• Skip to primary navigation
  • Skip to main content
  • Skip to footer
Sq Magazine LogoSQ Magazine

Smarter Insights for a Fast-Moving Digital World

  • Latest News
  • Statistics
  • About
  • Contact
Subscribe

SQ Magazine » The Threat Index » Data Breach Tracker

Data Breach Tracker

This tracker records breaches where a regulator register or the organization itself published the disclosure, from January 2024 onward. Each row gives the organization, the disclosure date, how many people were affected, and the attack vector, with a link to the primary source. Coverage follows what those registers publish, so it is a record of disclosure rather than a complete census of incidents.

26 records · newest disclosure 13 Aug 2026 · last verified 14 Aug 2026

Sofia Ramirez
Maintained By
Sofia Ramirez
Sofia Ramirez
Senior Tech Writer • 587 Articles
Sofia Ramirez is a technology and cybersecurity writer at SQ Magazine. With a keen eye on emerging threats and innovations, she helps reader...
LATEST POSTS:
Critical Windows BitLocker Flaw Sparks Urgent Patch
cPanel Fixes Powerful Root Access Bug in EmailTrack
QuickFox Partners with Murphy Security to Strengthen Client Software Supply Chain Security

Breaches tracked
26
At least affected · 10 disclosed counts
79,596,881
Sectors
7
Re-verify cycle
30day
Largest disclosed breach on this page Coupang · 33,000,000 (Dec 2025)

Latest change Five disclosures added after the register sweep: DentaQuest (15,000,000, largest US healthcare breach of 2026), Unlimited Technology Systems (3,803,750), MCBS (1,261,464), Amgen (count not published), RingCentral (company-confirmed; 1,596,490-email leaked corpus). Sub-million register entries stay parked as drafts per the publication floor. (14 Aug 2026) All changes

All records

26 breaches, newest disclosure first. Filter or search below.

What is in scope Breaches where a regulator register or the organization itself published the disclosure.

26 disclosed breaches. The most affected sector is Healthcare with 15. 10 of 26 disclose how many people were affected; the rest publish none, and this table leaves those cells empty rather than estimating them.

What changed 14 Aug 2026

The register catches up with three giant vendor breaches at once: DentaQuest reports 15 million people to federal regulators, the largest US healthcare breach of 2026, with the ShinyHunters group claiming a 234 GB theft; Unlimited Technology Systems follows at 3.8 million from a five-day 2025 intrusion disclosed nine months later; and billing firm MCBS adds 1.26 million with the PEAR group claiming 3.3 TB. Amgen files a material 8-K for cloud-storage exfiltration of patient data without publishing a count, and RingCentral confirms a social-engineering breach whose leaked corpus indexes 1.6 million unique emails. Four of the five publish no intrusion method; those vectors stay unknown rather than guessed.

