
Contents
The State Of Ransomware July 2026
July recorded 111 publicly disclosed ransomware attacks, a 6.7% increase over the 104 attacks reported during the same month last year. Victims spanned 27 countries, with the United States accounting for 53% of all incidents. Healthcare remained the most heavily targeted sector, making up 35% of reported attacks, followed by services (14%) and manufacturing (11%). While 31 ransomware groups were publicly linked to attacks, 47% of incidents remain unattributed, underscoring the continued difficulty of identifying the actors behind many intrusions. The Gentlemen was the most active group in July, claiming 11 attacks.
1. Aflac Life Insurance Japan disclosed the largest of the recent cyber incidents after attackers compromised its customer portal and other systems, exposing the personal information of approximately 4.38 million policyholders. The stolen data included customer names, addresses, and phone numbers, while about 230,000 customers also had their premium payment account information compromised. After detecting the intrusion, Aflac suspended portions of its systems but continued processing insurance claims and customer inquiries through alternative channels. The company said the breach was limited to its Japanese operations, notified Japanese law enforcement and cybersecurity authorities, and filed an 8-K disclosure with the U.S. Securities and Exchange Commission.
2. Industrial manufacturer Nidec disclosed that ransomware actors compromised part of the network at its Taiwanese subsidiary, Nidec Chaun Choung Technology, resulting in a potential information leak. While the company said it has not confirmed that any personal or confidential data has been published online, BlackField ransomware group claimed responsibility for the attack, alleging it stole more than 2 TB of corporate data, including employee, financial, procurement, manufacturing, legal, and IT records, and demanded a $2 million ransom. Nidec stated that the subsidiary operates on an independent network, limiting the impact on the broader organization. The company has not indicated whether it is in contact with the attackers.
3. Colorado Health Network (CHN), a nonprofit healthcare provider serving people living with HIV across Colorado, disclosed a 2025 data breach that affected 68,212 individuals after unauthorized access to its systems. The compromised information varies by individual but includes names, Social Security numbers, medical records, health insurance information, driver’s license and passport details, financial account and payment card information, and other sensitive personal data. Cephalus ransomware group claimed responsibility for the attack, although CHN has not publicly confirmed the group’s claims.
4. Sapporo Holdings disclosed a suspected cyberattack affecting two overseas subsidiaries, Singapore-based Pokka and Canadian brewer Sleeman Breweries, after detecting suspicious activity on their networks. In response, the company isolated the affected systems while investigating whether any corporate or customer data was accessed or exfiltrated. Sapporo said there is no evidence that its domestic operations in Japan were impacted. The company has not disclosed the type of attack or identified a threat actor. As of the latest update, the investigation remains ongoing, and the company has not confirmed whether any data was compromised.
5. Qilin ransomware group claimed responsibility for an attack on Canadian industrial equipment manufacturer Chamco Industries, alleging that it stole company data and threatening to publish the information if ransom negotiations are not initiated. Chamco has not publicly confirmed the incident or verified the attackers’ claims, and the full scope of any potential data compromise remains unknown. The allegations are based solely on statements posted by the ransomware group, with no independent confirmation that data was exfiltrated.
6. Following a cybersecurity incident that disrupted parts of its network, Salida School District in Colorado launched an investigation with the assistance of cybersecurity experts to assess the scope and impact of the attack. The district has not confirmed that any sensitive or personal information was accessed, but Qilin ransomware group has claimed responsibility, alleging it compromised the district’s systems. Recovery efforts remain ongoing as officials work to restore services and determine whether any data was affected.
7. Abans Financial Services disclosed a probable ransomware attack after receiving an alert from the Indian Computer Emergency Response Team (CERT-In). The company said the incident was limited to the IT infrastructure of its overseas subsidiaries and did not affect its own systems or disrupt business operations. While the company did not disclose the ransomware group involved or whether any data was compromised, it said it continues to monitor the situation and implement remedial measures.
8. Spanish defense and technology company Indra Group confirmed that a ransomware attack affected one of its subsidiaries after The Gentlemen ransomware group claimed responsibility. The company said the incident was contained within non-critical environment, with no disruption to operations and no evidence that the attack spread to other parts of the organization. While The Gentlemen claimed to have stolen sensitive data and threatened to publish it if ransom demands are not met, Indra has not verified those claims and said its investigation remains ongoing.
