SQ Magazine The Threat Index Data Breach Tracker
Data Breach Tracker
This tracker records breaches where a regulator register or the organization itself published the disclosure, from January 2024 onward. Each row gives the organization, the disclosure date, how many people were affected, and the attack vector, with a link to the primary source. Coverage follows what those registers publish, so it is a record of disclosure rather than a complete census of incidents.
26 records newest disclosure 13 Aug 2026 last verified 14 Aug 2026
- Breaches tracked
- 26
- At least affected · 10 disclosed counts
- 79,596,881
- Sectors
- 7
- Re-verify cycle
- 30day
Latest change Five disclosures added after the register sweep: DentaQuest (15,000,000, largest US healthcare breach of 2026), Unlimited Technology Systems (3,803,750), MCBS (1,261,464), Amgen (count not published), RingCentral (company-confirmed; 1,596,490-email leaked corpus). Sub-million register entries stay parked as drafts per the publication floor. (14 Aug 2026) All changes
All records
26 breaches, newest disclosure first. Filter or search below.
What is in scope Breaches where a regulator register or the organization itself published the disclosure.
26 disclosed breaches. The most affected sector is Healthcare with 15. 10 of 26 disclose how many people were affected; the rest publish none, and this table leaves those cells empty rather than estimating them.
| Organization | Disclosed | Records (as disclosed) | Sector | Vector | Our report | Record detail |
|---|---|---|---|---|---|---|
| RingCentral | 13 Aug 2026 |
1,596,490 records in Have I Been Pwned not a confirmed disclosure figure |
— | Phishing | Have I Been Pwned ↗ | |
|
||||||
| Amgen INC | 31 Jul 2026 | Undisclosed | — | Unknown | SEC EDGAR (Form 8-K, Item 1.05) ↗ | |
|
||||||
| Unlimited Technology Systems, LLC | 21 Jul 2026 | 3,803,750 | Healthcare | Third-party / supply chain | HHS Office for Civil Rights breach portal ↗ | |
|
||||||
| DentaQuest, LLC | 16 Jul 2026 | 15,000,000 | Healthcare | Unknown | HHS Office for Civil Rights breach portal ↗ | |
|
||||||
| Navient | 2 Jul 2026 | Undisclosed | Finance & banking | Ransomware | SEC EDGAR (Form 8-K, Item 1.05) ↗ | confirmed 23 Jul 2026 |
|
||||||
| AdaptHealth | 2 Jul 2026 | Undisclosed | Healthcare | Phishing | SEC EDGAR (Form 8-K, Item 1.05) ↗ | confirmed 23 Jul 2026 |
|
||||||
| MCBS, LLC | 26 Jun 2026 | 1,261,464 | Healthcare | Third-party / supply chain | HHS Office for Civil Rights breach portal ↗ | |
|
||||||
| Xsolis | 5 Jun 2026 | 1,396,519 | Healthcare | Phishing | HHS Office for Civil Rights breach portal ↗ | confirmed 23 Jul 2026 |
|
||||||
| West Pharmaceutical Services | 11 May 2026 | Undisclosed | Healthcare | Ransomware | SEC EDGAR (Form 8-K, Item 1.05) ↗ | confirmed 23 Jul 2026 |
|
||||||
| Stryker | 9 Apr 2026 | Undisclosed | Healthcare | Unknown | Iran Linked Hackers Claim Massive Attack on Stryker → | confirmed 23 Jul 2026 |
|
||||||
| Nacogdoches Memorial Hospital | 30 Mar 2026 | 2,507,073 | Healthcare | HHS OCR Breach Portal (Cases Currently Under Investigation) ↗ | confirmed 24 Jul 2026 | |
|
||||||
| NYC Health + Hospitals | 24 Mar 2026 | Undisclosed | Healthcare | Third-party / supply chain | NYC Health + Hospitals - Notice of Data Breach (official) ↗ | confirmed 24 Jul 2026 |
|
||||||
| Navia Benefit Solutions | 18 Mar 2026 | 2,151,330 | Healthcare | 2.7 Million Affected in Navia Cyberattack Linked to API Flaw → | confirmed 24 Jul 2026 | |
|
||||||
| QualDerm Partners | 22 Feb 2026 | 3,117,874 | Healthcare | HHS OCR Breach Portal (Cases Currently Under Investigation) ↗ | confirmed 24 Jul 2026 | |
|
||||||
| TriZetto Provider Solutions | 6 Feb 2026 | 3,433,965 | Healthcare | HHS OCR Breach Portal (Cases Currently Under Investigation) ↗ | confirmed 24 Jul 2026 | |
|
||||||
| Coupang | 16 Dec 2025 | 33,000,000 | Retail & e-commerce | Insider | Coupang Faces Backlash Over $1.1 Billion Data Breach Payout in Vouchers → | confirmed 23 Jul 2026 |
|
||||||
| F5 | 15 Oct 2025 | Undisclosed | Technology | Unknown | SEC EDGAR (Form 8-K, Item 1.05) ↗ | confirmed 23 Jul 2026 |
|
||||||
| Jaguar Land Rover | 2 Sep 2025 | Undisclosed | Other | Jaguar Land Rover Faces Massive £540 Million Blow from Unprecedented Cyberattack → | confirmed 24 Jul 2026 | |
|
||||||
| Aflac | 8 Aug 2025 | 13,924,906 | Healthcare | Unknown | HHS Office for Civil Rights breach portal ↗ | |
|
||||||
| Columbia University | 7 Aug 2025 | Undisclosed | Education | Unknown | Oregon Department of Justice breach registry ↗ | |
|
||||||
| Ingram Micro | 5 Jul 2025 | Undisclosed | Technology | Ransomware | SEC EDGAR (Form 8-K, Item 8.01 — company statement) ↗ | |
|
||||||
| Fidelity Investments | 9 Oct 2024 | Undisclosed | Finance & banking | Unknown | Oregon Department of Justice breach registry ↗ | |
|
||||||
| National Public Data | 5 Sep 2024 | Undisclosed | Other | Unknown | Oregon Department of Justice breach registry ↗ | |
|
||||||
| AT&T | 12 Jul 2024 | Undisclosed | Telecom | Unknown | SEC EDGAR (Form 8-K, Item 1.05) ↗ | |
|
||||||
| Cencora | 27 Feb 2024 | Undisclosed | Healthcare | Unknown | SEC EDGAR (Form 8-K, Item 1.05) ↗ | |
|
||||||
| Change Healthcare | 22 Feb 2024 | Undisclosed | Healthcare | Unknown | SEC EDGAR (Form 8-K, Item 1.05, filed by UnitedHealth Group) ↗ | |
|
||||||
No records match the current filters.