Every row links our own report where we have one; the primary source is always in the record detail. Counts are as stated at disclosure and are often revised later. 15 of these 24 records are healthcare, which reflects which regulators publish breach notices in public registers rather than where breaches actually happen.
Organization Disclosed Records (as disclosed) Sector Vector Our report Record detail
RingCentral 13 Aug 2026 1,596,490 records in Have I Been Pwned
not a confirmed disclosure figure
— Phishing Have I Been Pwned ↗
What was exposed
Names Email addresses Postal addresses Phone numbers
Disclosed via
Company statement only
Occurred → disclosed
27 Jul 2026 → 13 Aug 2026
17-day gap
Attributed to
ShinyHunters (claimed)
Primary source
Have I Been Pwned ↗
Last confirmed
14 Aug 2026
Revision
Record count revised. Verified 14 Aug 2026. RingCentral confirmed that a social-engineering campaign led to unauthorized access to data of a limited portion of its customers in July 2026; the company is notifying affected customers directly and has published no affected count, so the confirmed-count cell stays empty. The 1,596,490 figure is the unique-email corpus Have I Been Pwned indexed on 13 Aug 2026 from data the ShinyHunters extortion group leaked, alleging roughly 623 GB taken; corpus counts are not confirmed disclosure figures and are recorded in the corpus column only. Exposed categories per the leaked corpus: names, email addresses, physical addresses, phone numbers. Vector recorded as phishing on the company own description of a social-engineering campaign.
Amgen INC 31 Jul 2026 Undisclosed — Unknown SEC EDGAR (Form 8-K, Item 1.05) ↗
What was exposed
Medical records
Disclosed via
SEC Form 8-K
Country
United States
Primary source
SEC EDGAR (Form 8-K, Item 1.05) ↗
Last confirmed
14 Aug 2026
Revision
Record count revised. Verified 14 Aug 2026 against the Form 8-K and press coverage. Amgen identified unauthorized activity in cloud storage environments hosted by external service providers in July 2026, determined on 29 Jul that the incident was material, and filed the 8-K on 31 Jul. Exfiltrated material includes patient protected health information and proprietary company data; the proprietary loss has no token in the exposed vocabulary and is recorded here instead. Amgen has published no affected-individuals count, so that cell stays empty, and no intrusion method or attribution, so the vector stays unknown. The company states it does not expect impact on financial position, products or manufacturing. Investigation ongoing; revisit for a count when notifications or an OCR entry appear.
Unlimited Technology Systems, LLC 21 Jul 2026 3,803,750 Healthcare Third-party / supply chain HHS Office for Civil Rights breach portal ↗
What was exposed
Names Dates of birth Social Security numbers Medical records
Disclosed via
HHS OCR breach portal
Discovered
19 Oct 2025
14-day dwell
Occurred → disclosed
5 Oct 2025 → 21 Jul 2026
289-day gap
Country
United States
Primary source
HHS Office for Civil Rights breach portal ↗
Last confirmed
14 Aug 2026
Revision
Record count revised. Verified 14 Aug 2026 against the HHS OCR portal entry and press coverage. Unlimited Technology Systems, an Ohio revenue cycle management vendor processing billing for over 4,500 oncology practices and 6,500 specialty providers, reported 3,803,750 individuals to OCR on 21 Jul 2026. The intrusion ran 5 to 10 Oct 2025 and was identified that October; disclosure followed nine months later, the second-largest US healthcare breach reported in 2026 behind DentaQuest. Stolen data includes names, birthdates, Social Security numbers, driver license scans, and medical and health-insurance information; driver licenses have no separate token and ride under the note. No public attribution, and the intrusion method is not described, so the vector stays unknown.
DentaQuest, LLC 16 Jul 2026 15,000,000 Healthcare Unknown HHS Office for Civil Rights breach portal ↗
What was exposed
Names Postal addresses Social Security numbers Medical records
Disclosed via
HHS OCR breach portal
Occurred → disclosed
17 May 2026 → 16 Jul 2026
60-day gap
Country
United States
Attributed to
ShinyHunters (claimed)
Primary source
HHS Office for Civil Rights breach portal ↗
Last confirmed
14 Aug 2026
Revision
Record count revised. Verified 14 Aug 2026 against the HHS OCR portal entry and press coverage of the company notices. DentaQuest, the second-largest US dental benefits administrator, reported 15,000,000 individuals to OCR on 16 Jul 2026 after unauthorized access to its systems between 17 and 20 May 2026; notification letters began 17 Jul. The recorded figure is the OCR-submitted count. HIPAA Journal aggregates state filings to a potentially higher 23.4 million, and state attorney-general filings in Texas, Massachusetts and South Carolina cover at least 4.5 million between them; the column keeps the figure DentaQuest itself submitted. The ShinyHunters extortion group claimed the theft and reportedly leaked about 234 GB; DentaQuest did not describe the intrusion method, so the vector stays unknown. Exposed categories per the notices: names, addresses, Social Security numbers, member and Medicaid or Medicare identifiers, and dental or vision treatment and billing information.
Navient 2 Jul 2026 Undisclosed Finance & banking Ransomware SEC EDGAR (Form 8-K, Item 1.05) ↗ confirmed 23 Jul 2026
What was exposed
Names Dates of birth Postal addresses Social Security numbers
Disclosed via
SEC Form 8-K
Discovered
8 Jun 2026
Country
United States
Primary source
SEC EDGAR (Form 8-K, Item 1.05) ↗
Last confirmed
23 Jul 2026
Revision
Record count revised. Verified 2026-07-23 via primary sources (Navient SEC 8-K). Ransomware attack against a third-party law firm that provides services to Navient; Navient became aware 2026-06-08 and determined materiality 2026-06-29. Borrower data exposed via the firm included names, dates of birth, addresses and Social Security numbers. No evidence of access to Navient own systems. Individual count not stated in the filing. Originally ingested from SEC EDGAR Item 1.05.
AdaptHealth 2 Jul 2026 Undisclosed Healthcare Phishing SEC EDGAR (Form 8-K, Item 1.05) ↗ confirmed 23 Jul 2026
What was exposed
Medical records Credentials / passwords
Disclosed via
SEC Form 8-K
Discovered
15 Jun 2026
Country
United States
Primary source
SEC EDGAR (Form 8-K, Item 1.05) ↗
Last confirmed
23 Jul 2026
Revision
Record count revised. Verified 2026-07-23 via primary sources (AdaptHealth SEC 8-K). Threat actor contacted the company 2026-06-15; materiality determined 2026-06-27. Attacker compromised a third-party contractor user session via social engineering and accessed cloud-based patient-management systems and document storage, exfiltrating stored password files tied to insurance-billing and external EHR portals containing patient PHI. Volume at risk not quantified. Large US home-medical-equipment provider. Originally ingested from SEC EDGAR Item 1.05.
MCBS, LLC 26 Jun 2026 1,261,464 Healthcare Third-party / supply chain HHS Office for Civil Rights breach portal ↗