9. Pennant Hills Golf Club launched an investigation into a cybersecurity incident after detecting unauthorized access to its systems. The club said it quickly secured the affected environment and engaged external cybersecurity experts to support the response. Although the Qilin ransomware group has claimed responsibility for the attack, the club has not confirmed the group’s allegations or disclosed whether any data was accessed or exfiltrated.
10. Women’s Center for Radiology, a medical imaging provider with three locations in Orlando, Florida, notified patients of a data breach after discovering unauthorized access to a portion of its network on or around April 28, 2026. An investigation found that an unauthorized third party viewed or downloaded files containing sensitive patient information, including names, addresses, dates of birth, contact information, medical records, diagnoses, lab results, health insurance information, and driver’s license numbers. The provider is offering complimentary credit monitoring and identity theft protection services while reviewing its security policies and procedures. The total number of affected individuals has not yet been publicly disclosed.
11. A social engineering attack targeting a third-party contractor’s account led to unauthorized access to cloud-based business applications used by AdaptHealth, exposing patient data. The home medical equipment and healthcare services provider said the attackers gained access to internal patient management systems, document storage platforms, and external electronic health record portals, resulting in the exfiltration of personally identifiable information, protected health information, and stored password files associated with insurance billing accounts. ShinyHunters extortion group later claimed responsibility for the incident, although AdaptHealth has not confirmed the attribution. The company has engaged cybersecurity experts, notified law enforcement, and continues to investigate the full scope and impact of the incident.
12. North Media reported a cybersecurity incident affecting its Swedish subsidiary, SDR Svensk Direktreklam, prompting the company to isolate impacted systems and launch an investigation. The attack disrupted operations at SDR, although North Media said there is currently no indication that customer or employee data was compromised. Play ransomware group later claimed responsibility for the incident, but the company has not confirmed the group’s allegations or whether any data was exfiltrated. Recovery efforts remain ongoing as investigators assess the full scope of the attack.
13. The City of Acworth, Georgia, is continuing to investigate a cybersecurity incident detected on June 8 that affected certain municipal computer systems.City officials worked with external cybersecurity specialists and law enforcement to restore impacted systems, which are now fully operational, while the investigation remains ongoing. Although the city has not confirmed the nature of the attack or whether any data was compromised, INC later claimed responsibility and alleged it had stolen municipal data.
14. Texas Hearing Institute, a pediatric hearing center in Houston, has begun notifying at least 29,498 individuals that a March 2026 cyberattack exposed sensitive personal and health information. The compromised data includes names, Social Security numbers, financial information, and medical records. Although the institute has not publicly identified the nature of the attack, Interlock ransomware group claimed responsibility, alleging it stole 540 GB of data.
15. Family Health Centers of Southern Indiana notified 7,117 individuals following a January 2026 cyberattack that allowed an unauthorized third party to access portions of its network containing patient data. The compromised information includes names, dates of birth, contact information, Social Security numbers, medical records, and health insurance information. Termine ransomware group claimed responsibility for the attack, alleging it exfiltrated approximately 250 GB of data and posted samples of the stolen information on its leak site.
16. The City of Oak Park, Michigan, started an investigation into a cybersecurity incident after INC claimed responsibility and listed the city on its data leak site. The threat group alleges that it exfiltrated municipal data and has threatened to publish the information if its demands are not met. City officials have not confirmed the group’s claims, and it remains unclear whether any resident or municipal data was compromised.
17. Following claims by INC that it breached Carvalima Transportes, the Brazilian logistics company is assessing the potential impact of the incident. While the ransomware group alleges it stole company data and threatened to publish it, Carvalima has not publicly confirmed the attack or verified the claims. The full scope of the incident, including whether any customer or operational data was compromised, remains unknown.
18. The City of Jacksonville, Texas, started an investigation into a cybersecurity incident after detecting suspicious network activity on July 3 that prompted officials to take affected systems offline. The incident disrupted some online city services while third-party cybersecurity specialists worked to determine the nature and scope of the attack and restore operations. City officials have not said whether any personal information was accessed or whether ransomware was involved, and the investigation remains ongoing.
