SQ Magazine The Threat Index Tracker
This tracker records every major breach disclosed since January 2024. Each row gives the organization, the disclosure date, how many people were affected, and the attack vector, with a link to the primary source.
21 records updated through 2 Jul 2026
Latest change Every new row verified against SEC filings, the HHS OCR portal, or the company's own notice; counts publish only where a primary source states one (24 Jul 2026) All changes
| Organization | Disclosed | Records (as disclosed) | Sector | Vector | Our report | Record detail |
|---|---|---|---|---|---|---|
| AdaptHealth | 2 Jul 2026 | Undisclosed | Healthcare | Phishing | SEC EDGAR (Form 8-K, Item 1.05) ↗ | |
Record count revised. Verified 2026-07-23 via primary sources (AdaptHealth SEC 8-K). Threat actor contacted the company 2026-06-15; materiality determined 2026-06-27. Attacker compromised a third-party contractor user session via social engineering and accessed cloud-based patient-management systems and document storage, exfiltrating stored password files tied to insurance-billing and external EHR portals containing patient PHI. Volume at risk not quantified. Large US home-medical-equipment provider. Originally ingested from SEC EDGAR Item 1.05. |
||||||
| Navient | 2 Jul 2026 | Undisclosed | Finance & banking | Ransomware | SEC EDGAR (Form 8-K, Item 1.05) ↗ | |
Record count revised. Verified 2026-07-23 via primary sources (Navient SEC 8-K). Ransomware attack against a third-party law firm that provides services to Navient; Navient became aware 2026-06-08 and determined materiality 2026-06-29. Borrower data exposed via the firm included names, dates of birth, addresses and Social Security numbers. No evidence of access to Navient own systems. Individual count not stated in the filing. Originally ingested from SEC EDGAR Item 1.05. |
||||||
| Xsolis | 5 Jun 2026 | 1,396,519 | Healthcare | Phishing | HHS Office for Civil Rights breach portal ↗ | |
Record count revised. Verified 2026-07-23 via HHS OCR (1,396,519) plus multiple outlets citing the Xsolis notice. Tennessee healthcare-AI vendor (HIPAA business associate) breached via a targeted phishing email to a single employee; unauthorized access 2026-01-20 to 2026-01-22. Exposed names, dates of birth, Social Security numbers, health-insurance and medical-treatment information for 1,396,519 individuals across seven-to-eight hospital systems including Mayo Clinic. HHS OCR posted the figure 2026-06-22; breach report dated 2026-06-05. One of the largest US healthcare incidents of the year. Originally ingested from the HHS OCR breach portal. |
||||||
| West Pharmaceutical Services | 11 May 2026 | Undisclosed | Healthcare | Ransomware | SEC EDGAR (Form 8-K, Item 1.05) ↗ | |
Record count revised. Verified 2026-07-23 via primary sources (West SEC 8-K and 8-K/A). Detected a compromise 2026-05-04; determined material 2026-05-07. Ransomware: data exfiltrated and systems encrypted; company took systems offline globally and engaged Palo Alto Unit 42. Scope of affected data still under investigation; individual count not disclosed. S&P 500 pharmaceutical-packaging and drug-delivery supplier. Fold of 8-K/A 27890 (2026-05-20, operations restored). Originally ingested from SEC EDGAR Item 1.05. |
||||||
| Stryker | 9 Apr 2026 | Undisclosed | Healthcare | Unknown | Iran Linked Hackers Claim Massive Attack on Stryker → | |
Record count revised. Verified 2026-07-23 via primary sources (Stryker SEC 8-K/A + company customer notice). Identified 2026-03-11. Attributed to Handala, an Iran-linked hacktivist group, which weaponized Stryker Microsoft Intune device-management platform to wipe data from thousands of devices (destructive/wiper attack). Disrupted order processing, manufacturing and shipping; material impact to Q1 2026 results, no material impact to full-year guidance. 8-K/A filed 2026-04-09. SQ covered as post 19568. Originally ingested from SEC EDGAR Item 1.05. PII exfiltration unconfirmed as of Jul 2026: attackers claim data theft, the company has not confirmed it, and class-action litigation is ongoing. Listed with an Undisclosed count on that basis; owner call 2026-07-24 to include; update when the record clarifies. |
||||||
| Nacogdoches Memorial Hospital | 30 Mar 2026 | 2,507,073 | Healthcare | HHS OCR Breach Portal (Cases Currently Under Investigation) ↗ | ||