What was exposed
Names Postal addresses Dates of birth Social Security numbers Medical records
Disclosed via
HHS OCR breach portal
Occurred → disclosed
22 Sep 2025 → 26 Jun 2026
277-day gap
Country
United States
Attributed to
PEAR (claimed)
Primary source
HHS Office for Civil Rights breach portal ↗
Last confirmed
14 Aug 2026
Revision
Record count revised. Verified 14 Aug 2026 against the HHS OCR portal entry and press coverage. Medical Computer Business Services, an Augusta, Georgia medical billing and practice-management vendor, reported 1,261,464 individuals to OCR after an intrusion between 22 and 26 Sep 2025; the investigation concluded in late May 2026 and the OCR entry followed on 26 Jun. Potentially stolen files held names, addresses, birthdates, Social Security numbers, and health-insurance and medical information. The extortion group PEAR claimed the intrusion and alleges 3.3 TB taken; the company did not describe the method, so the vector stays unknown.
Xsolis 5 Jun 2026 1,396,519 Healthcare Phishing HHS Office for Civil Rights breach portal ↗ confirmed 23 Jul 2026
What was exposed
Names Dates of birth Social Security numbers Medical records
Disclosed via
HHS OCR breach portal
Discovered
22 Jan 2026
2-day dwell
Occurred → disclosed
20 Jan 2026 → 5 Jun 2026
136-day gap
Country
United States
Primary source
HHS Office for Civil Rights breach portal ↗
Last confirmed
23 Jul 2026
Revision
Record count revised. Verified 2026-07-23 via HHS OCR (1,396,519) plus multiple outlets citing the Xsolis notice. Tennessee healthcare-AI vendor (HIPAA business associate) breached via a targeted phishing email to a single employee; unauthorized access 2026-01-20 to 2026-01-22. Exposed names, dates of birth, Social Security numbers, health-insurance and medical-treatment information for 1,396,519 individuals across seven-to-eight hospital systems including Mayo Clinic. HHS OCR posted the figure 2026-06-22; breach report dated 2026-06-05. One of the largest US healthcare incidents of the year. Originally ingested from the HHS OCR breach portal.
West Pharmaceutical Services 11 May 2026 Undisclosed Healthcare Ransomware SEC EDGAR (Form 8-K, Item 1.05) ↗ confirmed 23 Jul 2026
Disclosed via
SEC Form 8-K
Discovered
4 May 2026
Country
United States
Primary source
SEC EDGAR (Form 8-K, Item 1.05) ↗
Last confirmed
23 Jul 2026
Revision
Record count revised. Verified 2026-07-23 via primary sources (West SEC 8-K and 8-K/A). Detected a compromise 2026-05-04; determined material 2026-05-07. Ransomware: data exfiltrated and systems encrypted; company took systems offline globally and engaged Palo Alto Unit 42. Scope of affected data still under investigation; individual count not disclosed. S&P 500 pharmaceutical-packaging and drug-delivery supplier. Fold of 8-K/A 27890 (2026-05-20, operations restored). Originally ingested from SEC EDGAR Item 1.05.
Stryker 9 Apr 2026 Undisclosed Healthcare Unknown Iran Linked Hackers Claim Massive Attack on Stryker → confirmed 23 Jul 2026
Disclosed via
SEC Form 8-K
Discovered
11 Mar 2026
0-day dwell
Occurred → disclosed
11 Mar 2026 → 9 Apr 2026
29-day gap
Country
United States
Attributed to
Handala (Iran-linked hacktivist group)
Primary source
SEC EDGAR (Form 8-K, Item 1.05) ↗
Last confirmed
23 Jul 2026
Revision
Record count revised. Verified 23 Jul 2026 against primary sources: Stryker's SEC Form 8-K/A and its customer notice. Identified 11 March 2026 and attributed to Handala, an Iran-linked hacktivist group, which weaponized Stryker's Microsoft Intune device-management platform to wipe data from thousands of devices in a destructive attack. It disrupted order processing, manufacturing and shipping, with a material impact on first-quarter 2026 results but none to full-year guidance; the 8-K/A was filed 9 April 2026. No affected-individuals count is recorded because exfiltration of personal data remains unconfirmed: the attackers claim data theft, the company has not confirmed it, and class-action litigation is ongoing. The record will be updated if that resolves.
Nacogdoches Memorial Hospital 30 Mar 2026 2,507,073 Healthcare HHS OCR Breach Portal (Cases Currently Under Investigation) ↗ confirmed 24 Jul 2026
What was exposed
Names Postal addresses Phone numbers Email addresses Social Security numbers Dates of birth Medical records
Disclosed via
HHS OCR breach portal
Discovered
31 Jan 2026
16-day dwell
Occurred → disclosed
15 Jan 2026 → 30 Mar 2026
74-day gap
Country
United States
Primary source
HHS OCR Breach Portal (Cases Currently Under Investigation) ↗
Last confirmed
24 Jul 2026
Revision
Record count revised. Verified 24 Jul 2026 against the HHS OCR breach portal, which lists Nacogdoches Memorial Hospital, healthcare provider (TX), 2,507,073 individuals, hacking/IT incident on a network server, submitted 30 March 2026. Counts differ by roughly ten times across sources: the hospital's own messaging and early trade press cite about 250,000 to 257,073 individuals, while the figure filed with HHS OCR is 2,507,073. This table uses the regulator filing and states the gap rather than choosing quietly between them. Unauthorized network access ran 15 to 31 January 2026, was discovered on 31 January, and consumer notifications began 31 March. Data involved: names, addresses, phone numbers, email addresses, Social Security numbers, dates of birth, medical record and account numbers, health plan beneficiary numbers and photographs. No group claimed responsibility and the threat actor was not disclosed.
NYC Health + Hospitals 24 Mar 2026 Undisclosed Healthcare Third-party / supply chain NYC Health + Hospitals - Notice of Data Breach (official) ↗ confirmed 24 Jul 2026
What was exposed
Names Postal addresses Medical records Financial account data Social Security numbers Government ID numbers Biometric data
Disclosed via
Company statement only
Discovered
2 Feb 2026
69-day dwell
Occurred → disclosed
25 Nov 2025 → 24 Mar 2026
119-day gap
Country
United States
Primary source
NYC Health + Hospitals - Notice of Data Breach (official) ↗
Last confirmed
24 Jul 2026
Revision
Record count revised. Verified 24 Jul 2026. No affected-individuals count is published: the HHS OCR portal shows no exact figure for this incident, and every source describes it as approximately, up to, or at least 1.8 million current and former patients and employees. The count is therefore left blank rather than estimated from an approximation. A separate, unrelated NYC Health + Hospitals entry of 5,728 individuals submitted 6 June 2025 appears on the same portal and is a different, much smaller incident. Per the official notice of data breach, an unauthorized third party exploited a flaw at an unnamed third-party vendor and had access from 25 November 2025 to 11 February 2026; suspicious activity was discovered on 2 February 2026. Data involved: demographic, medical, insurance and billing information, Social Security numbers, government identification numbers, and biometric data including fingerprints and palm prints.