19. North Los Angeles County Regional Center has begun notifying individuals affected by a November 2024 ransomware attack that resulted in the theft of highly sensitive personal and health information. The compromised data includes Social Security numbers, government-issued identification, financial information, medical records, health insurance details, and other protected health information. Medusa ransomware group claimed responsibility for the attack, alleging it stole more than 600 GB of data before encrypting systems. The organization said it implemented additional security measures following the incident and completed an extensive review of the affected data before issuing notification letters.
20. Following a March 2026 cybersecurity incident, Midland Care Connection began notifying patients and other affected individuals whose personal and health information may have been accessed by an unauthorized third party. The compromised data varies by individual but may include names, dates of birth, medical and health insurance information, financial account details, and, in some cases, Social Security numbers. The total number of affected individuals has not yet been disclosed.
21. The Gentlemen ransomware group claimed responsibility for a cyberattack targeting Oman-based Arabia Falcon Insurance, alleging it had stolen company data. In response, Arabia Falcon Insurance said it detected and contained an unauthorized attempt to access its corporate network on June 25, 2026, and found no evidence that customer or company data had been compromised or exfiltrated. The insurer stated that the affected accounts were isolated before attackers could gain access and that its systems and business operations remained unaffected despite the claims circulating on social media.
22. Park Dental Research Corporation, an Oklahoma-based dental implant company, disclosed that an unauthorized third party accessed its systems around April 29, 2026, exposing sensitive personal information, including names, dates of birth, addresses, Social Security numbers, driver’s license numbers, bank account information, passport details, and I-9 forms. Although the company said there is no evidence the compromised information has been misused, it notified affected individuals on June 24, 2026, and is providing complimentary credit monitoring, identity theft protection, and a $1 million identity theft insurance policy. Separately, Interlock ransomware group claimed responsibility for the attack, alleging it exfiltrated 260 GB of data from the company’s network.
23. The Gentlemen ransomware group has claimed responsibility for a cyberattack targeting Mercado Libre, adding the Latin American e-commerce giant to its dark web leak site. The threat actor has not disclosed what data was allegedly stolen or how it gained access to the company’s systems. Mercado Libre’s marketplace, Mercado Pago, and other services remained fully operational, with no visible signs of disruption, and the company has not publicly confirmed that a breach occurred.
24. Latvia’s state-owned forestry company, Latvijas Valsts Meži (LVM), is continuing to restore its IT systems weeks after a ransomware attack disrupted internal operations and customer services. The incident, first disclosed in late June 2026, affected the company’s mapping platform, hunting application, and systems used to communicate with contractors and customers. Latvian authorities said the attackers had been inside LVM’s network for more than a week before being detected, exploiting a vulnerability in software that had not been updated for two years. Although LVM refused to pay a ransom, the attackers leaked approximately 44 GB of stolen data, including internal documents, source code, cryptographic keys, digital certificates, and user credentials.
25. Japanese telecommunications giant KDDI disclosed that a cyberattack on a shared email platform exposed the email addresses of approximately 12.2 million users and the passwords of 7.6 million accounts across six internet service providers. The attackers exploited a vulnerability in third-party software used by the platform, with some passwords reportedly stored without hashing or encryption. KDDI said it detected the unauthorized access on June 17, 2026, coordinated response efforts with the affected ISPs, and urged impacted customers to reset their passwords while the investigation into the incident continues.
26. McLeod Physician Associates, a South Carolina-based healthcare group practice, disclosed a data breach stemming from unauthorized access to a legacy server between October 17 and 18, 2025. The incident, which affected up to 19,553 patients, exposed sensitive information including names, dates of birth, Social Security numbers, health insurance details, and medical records such as diagnoses, medications, test results, and treatment information. The organization said the breach was limited to a single decommissioned server and did not impact McLeod Health’s current electronic medical record system.
27. ERMI LLC, a Georgia-based manufacturer of orthopedic medical equipment, disclosed a data breach affecting 74,074 individuals after determining that an unauthorized third party had access to its systems between February 15 and August 14, 2025. The exposed information varied by individual but included names combined with sensitive personal, financial, and medical data, such as Social Security numbers, driver’s license and passport numbers, financial account and payment card information, login credentials, health insurance details, and medical records. Following a detailed review completed in April 2026, ERMI notified affected individuals and is offering complimentary credit monitoring to those whose Social Security numbers were compromised.
