Unknown SEC EDGAR (Form 8-K, Item 1.05) ↗
Country
United States

Record count revised. VERIFIED 2026-07-21: 8-K Item 1.05 filing date and document URL confirmed live on EDGAR (accession 0000732717-24-000046). NEEDS SOURCING: records affected. This page covers BOTH 2024 incidents (March forum dump and July Snowflake) per the CW brief scope call.

Cencora 27 Feb 2024 Undisclosed Healthcare Unknown SEC EDGAR (Form 8-K, Item 1.05) ↗
Country
United States

Record count revised. VERIFIED 2026-07-21: 8-K Item 1.05 date and document URL confirmed live on EDGAR. Cencora filed a second Item 1.05 on 2024-07-31. Sector set to healthcare deliberately: the SIC code (5122, drug wholesale) maps to retail, which misdescribes a pharmaceutical distributor whose breach exposed patient data. NEEDS SOURCING: records affected.

Change Healthcare 22 Feb 2024 Undisclosed Healthcare Unknown SEC EDGAR (Form 8-K, Item 1.05, filed by UnitedHealth Group) ↗
Country
United States

Record count revised. VERIFIED 2026-07-21: filed by parent UnitedHealth Group; 8-K Item 1.05 date and document URL confirmed live on EDGAR. NEEDS SOURCING: records affected. The widely-cited ~192.7M figure was NOT verified against a primary source in this pass and must not be published until it is — HHS OCR is the place to confirm it, but this incident has aged out of the 24-month portal window and sits in the archive.

Verification ledger

2 most recent of 2 logged updates
  • Every new row verified against SEC filings, the HHS OCR portal, or the company's own notice; counts publish only where a primary source states one 24 Jul 2026
  • 13 major breaches added, extending coverage through July 2026: Coupang, F5, TriZetto, QualDerm, Jaguar Land Rover and more 24 Jul 2026

How this tracker is maintained

Every record passes the same checks before it appears, and stays under review after.

  1. Sourced

    Each record traces to a primary disclosure: an SEC filing, a state attorney general notice, the HHS breach portal, or the company’s own statement. Counts stay as disclosed, and a third-party corpus count is always labeled as one.

  2. Dated

    Each row carries its disclosure date, and where the source states it, the gap between occurrence and disclosure.

  3. Re-checked

    Records are re-verified on a 30-day cycle, and disclosed counts get corrected when organizations revise their filings.

Where do these come from?
Regulator portals and company disclosures only, linked on every row. An absent count renders as Undisclosed rather than zero, because absence is a real answer.
Why is healthcare so common here?
The HHS breach portal is the most complete public disclosure feed, so healthcare incidents surface more reliably than other sectors. That reflects disclosure rules, not how attacks distribute across industries.
Can I cite this?
Yes. Use “Cite this tracker” and cite the disclosure date alongside any count; organizations revise figures over time.

This is informational content. Disclosed figures reflect what organizations reported as of the stated dates, and companies revise counts. Confirm with the linked primary source before relying on a number.

Sources