Navia Benefit Solutions 18 Mar 2026 2,151,330 Healthcare 2.7 Million Affected in Navia Cyberattack Linked to API Flaw → confirmed 24 Jul 2026
What was exposed
Names Postal addresses Phone numbers Email addresses Social Security numbers Dates of birth
Disclosed via
HHS OCR breach portal
Discovered
23 Jan 2026
32-day dwell
Occurred → disclosed
22 Dec 2025 → 18 Mar 2026
86-day gap
Country
United States
Primary source
HHS OCR Breach Portal (Cases Currently Under Investigation) ↗
Last confirmed
24 Jul 2026
Revision
Record count revised. Verified 24 Jul 2026 against the HHS OCR breach portal, which lists Navia Benefit Solutions, Inc., business associate (WA), 2,151,330 individuals, hacking/IT incident on a network server, submitted 18 March 2026. Sources disagree on the count: much of the press reports roughly 2.7 million, while 2,151,330 is the protected-health-information count Navia itself filed with HHS OCR, and that filing is what this table records. Navia administers employee health and benefits plans as a HIPAA business associate. Unauthorized access ran 22 December 2025 to 15 January 2026 and suspicious activity was identified around 23 January. Data involved: names, Navia identification numbers, addresses, phone numbers, email addresses, enrollment dates, employee identifiers, Social Security numbers and dates of birth. The intrusion vector was not disclosed.
QualDerm Partners 22 Feb 2026 3,117,874 Healthcare HHS OCR Breach Portal (Cases Currently Under Investigation) ↗ confirmed 24 Jul 2026
What was exposed
Names Postal addresses Dates of birth Email addresses Medical records Government ID numbers
Disclosed via
HHS OCR breach portal
Discovered
24 Dec 2025
1-day dwell
Occurred → disclosed
23 Dec 2025 → 22 Feb 2026
61-day gap
Country
United States
Primary source
HHS OCR Breach Portal (Cases Currently Under Investigation) ↗
Last confirmed
24 Jul 2026
Revision
Record count revised. Verified 24 Jul 2026 against the HHS OCR breach portal, which lists QualDerm Partners, LLC, healthcare provider (TN), 3,117,874 individuals, hacking/IT incident on a network server, submitted 22 February 2026 — matching the company notice exactly. QualDerm is a dermatology practice group. An unauthorized actor accessed a limited number of systems over roughly two days, 23 to 24 December 2025; the incident was discovered on 24 December and notification letters were mailed from 22 February 2026. Data involved: names, addresses, dates of birth, email addresses, medical record numbers, treating-physician names, treatment and diagnosis information, health insurance information, dates of death, and in some cases government-issued identification. No group claimed the attack and the vector was not disclosed.
TriZetto Provider Solutions 6 Feb 2026 3,433,965 Healthcare HHS OCR Breach Portal (Cases Currently Under Investigation) ↗ confirmed 24 Jul 2026
What was exposed
Names Postal addresses Dates of birth Social Security numbers Medical records
Disclosed via
HHS OCR breach portal
Discovered
2 Oct 2025
317-day dwell
Occurred → disclosed
19 Nov 2024 → 6 Feb 2026
444-day gap
Country
United States
Primary source
HHS OCR Breach Portal (Cases Currently Under Investigation) ↗
Last confirmed
24 Jul 2026
Revision
Record count revised. Verified 24 Jul 2026 against the HHS OCR breach portal, which lists TriZetto Provider Solutions, business associate (MO), 3,433,965 individuals, hacking/IT incident on a network server, submitted 6 February 2026 — matching the figure in the company notice exactly. TriZetto is Cognizant's revenue-cycle and clearinghouse subsidiary. An unauthorized third party first accessed historical eligibility transaction reports in November 2024; only the month is stated in the notice, so no exact incident date is recorded. Suspicious activity was identified in a customer web portal on 2 October 2025, healthcare-client notifications began 9 December 2025, and consumer notifications in early February 2026. Data involved: names, addresses, dates of birth, Social Security numbers, health insurance and Medicare beneficiary numbers, and provider and insurer details. The company states no financial information was involved. The intrusion vector was not disclosed.
Coupang 16 Dec 2025 33,000,000 Retail & e-commerce Insider Coupang Faces Backlash Over $1.1 Billion Data Breach Payout in Vouchers → confirmed 23 Jul 2026
What was exposed
Names Phone numbers Postal addresses Email addresses
Disclosed via
SEC Form 8-K
Discovered
18 Nov 2025
Country
South Korea
Primary source
SEC EDGAR (Form 8-K, Item 1.05) ↗
Last confirmed
23 Jul 2026
Revision
Record count revised. Verified 23 Jul 2026 against Coupang's SEC Form 8-K. Coupang became aware on 18 November 2025. A former employee may have obtained names, phone numbers, delivery addresses and email addresses associated with up to 33 million customer accounts, plus order histories for a subset. No banking, payment-card or login credentials were compromised. The count recorded is the up-to-33-million figure the company itself stated; later Korean forensic reporting indicated data from roughly 3,000 accounts was actually stored, and both are noted here rather than one being chosen silently.
F5 15 Oct 2025 Undisclosed Technology Unknown SEC EDGAR (Form 8-K, Item 1.05) ↗ confirmed 23 Jul 2026
Disclosed via
SEC Form 8-K
Discovered
9 Aug 2025
Country
United States
Attributed to
Nation-state threat actor (unnamed by F5; public reporting links to China)
Primary source
SEC EDGAR (Form 8-K, Item 1.05) ↗
Last confirmed
23 Jul 2026
Revision
Record count revised. Verified 2026-07-23 via primary sources (F5 SEC 8-K + CISA ED-26-01). Nation-state actor held persistent access for an extended period; F5 became aware 2025-08-09 and disclosed 2025-10-15 after a DOJ-authorized delay. Stolen: portions of BIG-IP source code, undisclosed vulnerability research, and limited customer configuration data. CISA issued Emergency Directive ED-26-01 ordering federal agencies to patch or disconnect F5 devices. No consumer PII record count stated. Systemic security-vendor supply-chain event. Originally ingested from SEC EDGAR Item 1.05.
Jaguar Land Rover 2 Sep 2025 Undisclosed Other Jaguar Land Rover Faces Massive £540 Million Blow from Unprecedented Cyberattack → confirmed 24 Jul 2026
Disclosed via
Company statement only
Occurred → disclosed
31 Aug 2025 → 2 Sep 2025
2-day gap
Country
United Kingdom
Attributed to
Scattered Lapsus$ Hunters / Scattered Spider (claimed)
Primary source
Jaguar Land Rover - Statement on Cyber Incident (official) ↗
Last confirmed
24 Jul 2026
Revision