Record count revised. Verified 2026-07-24 against the HHS OCR Breach Portal. Listed as Nacogdoches Memorial Hospital, Healthcare Provider (TX), 2,507,073 individuals, Hacking/IT Incident, Network Server, breach submission date 03/30/2026. DISCREPANCY FLAG: the hospital's public messaging and early press (SecurityWeek, Paubox) cite roughly 250,000 / 257,073 individuals, but the HHS OCR filing states 2,507,073; per task instruction the OCR figure is used. An editor should confirm before publishing given the ~10x gap. Unauthorized access to the network 2026-01-15 to 2026-01-31; discovered 2026-01-31; consumer notifications began 2026-03-31. Data involved: names, addresses, phone numbers, email addresses, SSNs, dates of birth, medical record numbers, account numbers, health plan beneficiary numbers, and photographs. No known ransomware group claimed responsibility; threat actor not disclosed. Count authority: OCR portal. |
||||||
| NYC Health + Hospitals | 24 Mar 2026 | Undisclosed | Healthcare | Third-party / supply chain | NYC Health + Hospitals - Notice of Data Breach (official) ↗ | |
Record count revised. Verified 2026-07-24. records left blank (Undisclosed) per task instruction: the OCR portal shows NO exact figure for this incident. Every source describes the count as approximately / up to / at least 1.8 million current and former patients and employees - never an exact posted number. NOTE: the OCR portal does list a SEPARATE, unrelated NYC Health + Hospitals entry of 5,728 individuals submitted 06/06/2025, which is a different and much smaller incident and NOT this breach; this mega-breach (reported to HHS 2026-03-24) was not yet individually posted on the public portal at time of verification. Per the official Notice of Data Breach: an unauthorized third party exploited a flaw in an unnamed third-party vendor (hence vector supply-chain), had access 2025-11-25 to 2026-02-11; NYC H+H discovered suspicious activity 2026-02-02. Data involved: demographic, medical, insurance and billing information, SSNs, government identification numbers, and biometric data including fingerprints and palm prints. Primary source: NYC Health + Hospitals official Notice of Data Breach. PUBLISH-READY only if the Undisclosed count is acceptable to the editor; otherwise hold for the exact OCR figure once posted. |
||||||
| Navia Benefit Solutions | 18 Mar 2026 | 2,151,330 | Healthcare | 2.7 Million Affected in Navia Cyberattack Linked to API Flaw → | ||
Record count revised. Verified 2026-07-24 against the HHS OCR Breach Portal. Listed as Navia Benefit Solutions, Inc., Business Associate (WA), 2,151,330 individuals, Hacking/IT Incident, Network Server + Other, breach submission date 03/18/2026. DISCREPANCY FLAG: many press reports and the existing SQ article (post 19870) cite ~2.7 million; the 2,151,330 figure is the PHI count Navia reported to HHS OCR and is used here per task instruction (OCR is the count authority). Navia administers employee health/benefits (FSA/HSA/COBRA), a HIPAA business associate. Unauthorized access 2025-12-22 to 2026-01-15; suspicious activity identified around 2026-01-23. Data involved: first and last names, Navia ID numbers, addresses, phone numbers, email addresses, enrollment start/end dates, employee IDs, SSNs, and dates of birth. Vector not disclosed. Existing SQ coverage set as _brt_coverage (post 19870). Count authority: OCR portal. |
||||||
| QualDerm Partners | 22 Feb 2026 | 3,117,874 | Healthcare | HHS OCR Breach Portal (Cases Currently Under Investigation) ↗ | ||
Record count revised. Verified 2026-07-24 against the HHS OCR Breach Portal. Listed as QualDerm Partners, LLC, Healthcare Provider (TN), 3,117,874 individuals, Hacking/IT Incident, Network Server, breach submission date 02/22/2026 - count matches the lead exactly. QualDerm is a dermatology practice group. Unauthorized actor accessed a limited number of systems 2025-12-23 to 2025-12-24 (about two days); incident discovered 2025-12-24; notification letters mailed from 2026-02-22. Data involved: names, addresses, dates of birth, email addresses, medical record numbers, treating-physician names, treatment/diagnosis information, health insurance information, dates of death, and in some cases government-issued ID information. No ransomware group claimed the attack; specific vector not disclosed. Count authority: OCR portal. |
||||||
| TriZetto Provider Solutions | 6 Feb 2026 | 3,433,965 | Healthcare | HHS OCR Breach Portal (Cases Currently Under Investigation) ↗ | ||