28. Up to 8,000 current and former patients and employees of Centers for Dialysis Care were affected by a data breach after an unauthorized party gained access to the Ohio-based provider’s network. The organization discovered suspicious activity on March 20, 2026, and later confirmed that files containing sensitive personal and protected health information had been accessed. The compromised data may have included names, dates of birth, Social Security numbers, medical and treatment information, health insurance details, and tax or financial information. Centers for Dialysis Care said it has since implemented additional security measures to strengthen its network and reduce the risk of similar incidents.
29. Australian food manufacturer Royal Foods has confirmed it is investigating a cyber incident after The Gentlemen ransomware group claimed responsibility and alleged it had stolen company data. The company said it activated its incident response plan immediately upon discovering the issue, isolated the affected environment, and engaged external cybersecurity specialists to investigate. Royal Foods has also notified the Australian Cyber Security Centre and stated that while it is aware of the ransomware group’s claims, it has not yet confirmed whether any personal or confidential information was compromised.
30. Aitkin County Health and Human Services in Minnesota disclosed a data breach affecting 83,114 individuals after unauthorized access to three employee email accounts led to the download of sensitive information from one account. The incident occurred between April 7 and 8, 2026, after attackers compromised the email environment and used one account to send phishing emails. The exposed data included names, addresses, dates of birth, Social Security numbers, medical and health information, health insurance details, case identifiers, and information related to services provided by Aitkin County HHS. In response, the organization reset affected passwords, provided additional phishing awareness training to employees, updated its email retention policy, and is implementing enhanced cybersecurity measures to strengthen its defenses.
31. LockBit ransomware group claimed responsibility for a cyberattack on Decatur Diagnostic Laboratory, alleging it exfiltrated data from the Alabama-based clinical laboratory and adding the organization on its dark web leak site. Although the laboratory did not attribute the incident to ransomware, it confirmed that attackers stole sensitive information, including names combined with dates of birth, Social Security numbers, driver’s license numbers, medical record numbers, and patient codes. The organization has reported the breach to the U.S. Department of Health and Human Services using a placeholder estimate of at least 500 affected individuals and has advised those impacted to remain vigilant against identity theft and fraud.
32. Akira ransomware group claimed responsibility for a cyberattack on Todd, Hamaker & Johnson, a Texas-based accounting firm, alleging it exfiltrated approximately 40 GB of client and employee data. The attack was detected on June 30, 2026, with the stolen data reportedly including sensitive information that the group threatened to publish on its leak site. Todd, Hamaker & Johnson has confirmed it is investigating the incident but has not disclosed the nature or extent of any data that may have been compromised.
33. DeadLock ransomware group claimed responsibility for a ransomware attack targeting Eko-Flor Plus, Croatia’s largest private waste collection company, alleging it had stolen company data and listing the organization on its leak site. The incident would mark the second ransomware claim against the company in four months. However, Eko-Flor Plus denied that a new security incident had occurred, stating that it had not experienced a ransomware attack, that no customer data had been compromised or stolen, and that the group’s claims were false.
34. German textile manufacturer ZEGO Textilveredelungszentrum has filed for insolvency after a cyber incident on March 29, 2026, forced its production systems offline for nearly six weeks, causing financial losses the company said it could not overcome. While ZEGO did not disclose the nature of the attack or confirm whether ransomware was involved, it attributed the prolonged operational disruption led directly to its decision to seek insolvency protection. The company said it intends to continue operating during the restructuring process in an effort to preserve jobs and maintain customer and supplier relationships.
35. After ransom negotiations reportedly broke down, Anubis ransomware group published data it claims was stolen from Northeast Pediatrics & Adolescent Medicine, a New York-based pediatric healthcare provider. Leaked chat logs suggest the organization initially engaged with the threat actors before communication ceased, prompting the group to release the data on its leak site. The leaked files reportedly contain sensitive patient and employee information, although Northeast Pediatrics has not publicly confirmed the extent of the breach or the authenticity of the published data.