Record count revised. Verified 24 Jul 2026 against Jaguar Land Rover's own statements and UK official bodies. No affected-individuals count is recorded: JLR confirmed data theft but never published one, and the stolen material was an internal employee dataset alongside source code and development logs rather than a defined set of consumer records. Personal-data categories are likewise left empty because JLR did not enumerate them; third-party analysis of attacker-claimed data describes employee usernames, email addresses, display names and time zones. The attack began 31 August 2025; JLR took systems offline and disclosed publicly on 2 September, initially stating no evidence of customer data theft, then confirmed on 10 September that some data had been affected, and notified the ICO and the NCSC. The UK Cyber Monitoring Centre rated this a Category 3 systemic event on its five-point scale, estimating UK financial impact at 1.9 billion pounds (modelled range 1.6 to 2.1 billion) across more than 5,000 UK organizations — the most economically damaging cyber event to hit the UK.
Aflac 8 Aug 2025 13,924,906 Healthcare Unknown HHS Office for Civil Rights breach portal ↗
Disclosed via
HHS OCR breach portal
Country
United States
Primary source
HHS Office for Civil Rights breach portal ↗
Revision
Record count revised. VERIFIED 2026-07-21: read directly from the HHS OCR portal — "Aflac Incorporated", 13,924,906 individuals affected, submitted 08/08/2025, Hacking/IT Incident, business associate not present. This is a national entity-submitted figure and is the only count in this batch confirmed from a primary source today. Date shown is the HHS submission date, not the public announcement date.
Columbia University 7 Aug 2025 Undisclosed Education Unknown Oregon Department of Justice breach registry ↗
Disclosed via
US state attorney general filing
Discovered
8 Jul 2025
53-day dwell
Occurred → disclosed
16 May 2025 → 7 Aug 2025
83-day gap
Country
United States
Primary source
Oregon Department of Justice breach registry ↗
Revision
Record count revised. Verified 21 Jul 2026 from the Oregon Department of Justice breach registry: reported 7 August 2025, breach dates 16 May and 24 June 2025, discovered 8 July. The disclosure date recorded is Oregon's regulatory reporting date rather than a press announcement, and the incident date is the earlier of the two breach dates. No affected-individuals count has been published by a primary source, so the count is left blank rather than estimated. This record is Columbia University and is distinct from the HHS OCR entries for Columbia Eye Clinic, Columbia Orthopaedic Group and Columbia Medical Practice, which are unrelated entities.
Ingram Micro 5 Jul 2025 Undisclosed Technology Ransomware SEC EDGAR (Form 8-K, Item 8.01 — company statement) ↗
Disclosed via
SEC Form 8-K
Country
United States
Primary source
SEC EDGAR (Form 8-K, Item 8.01 — company statement) ↗
Revision
Record count revised. VERIFIED 2026-07-21 by reading the filed press release in full. Ingram Micro Holding Corporation (NYSE: INGM) issued the statement dated July 5, 2025; the 8-K was filed 2025-07-07. Vector is set to ransomware because the company states it directly — "Ingram Micro recently identified ransomware on certain of its internal systems" — rather than being inferred. Filed under Item 8.01 (Other Events), NOT Item 1.05, which is why an Item 1.05 sweep does not surface it; a material-looking incident is not always filed as one. The statement gives no records-affected figure, so that stays undisclosed. `occurred` and `discovered` are empty: the release says only "recently identified" and gives no dates.
Fidelity Investments 9 Oct 2024 Undisclosed Finance & banking Unknown Oregon Department of Justice breach registry ↗
Disclosed via
US state attorney general filing
Discovered
19 Aug 2024
2-day dwell
Occurred → disclosed
17 Aug 2024 → 9 Oct 2024
53-day gap
Country
United States
Primary source
Oregon Department of Justice breach registry ↗
Revision
Record count revised. Verified 21 Jul 2026 from the Oregon Department of Justice breach registry: reported 9 October 2024, breach dates 17 and 19 August 2024, discovered 19 August, notice sent 9 October. The disclosure date recorded is Oregon's regulatory reporting date, not a press-announcement date. No affected-individuals count has been published by a primary source, so the count is left blank rather than estimated. This record is Fidelity Investments specifically. Oregon separately lists Fidelity National Information Services, Fidelity & Guaranty Life Insurance and Fidelity Life Association, which are unrelated companies with their own 2023 filings and should not be merged with this one.
National Public Data 5 Sep 2024 Undisclosed Other Unknown Oregon Department of Justice breach registry ↗
Disclosed via
US state attorney general filing
Country
United States
Primary source
Oregon Department of Justice breach registry ↗
Revision
Record count revised. Verified 21 Jul 2026 from the Oregon Department of Justice breach registry, filed as Jerico Pictures, Inc. doing business as National Public Data, reported 5 September 2024. Oregon lists no breach dates and no discovery date for this filing, so both are left empty rather than inferred, and the disclosure date recorded is the regulatory reporting date. No affected-individuals count has been published by a primary source, so the count is left blank rather than estimated.
AT&T 12 Jul 2024 Undisclosed Telecom Unknown SEC EDGAR (Form 8-K, Item 1.05) ↗
Disclosed via
SEC Form 8-K
Country
United States
Primary source
SEC EDGAR (Form 8-K, Item 1.05) ↗
Revision
Record count revised. Verified 21 Jul 2026: the SEC Form 8-K Item 1.05 filing date and document URL were confirmed live on EDGAR (accession 0000732717-24-000046). This record covers both 2024 incidents, the March forum dump and the July Snowflake-related breach. No affected-individuals count has been published by a primary source, so the count is left blank rather than estimated.
Cencora 27 Feb 2024 Undisclosed Healthcare Unknown SEC EDGAR (Form 8-K, Item 1.05) ↗
Disclosed via
SEC Form 8-K
Country
United States
Primary source
SEC EDGAR (Form 8-K, Item 1.05) ↗
Revision
Record count revised. Verified 21 Jul 2026: the SEC Form 8-K Item 1.05 filing date and document URL were confirmed live on EDGAR. Cencora filed a second Item 1.05 on 31 July 2024. The sector is recorded as healthcare deliberately: Cencora's SIC code (5122, drug wholesale) maps to retail, which misdescribes a pharmaceutical distributor whose breach exposed patient data. No affected-individuals count has been published by a primary source, so the count is left blank rather than estimated.
Change Healthcare 22 Feb 2024 Undisclosed Healthcare Unknown SEC EDGAR (Form 8-K, Item 1.05, filed by UnitedHealth Group) ↗
Disclosed via
SEC Form 8-K
Discovered
21 Feb 2024
4-day dwell
Occurred → disclosed
17 Feb 2024 → 22 Feb 2024
5-day gap
Country
United States
Primary source
SEC EDGAR (Form 8-K, Item 1.05, filed by UnitedHealth Group) ↗
Revision
Record count revised. Verified 21 Jul 2026: filed by parent UnitedHealth Group, with the SEC Form 8-K Item 1.05 filing date and document URL confirmed live on EDGAR. No affected-individuals count is recorded. The widely-cited figure of about 192.7 million has not been confirmed against a primary source, and this table does not publish a number it has not verified. HHS OCR is where it would be confirmed, but the incident has aged out of the portal's 24-month window and sits in the archive.