What the data shows
Every figure below comes from the verified table above, redrawn as the trends and comparisons a table cannot show.
If your data was in one of these
Every record above names the public register its notice was filed in, because that notice is the document that says what was taken. Start there rather than with coverage: it is dated, official, and specific to you.
- Read the organization’s own notice. Each row’s detail links the primary source. It states what categories of data were involved, which is the fact that decides what to do next.
- Check the register for your jurisdiction. The routes below are the ones this page cites.
- Watch the date, not the headline. Counts on this page are as stated at disclosure and are often revised upward later, so a notice can be more current than the number here.
- HHS OCR breach portal ↗ US health data. Searchable by organization; lists every breach of 500 or more records.
- US state attorney general filings ↗ Many states publish the notice letters themselves, which name the exact data involved.
- SEC Form 8-K ↗ What a listed company told its investors, on the record and dated.
This page tracks disclosures. It is not legal advice, and it cannot tell you whether you personally appear in a given breach; only the notice and the register can.
Verification ledger
5 most recent of 5 logged updates- Five disclosures added after the register sweep: DentaQuest (15,000,000, largest US healthcare breach of 2026), Unlimited Technology Systems (3,803,750), MCBS (1,261,464), Amgen (count not published), RingCentral (company-confirmed; 1,596,490-email leaked corpus). Sub-million register entries stay parked as drafts per the publication floor. 14 Aug 2026
- Five-lens page audit passed; Dataset creator reference corrected in schema (3.83.1). 30 Jul 2026
- Notice pathway recorded on all 21 records: how each disclosure reached its public register (state attorney general filing, HHS OCR portal, SEC 8-K, data protection authority notice, or company statement). 30 Jul 2026
- Every new row verified against SEC filings, the HHS OCR portal, or the company's own notice; counts publish only where a primary source states one 24 Jul 2026
- 13 major breaches added, extending coverage through July 2026: Coupang, F5, TriZetto, QualDerm, Jaguar Land Rover and more 24 Jul 2026
How this tracker is maintained
Every record passes the same checks before it appears, and stays under review after.
-
Sourced
Each record traces to a primary disclosure: an SEC filing, a state attorney general notice, the HHS breach portal, or the company’s own statement. Counts stay as disclosed, and a third-party corpus count is always labeled as one.
-
Dated
Each row carries its disclosure date, and where the source states it, the gap between occurrence and disclosure.
-
Re-checked
Records are re-verified on a 30-day cycle, and disclosed counts get corrected when organizations revise their filings.
- Where do these come from?
- Regulator portals and company disclosures only, linked on every row. An absent count renders as Undisclosed rather than zero, because absence is a real answer.
- Why is healthcare so common here?
- The HHS breach portal is the most complete public disclosure feed, so healthcare incidents surface more reliably than other sectors. That reflects disclosure rules, not how attacks distribute across industries.
This is informational content. Disclosed figures reflect what organizations reported as of the stated dates, and companies revise counts. Confirm with the linked primary source before relying on a number.
Quoting a figure with a link to this page needs no permission. Cite it as you would any source. Reuse of the compiled dataset itself is licensed under CC BY 4.0: credit SQ Magazine and link back.
Sources
- HHS OCR Breach Portal (Cases Currently Under Investigation)
- HHS Office for Civil Rights breach portal
- Have I Been Pwned
- Jaguar Land Rover - Statement on Cyber Incident (official)
- NYC Health + Hospitals - Notice of Data Breach (official)
- Oregon Department of Justice breach registry
- SEC EDGAR (Form 8-K, Item 1.05)
- SEC EDGAR (Form 8-K, Item 1.05, filed by UnitedHealth Group)
- SEC EDGAR (Form 8-K, Item 8.01 — company statement)
Breach data from Have I Been Pwned, licensed under CC BY 4.0. Corpus counts are the number of records in that dataset and are not confirmed disclosure figures.