36. Up to 75,532 individuals were affected by a data breach at the Gay & Lesbian Community Services Center of Orange County, a California-based provider of mental health, HIV testing, education, and outreach services. An investigation determined that an unauthorized party accessed the organization’s network between December 25 and 26, 2025, potentially exposing a wide range of sensitive personal and protected health information, including Social Security numbers, medical histories, diagnoses, prescription information, financial account details, payment card information, and government-issued identification numbers.Â
37. Alta Orthopaedics, a California-based orthopedic practice, disclosed a data breach after identifying unauthorized access to its network between February 3 and 6, 2026. The incident exposed sensitive personal and protected health information, including names, addresses, Social Security numbers, driver’s license details, medical record numbers, diagnoses, treatment information, billing records, and health insurance information. The practice detected the intrusion on March 10, 2026, notified law enforcement and regulators, and has begun mailing notification letters to affected patients.Â
38. More than a year after detecting unauthorized access to its network, Lake Region Healthcare has completed its investigation into a data breach that may have exposed sensitive patient information. The Minnesota-based nonprofit health system determined that files containing names, dates of birth, Social Security numbers, medical record and patient account numbers, health insurance information, contact details, medical and treatment information, government-issued identification, and financial information may have been accessed during the May 19, 2025, incident. Although the organization said there is no evidence the compromised information has been misused and electronic medical records were not affected, it is offering complimentary identity theft protection services to impacted individuals.
39. A threat actor known as 2019 has claimed to be selling the personal information of more than 200,000 Hot Toner Australia customers on a cybercrime forum. The allegedly stolen dataset is said to include customer names, email addresses, phone numbers, and purchase histories, with sample records reportedly shared to support the claims. Hot Toner Australia has not publicly confirmed a data breach, and the authenticity of the data remains unverified.
40. DragonForce ransomware group claimed responsibility for an attack on Australian equipment hire company Access Group International, alleging it exfiltrated approximately 42 GB of data from the company’s systems. The gang published sample files on its leak site that reportedly included invoices, customer credit checks, and customer hire records as proof of the breach. Access Group International has not publicly confirmed the ransomware attack or verified the authenticity of the allegedly stolen data.
41. AiLock ransomware group claimed responsibility for an attack on Japan’s largest taxi operator, Nihon Kotsu, after the company confirmed that unauthorized external access and a malware infection had disrupted its internal systems. The incident forced the temporary shutdown of taxi dispatch services, web booking and reservation systems, and parts of the company’s internal network, while the GO taxi app remained operational. Nihon Kotsu later acknowledged that potentially leaked had appeared online, although it continues to investigate the scope of the exposure and has not confirmed AiLock’s involvement or whether customer data was stolen.
42. Lifeline Australia has confirmed that an unauthorized party accessed information relating to some staff and volunteers after threat actor 2019 claimed to have stolen more than 10,000 records and shared the data on an underground hacking forum. The organization said its investigation found that some of the published information was authentic, although portions of the dataset had been altered with falsified data. Lifeline emphasized that no help-seeker information or financial data was compromised and said it has engaged external cybersecurity experts while continuing its investigation into the incident.
43. INC ransomware group has claimed responsibility for the incident affecting Greene County, Georgia, adding the county to its dark web leak site after officials disclosed a cybersecurity incident that forced the local government to take its entire network offline. While the county has not confirmed that ransomware was involved, it said the outage prompted the temporary shutdown of county servers as a precaution while external cybersecurity experts investigated. Officials also stated that there is currently no evidence that personal information or county data was accessed or stolen, and emergency services, including 911 and the Sheriff’s Office, remained fully operational throughout the incident.
44. The Gentlemen ransomware group has claimed responsibility for an attack on VASBE (Vigilantes Asociados al Servicio de Banca y Empresas), a Spanish private security and surveillance firm that primarily protects banks and financial institutions. The group added VASBE to its dark web leak site, alleging it had stolen company data, although it did not disclose the nature of the allegedly exfiltrated information or its ransom demands. VASBE had not publicly commented on the incident or confirmed whether any systems or data had been compromised.
45. WilmerHale is facing a proposed class action lawsuit following a data breach that allegedly exposed the personal information of thousands of clients, including names and Social Security numbers. The Washington, D.C.-based law firm notified affected individuals on July 10, 2026, after discovering the incident in early May, stating that an unauthorized third party obtained a limited set of information but did not directly access the firm’s internal systems. Although no ransomware group has publicly claimed responsibility, the reported circumstances resemble tactics associated with Silent Ransom Group. This has not been confirmed.