No records match the current filters.

What the data shows

Every figure below comes from the verified table above, redrawn as the trends and comparisons a table cannot show.

Records affected by monthGrouped by disclosure month. Breaches with no stated record count are excluded rather than counted as zero.010M20M30M40MAug 2025: 13.9M records13.9M recordsAug 2025Dec 2025: 33.0M records33.0M recordsDec 2025Feb 2026: 6.6M records6.6M recordsFeb 2026Mar 2026: 4.7M records4.7M recordsMar 2026Jun 2026: 2.7M records2.7M recordsJun 2026Jul 2026: 18.8M records18.8M recordsJul 2026
Breaches by sectorDisclosed breaches per sector.Healthcare: 15Healthcare 15Finance & banking: 2Finance & banking 2Technology: 2Technology 2Other: 2Other 2Retail & e-commerce: 1Retail & e-commerce 1Education: 1Education 1Telecom: 1Telecom 1
Largest by records affectedOf breaches with a verified record count; many disclosures never state one.010M20M30M40MCoupangCoupang: 33,000,00033,000,000DentaQuestDentaQuest: 15,000,00015,000,000AflacAflac: 13,924,90613,924,906Unlimited Technol…Unlimited Technol…: 3,803,7503,803,750TriZetto Provider…TriZetto Provider…: 3,433,9653,433,965QualDerm PartnersQualDerm Partners: 3,117,8743,117,874Nacogdoches Memor…Nacogdoches Memor…: 2,507,0732,507,073Navia Benefit Sol…Navia Benefit Sol…: 2,151,3302,151,330XsolisXsolis: 1,396,5191,396,519MCBSMCBS: 1,261,4641,261,464
Longest disclosure lagsDays from occurrence to disclosure, where both dates are verified.0200400600TriZetto Provider…TriZetto Provider…: 444 days444 daysUnlimited Technol…Unlimited Technol…: 289 days289 daysMCBSMCBS: 277 days277 daysXsolisXsolis: 136 days136 daysNYC Health + Hosp…NYC Health + Hosp…: 119 days119 daysNavia Benefit Sol…Navia Benefit Sol…: 86 days86 daysColumbia Universi…Columbia Universi…: 83 days83 daysNacogdoches Memor…Nacogdoches Memor…: 74 days74 daysQualDerm PartnersQualDerm Partners: 61 days61 daysDentaQuestDentaQuest: 60 days60 days

If your data was in one of these

Every record above names the public register its notice was filed in, because that notice is the document that says what was taken. Start there rather than with coverage: it is dated, official, and specific to you.

  1. Read the organization’s own notice. Each row’s detail links the primary source. It states what categories of data were involved, which is the fact that decides what to do next.
  2. Check the register for your jurisdiction. The routes below are the ones this page cites.
  3. Watch the date, not the headline. Counts on this page are as stated at disclosure and are often revised upward later, so a notice can be more current than the number here.
  • HHS OCR breach portal ↗ US health data. Searchable by organization; lists every breach of 500 or more records.
  • US state attorney general filings ↗ Many states publish the notice letters themselves, which name the exact data involved.
  • SEC Form 8-K ↗ What a listed company told its investors, on the record and dated.

This page tracks disclosures. It is not legal advice, and it cannot tell you whether you personally appear in a given breach; only the notice and the register can.