Record count revised. Verified 2026-07-24 against the HHS OCR Breach Portal. Listed there as TriZetto Provider Solutions, Business Associate (MO), 3,433,965 individuals, Hacking/IT Incident, Network Server, breach submission date 02/06/2026 - count matches the lead exactly. TriZetto is Cognizant's RCM/clearinghouse subsidiary. An unauthorized third party first accessed historical eligibility transaction reports in November 2024 (only the month is stated in the notice, so _brt_occurred left blank); suspicious activity was identified in a customer web portal on 2025-10-02; healthcare-client notifications began 2025-12-09 and consumer notifications early Feb 2026. Data involved: names, addresses, dates of birth, SSNs, health insurance numbers, Medicare beneficiary numbers, provider and insurer names, primary-insured details; the company states no financial information was involved. Specific intrusion vector not disclosed. Count authority: OCR portal; corroborated by the company notice as summarised by HIPAA Journal. |
||||||
| Coupang | 16 Dec 2025 | 33,000,000 | Retail & e-commerce | Insider | Coupang Faces Backlash Over $1.1 Billion Data Breach Payout in Vouchers → | |
Record count revised. Verified 2026-07-23 against the primary SEC 8-K (cpng-20251215). Coupang became aware 2025-11-18. A former employee may have obtained name, phone number, delivery address and email address associated with up to 33 million customer accounts, plus certain order histories for a subset. No banking, payment-card or login credentials were compromised. Records = up to 33M accounts as stated by the company (later Korean forensic reporting indicated data from roughly 3,000 accounts was actually stored). Fold of 8-K/A 27897 (2025-12-29). SQ covered as post 15744. Originally ingested from SEC EDGAR Item 1.05. |
||||||
| F5 | 15 Oct 2025 | Undisclosed | Technology | Unknown | SEC EDGAR (Form 8-K, Item 1.05) ↗ | |
Record count revised. Verified 2026-07-23 via primary sources (F5 SEC 8-K + CISA ED-26-01). Nation-state actor held persistent access for an extended period; F5 became aware 2025-08-09 and disclosed 2025-10-15 after a DOJ-authorized delay. Stolen: portions of BIG-IP source code, undisclosed vulnerability research, and limited customer configuration data. CISA issued Emergency Directive ED-26-01 ordering federal agencies to patch or disconnect F5 devices. No consumer PII record count stated. Systemic security-vendor supply-chain event. Originally ingested from SEC EDGAR Item 1.05. |
||||||
| Jaguar Land Rover | 2 Sep 2025 | Undisclosed | Other | Jaguar Land Rover Faces Massive £540 Million Blow from Unprecedented Cyberattack → | ||
Record count revised. Verified 2026-07-24 via Jaguar Land Rover official statements and UK official bodies. records left blank (Undisclosed): JLR confirmed data theft but never published an affected-individuals count; the stolen material was an internal/employee dataset plus source code and development logs, not a defined consumer PII set. Timeline: attack began 2025-08-31; JLR took IT systems offline and disclosed the incident publicly 2025-09-02 (initially stated no evidence of customer data theft); on 2025-09-10 it confirmed some data has been affected; it notified the ICO and the NCSC. exposed left empty because JLR did not enumerate personal-data categories; attacker-claimed data (per third-party analysis) includes employee usernames, email addresses, display names and time zones plus source code and dev logs. CLASSIFICATION: the UK Cyber Monitoring Centre (CMC) rated this a Category 3 systemic event on its five-point scale, estimating UK financial impact at 1.9 billion pounds (modelled range 1.6 to 2.1 billion pounds) and 5,000+ affected UK organisations - the most economically damaging cyber event to hit the UK (CMC statement 2025-10-22, https://cybermonitoringcentre.com/2025/10/22/cyber-monitoring-centre-statement-on-the-jaguar-land-rovercyber-incident-october-2025/ ; NCSC https://www.ncsc.gov.uk/news/jlr-incident). Sector set to other (automotive manufacturing). Attribution recorded in _brt_attributed. Existing SQ coverage set as _brt_coverage (post 12324). |
||||||
| Aflac | 8 Aug 2025 | 13,924,906 | Healthcare | Unknown | HHS Office for Civil Rights breach portal ↗ | |
Record count revised. VERIFIED 2026-07-21: read directly from the HHS OCR portal — "Aflac Incorporated", 13,924,906 individuals affected, submitted 08/08/2025, Hacking/IT Incident, business associate not present. This is a national entity-submitted figure and is the only count in this batch confirmed from a primary source today. Date shown is the HHS submission date, not the public announcement date. |
||||||
| Columbia University | 7 Aug 2025 | Undisclosed | Education | Unknown | Oregon Department of Justice breach registry ↗ | |
Record count revised. VERIFIED 2026-07-21 from the Oregon DOJ breach registry: reported 08/07/2025, dates of breach 5/16/2025 and 6/24/2025, date of discovery 7/8/2025. `disclosed` holds Oregon's REPORTED date (a regulatory notification), not a press-announcement date — replace it if the university announced publicly on a different day. `occurred` is the earliest of the two breach dates. NEEDS SOURCING: records affected. ⚠️ Do NOT confuse with the HHS OCR entries for Columbia Eye Clinic, Columbia Orthopaedic Group or Columbia Medical Practice — all unrelated entities. |