46. Community Health Center of Buffalo (CHCB), a New York-based healthcare provider, disclosed a data breach after confirming that an unauthorized party accessed its network between April 20 and 21, 2026. While the investigation is ongoing, the organization said the compromised files likely contain names along with sensitive personal and protected health information, including addresses, dates of birth, Social Security numbers, driver’s license details, medical records, diagnoses, treatment information, prescriptions, lab results, and health insurance information. CHCB has reported the incident to the U.S. Department of Health and Human Services using a preliminary estimate of at least 501 affected individuals and said it will offer complimentary credit monitoring and identity theft protection services to those impacted.
47. More than 12,800 individuals are being notified following a data breach at New Jersey law firm Greenbaum, Rowe, Smith & Davis LLP, which provides legal services to several healthcare organizations in the state. The incident involved unauthorized access to systems containing patient information from Atlantic Health System, Hackensack Meridian Health, and Trinitas Regional Medical Center. The exposed data included names, Social Security numbers, medical information, health insurance details, and other personal information. The firm said it is not aware of any public disclosure of the compromised data.
48. World Leaks ransomware group claimed responsibility for a breach involving files linked to India’s Kudankulam Nuclear Power Plant, alleging it had stolen and published thousands of documents from contractor Reliance Infrastructure. Reliance confirmed a partial data breach involving a server hosted by the third-party data center provider Yotta but said the incident was limited to that environment and reported it to the Indian government. The allegedly leaked files include engineering drawings, supplier information, inspection records, and project documents, although their authenticity has not been independently verified. Indian authorities, including CERT-In, are investigating the incident, while the Nuclear Power Corporation of India (NPCIL) has stated that no nuclear safety or security systems were affected.
49. Israeli fintech company Nayax has refused to pay an extortion demand following a cyber incident claimed by The Syndicate ransomware group, which alleged it had stolen more than 100 TB of data, including more than one billion payment card records. After completing its investigation, Nayax confirmed that data had been exfiltrated from a cloud account belonging to one of its subsidiaries, but said the stolen information was limited to backups of scanned documents, business-related files, and payment transaction records that did not contain sensitive payment authentication data such as cardholder names or CVV codes. The company added that its production environment and core systems were not compromised, customer funds were unaffected, and business operations continue as normal.
50. Partnered Health, one of Australia’s largest primary healthcare providers, has confirmed that a malicious actor accessed patient data across multiple clinics in its national network, compromising personal and health information, including names, contact details, Medicare and private health insurance information, consultation notes, pathology results, referral letters, and treatment records. The healthcare provider said it became aware of the incident on June 23, 2026, and has since engaged external cybersecurity experts, notified regulators, and obtained a court injunction to prevent the publication or misuse of the stolen data. Separately, INC ransomware group has claimed responsibility for the breach, alleging it exfiltrated approximately 500 GB of data and listing Partnered Health on its leak site. However, the organization said its investigation is ongoing and has not confirmed the group’s claims regarding the volume of data stolen.
51. German banking giant Deutsche Bank confirmed it is investigating a cybersecurity incident involving a third-party service provider after the Unsafe ransomware group claimed responsibility and published what it said were employee database records on its leak site. The bank said the incident was limited to a German vendor that operates a marketing and incentive platform for sales partners, stressing that there is no evidence its internal systems or networks were compromised. The leaked samples reportedly include employee email addresses, password hashes, physical addresses, and internal database records, although there is no indication that customer data was affected.
52. Anubis ransomware group claimed responsibility for an attack on Coca-Cola’s dairy subsidiary, Fairlife, alleging it encrypted the company’s systems and stole approximately 1 TB of confidential data. Coca-Cola confirmed that the ransomware incident disrupted Fairlife’s production-related systems, forcing a temporary suspension of U.S. dairy production while recovery efforts were underway. The company has since acknowledged that data was exfiltrated during the attack but said it is continuing to assess the scope of the breach, restore affected systems, and investigate what information was compromised. Canadian operations and product safety were not affected.