Verification ledger

5 most recent of 5 logged updates
  • Five disclosures added after the register sweep: DentaQuest (15,000,000, largest US healthcare breach of 2026), Unlimited Technology Systems (3,803,750), MCBS (1,261,464), Amgen (count not published), RingCentral (company-confirmed; 1,596,490-email leaked corpus). Sub-million register entries stay parked as drafts per the publication floor. 14 Aug 2026
  • Five-lens page audit passed; Dataset creator reference corrected in schema (3.83.1). 30 Jul 2026
  • Notice pathway recorded on all 21 records: how each disclosure reached its public register (state attorney general filing, HHS OCR portal, SEC 8-K, data protection authority notice, or company statement). 30 Jul 2026
  • Every new row verified against SEC filings, the HHS OCR portal, or the company's own notice; counts publish only where a primary source states one 24 Jul 2026
  • 13 major breaches added, extending coverage through July 2026: Coupang, F5, TriZetto, QualDerm, Jaguar Land Rover and more 24 Jul 2026

How this tracker is maintained

Every record passes the same checks before it appears, and stays under review after.

  1. 01

    Sourced

    Each record traces to a primary disclosure: an SEC filing, a state attorney general notice, the HHS breach portal, or the company’s own statement. Counts stay as disclosed, and a third-party corpus count is always labeled as one.

  2. 02

    Dated

    Each row carries its disclosure date, and where the source states it, the gap between occurrence and disclosure.

  3. 03

    Re-checked

    Records are re-verified on a 30-day cycle, and disclosed counts get corrected when organizations revise their filings.

Where do these come from?
Regulator portals and company disclosures only, linked on every row. An absent count renders as Undisclosed rather than zero, because absence is a real answer.
Why is healthcare so common here?
The HHS breach portal is the most complete public disclosure feed, so healthcare incidents surface more reliably than other sectors. That reflects disclosure rules, not how attacks distribute across industries.

This is informational content. Disclosed figures reflect what organizations reported as of the stated dates, and companies revise counts. Confirm with the linked primary source before relying on a number.

Quoting a figure with a link to this page needs no permission. Cite it as you would any source. Reuse of the compiled dataset itself is licensed under CC BY 4.0: credit SQ Magazine and link back.

Sources

  • HHS OCR Breach Portal (Cases Currently Under Investigation)
  • HHS Office for Civil Rights breach portal
  • Have I Been Pwned
  • Jaguar Land Rover - Statement on Cyber Incident (official)
  • NYC Health + Hospitals - Notice of Data Breach (official)
  • Oregon Department of Justice breach registry
  • SEC EDGAR (Form 8-K, Item 1.05)
  • SEC EDGAR (Form 8-K, Item 1.05, filed by UnitedHealth Group)
  • SEC EDGAR (Form 8-K, Item 8.01 — company statement)

Breach data from Have I Been Pwned, licensed under CC BY 4.0. Corpus counts are the number of records in that dataset and are not confirmed disclosure figures.

Footer

SQ Magazine Logo

Smarter Insights for a Fast-Moving Digital World

Connect With Us

Follow Us on Google News

Editorial & Trust

  • About
  • Publishing Principles
  • Fact-Check Policy
  • Corrections Policy
  • Ethics Policy
  • Disclaimer

Worth Checking

  • Social Media Attention Span Stats
  • Gen Z Social Media Statistics
  • TikTok vs. Instagram Statistics
  • LLM Hallucination Statistics
  • Spotify User Statistics
  • Apple Customer Loyalty Statistics
  • Data Breach Tracker
  • Patch Tuesday Dashboard
  • AI Model Tracker
  • AI Funding Tracker
Contact Us
13570 Grove Dr #189,
Maple Grove, MN 55311,
United States
10 a.m. to 6 p.m. | Every day

Copyright © 2022–2026 SQ Magazine. All Rights Reserved. Powered by the Neural Stack.