||||||
| Ingram Micro | 5 Jul 2025 | Undisclosed | Technology | Ransomware | SEC EDGAR (Form 8-K, Item 8.01 — company statement) ↗ | |
Record count revised. VERIFIED 2026-07-21 by reading the filed press release in full. Ingram Micro Holding Corporation (NYSE: INGM) issued the statement dated July 5, 2025; the 8-K was filed 2025-07-07. Vector is set to ransomware because the company states it directly — "Ingram Micro recently identified ransomware on certain of its internal systems" — rather than being inferred. Filed under Item 8.01 (Other Events), NOT Item 1.05, which is why an Item 1.05 sweep does not surface it; a material-looking incident is not always filed as one. The statement gives no records-affected figure, so that stays undisclosed. `occurred` and `discovered` are empty: the release says only "recently identified" and gives no dates. |
||||||
| Fidelity Investments | 9 Oct 2024 | Undisclosed | Finance & banking | Unknown | Oregon Department of Justice breach registry ↗ | |
Record count revised. VERIFIED 2026-07-21 from the Oregon DOJ breach registry: reported 10/09/2024, dates of breach 8/17/2024 and 8/19/2024, date of discovery 8/19/2024, notice sent 10/9/2024. Replaces Comcast in Batch 1, whose own filing (reported 12/18/2023, breach October 2023) falls outside the 2024-to-July-2025 window. `disclosed` holds Oregon's regulatory reporting date, not a press-announcement date. NEEDS SOURCING: records affected. ⚠️ This is FIDELITY INVESTMENTS specifically. Oregon separately lists Fidelity National Information Services, Fidelity & Guaranty Life Insurance and Fidelity Life Association — all 2023 filings by unrelated companies. Do not merge or cite them. |
||||||
| National Public Data | 5 Sep 2024 | Undisclosed | Other | Unknown | Oregon Department of Justice breach registry ↗ | |
Record count revised. VERIFIED 2026-07-21 from the Oregon DOJ breach registry, filed as "JERICO PICTURES, INC. D/B/A NATIONAL PUBLIC DATA": reported 09/05/2024. Oregon lists NO dates of breach and NO date of discovery for this filing, so `occurred` and `discovered` stay empty rather than being inferred. `disclosed` holds the regulatory reporting date. NEEDS SOURCING: records affected. |
||||||
| AT&T | 12 Jul 2024 | Undisclosed | Telecom | Unknown | SEC EDGAR (Form 8-K, Item 1.05) ↗ | |
Record count revised. VERIFIED 2026-07-21: 8-K Item 1.05 filing date and document URL confirmed live on EDGAR (accession 0000732717-24-000046). NEEDS SOURCING: records affected. This page covers BOTH 2024 incidents (March forum dump and July Snowflake) per the CW brief scope call. |
||||||
| Cencora | 27 Feb 2024 | Undisclosed | Healthcare | Unknown | SEC EDGAR (Form 8-K, Item 1.05) ↗ | |
Record count revised. VERIFIED 2026-07-21: 8-K Item 1.05 date and document URL confirmed live on EDGAR. Cencora filed a second Item 1.05 on 2024-07-31. Sector set to healthcare deliberately: the SIC code (5122, drug wholesale) maps to retail, which misdescribes a pharmaceutical distributor whose breach exposed patient data. NEEDS SOURCING: records affected. |
||||||
| Change Healthcare | 22 Feb 2024 | Undisclosed | Healthcare | Unknown | SEC EDGAR (Form 8-K, Item 1.05, filed by UnitedHealth Group) ↗ | |
Record count revised. VERIFIED 2026-07-21: filed by parent UnitedHealth Group; 8-K Item 1.05 date and document URL confirmed live on EDGAR. NEEDS SOURCING: records affected. The widely-cited ~192.7M figure was NOT verified against a primary source in this pass and must not be published until it is — HHS OCR is the place to confirm it, but this incident has aged out of the 24-month portal window and sits in the archive. |
||||||
No records match the current filters.
Every record passes the same checks before it appears, and stays under review after.
Each record traces to a primary disclosure: an SEC filing, a state attorney general notice, the HHS breach portal, or the company’s own statement. Counts stay as disclosed, and a third-party corpus count is always labeled as one.
Each row carries its disclosure date, and where the source states it, the gap between occurrence and disclosure.
Records are re-verified on a 30-day cycle, and disclosed counts get corrected when organizations revise their filings.
This is informational content. Disclosed figures reflect what organizations reported as of the stated dates, and companies revise counts. Confirm with the linked primary source before relying on a number.