53. Abbott confirmed that an unauthorized party gained access to a limited number of internal systems within its Cancer Diagnostics business after the ShinyHunters extortion group claimed responsibility for the incident. The healthcare giant said the attack was confined to legacy Exact Sciences systems and did not affect manufacturing, laboratory operations, product availability, patient services, or any other Abbott business units. While ShinyHunters has alleged it stole internal documents, contracts, customer information, and large volumes of personally identifiable information, Abbott has not confirmed the group’s claims or disclosed what data, if any, was accessed. The company has engaged third-party cybersecurity experts and law enforcement as its investigation continues.
54. Ohio Living, a nonprofit senior living provider based in Ohio, disclosed a data breach after confirming that an unauthorized party accessed its network and exfiltrated files containing patient information between April 16 and 17, 2026. Although the review of the compromised data is ongoing, the organization said the exposed information may include names, addresses, dates of birth, Social Security numbers, medical histories, diagnoses, treatment and prescription information, physician details, health insurance information, and financial account information or payment card information. Ohio Living has reported the incident to the U.S. Department of Health and Human Services using a preliminary estimate of at least 500 affected individuals and said it is strengthening its cybersecurity safeguards while the investigation continues.
55. An investigation into a security incident at Heart of America Eye Care found that an unauthorized party viewed or copied patient information from the provider’s systems between April 1 and 6, 2026. The Kansas and Missouri-based ophthalmology and optometry practice is still reviewing the affected files to determine the types of protected health information involved and the total number of impacted individuals. The incident has been reported to the U.S. Department of Health and Human Services using a preliminary estimate of at least 500 affected individuals, with that figure expected to increase once the review is complete.
56. A cyber incident at Japanese frozen food giant Nichirei triggered widespread supply chain disruption, affecting major customers including KFC Japan, Aeon supermarkets, and Kura Sushi. The company said unauthorized access to its systems caused failures in its cold storage and logistics operations, disrupting frozen food shipments to roughly 5,000 business partners nationwide. Although Nichirei has not confirmed the nature of the attack, the RansomHouse extortion group has since claimed responsibility, alleging it stole company data. The company continues to investigate the incident and has not confirmed whether any information was exfiltrated.
57. Frontier Airlines is facing two proposed class action lawsuits after separate cyber intrusions allegedly exposed the personal information of employees and customers. The complaints claim the airline failed to implement adequate cybersecurity measures and delayed notifying affected individuals following attacks in May and June 2026, which have been attributed to the Scattered Lapsus$ Hunters extortion group. Frontier said it launched its incident response procedures, engaged a third-party cybersecurity firm, and notified law enforcement after discovering unauthorized access to a data storage account containing personal information.
58. French food giant Danone, the company behind brands including Evian, Silk, and International Delight, has been added to Qilin’s leak site. The threat actors claim to have stolen approximately 221 GB of internal data, including financial records, customer-related documents, contracts, and other corporate files, and have threatened to publish the information if negotiations do not take place. Danone has not publicly confirmed the ransomware claim or whether any of the allegedly stolen data is authentic, leaving the extent of any potential compromise unclear.
59. South African travel management company BE Travel confirmed it was hit by a ransomware attack after the Arcus Media ransomware group claimed responsibility for the incident. The company, which provides travel services to the government’s Housing Development Agency, said attackers may have accessed, acquired, exposed, or encrypted personal information stored in its travel voucher and administration management system. BE Travel has notified affected individuals in accordance with South Africa’s POPIA requirements and is continuing its investigation into the scope of the compromise.
60. Eurohold Bulgaria and its insurance subsidiary Euroins said they successfully thwarted a sophisticated cyberattack aimed at disrupting operations, stealing sensitive data, and extorting the company. The incident temporarily affected access to Euroins’ website and online services, but Eurohold said its cybersecurity team, working alongside Bulgarian authorities, contained the attack before it caused significant operational damage. Separately, Krybit ransomware group claimed responsibility for the incident and listed both Eurohold and Euroins on its leak site, alleging it had stolen company data. However, the companies said they would not give in to extortion demands and have not confirmed that any data was compromised.
61. Healthcare technology firm Craneware revealed that a cyber incident resulted in the theft of employee data and a subset of customer and partner records after attackers gained unauthorized access to part of its data environment. The Scotland-based company, which provides software to thousands of hospitals, clinics, and pharmacies across the United States, said the incident has been contained and has not disrupted customer services or business operations. While investigators found that a significant volume of file names had been viewed and copied, Craneware said much of the affected information was non-sensitive or publicly available regulatory data. The company has notified the UK’s Information Commissioner’s Office and the FBI as its forensic investigation continues.