  • Privacy Policy
  • Terms
  • Accessibility Statement
Company
  • About Us
  • Our Team
  • Our Mission
  • Core Values
Discover
  • Brand Assets
    Brand Assets
  • Stats Methodology
    Stats Research Process
  • Glossary
    Glossary
Categories
  • Internet
  • Technology
  • Artificial Intelligence
  • Gaming
  • Cybersecurity
Internet
Spotify Listening Statistics
Spotify Listening Statistics 2026: Average Listening Time
How Many Subscribers Does MrBeast Have
How Many Subscribers Does MrBeast Have in 2026? Channel Growth Statistics
WhatsApp Business Statistics
WhatsApp Business Statistics 2026: Real Market Insights
Udemy Statistics
Udemy Statistics 2026: Revenue and Learner Data
Coursera Statistics
Coursera Statistics 2026: Learners, Revenue and Growth Data
Reddit vs X Statistics
Reddit vs X Statistics 2026: Users and Revenue
Technology
How Many iPhones Has Apple Sold
How Many iPhones Has Apple Sold in 2026? Units Sold by Year
How Many Employees Does Amazon Have
How Many Employees Does Amazon Have 2026: Workforce Growth
Netflix vs. Hulu Statistics
Netflix vs Hulu Statistics 2026: Viewer Growth Data
TripAdvisor Statistics
TripAdvisor Statistics 2026: Revenue, Reviews, Viator and TheFork Data
Search Engine Statistics
Search Engine Statistics 2026: Market Share, Volume & AI Shift
NVIDIA Employee Count Statistics
NVIDIA Employee Count Statistics 2026: Headcount, R&D, and Revenue
Artificial Intelligence
AI Music Statistics
AI Music Statistics 2026: Generation, Adoption and Industry Impact
AI Coding Statistics
AI Coding Statistics 2026: Adoption, Productivity and Market Data
How Much Content on Social Media Is AI Generated Statistics
How Much Content on Social Media Is AI Generated Statistics 2026: Hidden Truths
ChatGPT vs DeepSeek Statistics
ChatGPT vs DeepSeek Statistics 2026: Users, Benchmarks & Pricing
ChatGPT vs Claude vs Gemini vs Perplexity Statistics
ChatGPT vs Claude vs Gemini vs Perplexity Statistics 2026: Users, Revenue & Market Share
How Many People Work At Midjourney
How Many People Work At Midjourney 2026: Lean Team, Big Revenue
Gaming
Gaming Statistics
Gaming Statistics 2026: Market Size, Players, Revenue, and Platforms
Roblox vs Minecraft Statistics
Roblox vs Minecraft Statistics 2026: Players, Revenue, Creators
Online Gambling Regulations Statistics
Online Gambling Regulations Statistics 2026: Global Compliance and Enforcement Data
Fantasy Sports Statistics
Fantasy Sports Statistics 2026: Users, Revenue & Trends
Apex Legends Statistics
Apex Legends Statistics 2026: Players, Revenue, and Esports
Fortnite Statistics
Fortnite Statistics 2026: Players, Revenue, Esports, and Engagement
Cybersecurity
Signal Statistics
Signal Statistics 2026: Users, Finances and Encryption Adoption
Password Statistics
Password Statistics 2026: Credential Theft, MFA, and the Passkey Tipping Point
Identity Theft Statistics
Identity Theft Statistics 2026: Key Fraud Data and Trends
CVE Statistics
CVE Statistics 2026: Severity Distribution and Top Affected Vendors
Dark Web AI Tool Marketplace Statistics
Dark Web AI Tool Marketplace Statistics 2026: Explosive Market Growth
API Security Breach Statistics
API Security Breach Statistics 2026: Hidden Threats
Categories
  • Cybersecurity
  • Artificial Intelligence
  • Internet
  • Technology
  • Gaming
Cybersecurity
Microsoft Bitlocker Rce Patch
Critical Windows BitLocker Flaw Sparks Urgent Patch
Cpanel Mailtrack Flaw Patched
cPanel Fixes Powerful Root Access Bug in EmailTrack
Quickfox Supply Chain Security
QuickFox Partners with Murphy Security to Strengthen Client Software Supply Chain Security
Chrome Zero Day Exploited Patched
Google Fixes 12 Chrome Flaws: Urgent Update Released
Plex Patches Critical Media Server Security Flaws
Plex Patches Critical Media Server Security Flaws
X Password Reset Attack Crypto Accounts
X Users Hit by Barrage of Unsolicited Password Reset Emails
Artificial Intelligence
Openai Samsung Ai Chip Alliance
OpenAI Taps Samsung for Breakthrough Next-Gen Chips
Openai Agents Hijack German Wiki Site
OpenAI Agents Hijacked German Wiki, Researchers Say
Gpt 6 Astra Launched For Daybreak Users
OpenAI Releases GPT-6 Astra After Largest Training Run Yet
Claude Down Opus 5 And Fable 5
Claude Services Disrupted as Multiple Models Report Elevated Errors
Nvidia Huggingface Acquisition
Nvidia Confirms Acquisition of Hugging Face for $12.9 Billion
Gemini 3 8 Flash Vox Featured Text V2 1250x703 1
Gemini 3.8 Flash Rolls Out With a Major Performance Boost
Internet
Apple Wallet Ids Launch In Oklahoma
Apple Wallet IDs Launch in Oklahoma in Major Expansion
Meta to Pay 18 Billion in Landmark Teen Safety Deal
Meta to Pay $18 Billion in Landmark Teen Safety Deal
Whatsapp Brings Passkeys 2fa
WhatsApp Hits 1 Billion Passkey Users, Adds 2FA Passwords
Apple Eu App Store Fee Reduction
Apple Sets New EU App Store Fees, Effective October 1
Github Outage Aug 2026
GitHub Down: Outage Hits Thousands of Users Worldwide
Russia S Fsb Charges Telegram Founder Durov With Terrorism
Russia’s FSB Charges Telegram Founder Durov With Terrorism
Technology
Apple Iphone 18 And 18 Pro Launched
iPhone 18 Pro Debuts With Breakthrough Camera Upgrades
Iphone Foldable Launch Rumours Mark Gurmann
Apple Foldable iPhone To Top $2,000 In Leaked Roadmap
Eu Dsa Chatgpt Reddit Roblox Compliance
EU Expands Powerful DSA Oversight to ChatGPT and Reddit
Apple Confirms September 9 iPhone Event Under CEO Ternus
Apple Confirms September 9 iPhone Event Under CEO Ternus
Apple Mac Studio M5 Chip
New Mac Studio M5 Ultra Brings Massive On-Device AI Power
Walmart Finally Adds Apple Pay Ending Decade-Long Holdout
Walmart Adds Apple Pay and Google Pay Starting August 24
Gaming
Xbox Live Down Again
Xbox Live Down Again: Sign-In Error 0x80004005 Hits Players
Gta Vi Official Cover Art
GTA 6 Pre-Orders Start June 25, New Cover Art Unveiled
Epic Games Teases Unreal Engine 6 For Rocket League
Epic Games Teases Unreal Engine 6 for Rocket League
Stardew Valley Launched For Nintendo Switch 2 Edition
Stardew Valley Switch 2 Edition Arrives with Online Co-op
Hogwarts Legacy Game Crosses 40m Downloads
Hogwarts Legacy Crosses 40M Sales, Beating Industry Giants
Pubg Black Budget Closed Alpha Launched
PUBG: Black Budget Launches Closed Alpha Test With a Bold PvPvE Twist