62. The Gentlemen ransomware group claimed responsibility for an attack on Colombian energy giant Ecopetrol after the company disclosed that unauthorized access to its cloud-based file storage resulted in the theft of data associated with approximately 3,300 user accounts. While the attackers failed to deploy ransomware after Ecopetrol’s security controls blocked the encryption attempt, the group later alleged it had exfiltrated up to 1 TB of corporate data from the company and its subsidiaries. Ecopetrol said the stolen files contained pseudonymized data rather than user identities or login credentials, and that the incident did not disrupt production or other critical operations.
63. SafePay ransomware group claimed responsibility for an attack on AC Small Maxwell & Co, a century-old accounting and advisory firm based in Grafton, New South Wales. The threat actors added the firm to their dark web leak site and threatened to publish allegedly stolen data, although they did not provide samples to substantiate the claim. AC Small Maxwell & Co has not publicly acknowledged the incident or confirmed whether any client or corporate information was compromised.
64. Hong Kong-listed financial services firm Get Nice Holdings confirmed that a cyberattack disrupted the electronic trading systems of its securities and futures subsidiaries, temporarily affecting online trading and stock withdrawal services. The company said the incident, which occurred on July 19, prompted the immediate isolation of affected systems, while clients were still able to place orders through its dealing hotline. Get Nice has since restored its securities trading platform, engaged external cybersecurity specialists to investigate, and said there is currently no evidence that customer information has been misused. The company has also notified the Hong Kong Stock Exchange, the Securities and Futures Commission, and local police.
65. TriWest Healthcare Alliance, a U.S. Department of Veterans Affairs contractor, disclosed a data breach affecting 11,848 individuals after an unauthorized third party gained limited access to portions of its network and downloaded files containing protected health information. The incident, which was detected on April 16, 2026, exposed information including names, Department of Defense Benefits Numbers, beneficiaries’ ZIP codes, and health-related data. For five individuals, additional information was compromised, including addresses, dates of birth, and Social Security numbers.
66. Texas Medicaid and Healthcare Partnership (TMHP), a contractor that administers Texas Medicaid services, disclosed a fraud-related data breach affecting 2,045 individuals after unauthorized access to internal systems between February 5 and March 26, 2026. The incident exposed sensitive information belonging to 1,828 Medicaid clients and 217 healthcare providers, including names, addresses, dates of birth, Social Security numbers, Medicaid information, health records, financial information, tax identification numbers, and medical license details. TMHP said it contained the intrusion after detecting the unauthorized activity, enhanced its security measures, and notified affected individuals on June 18, 2026. While there is no evidence the compromised information has been misused, the organization is offering complimentary identity theft protection and identity recovery services.
67. Minnesota Health Insurance Network, a health insurance brokerage based in Burnsville, disclosed a data breach after attackers gained unauthorized access to parts of its network between March 16 and 17, 2026, and exfiltrated sensitive files. The compromised information included names, dates of birth, Social Security numbers, driver’s license and other government-issued ID numbers, financial account and payment card information, as well as health insurance, diagnosis, and treatment information. The brokerage has notified regulators and begun informing affected individuals, although the total number of impacted people has not yet been disclosed.
68. A cybersecurity incident forced Tennessee’s Sumner County Schools to delay the start of the 2026-27 school year, affecting approximately 31,000 students across 53 schools. After detecting unauthorized access to its network on July 20, the district postponed the first day of classes from August 4 to August 10 while registration events were also rescheduled. Sumner County Schools has engaged third-party forensic specialists and notified federal, state, and local authorities, including the FBI, as it investigates the incident. Officials have not disclosed whether any data was compromised, and no threat actor has claimed responsibility.
69. A cyberattack left University City, Missouri, without several key online services for more than a month, disrupting bill payments, building permits, public records requests, and other municipal functions. City officials initially attributed the outage to server issues before confirming that the network had been targeted with malicious activity and that affected systems were being rebuilt in phases. While staff reverted to manual processes to maintain essential services, the city said there is no evidence that residents’ personal information was accessed or stolen, and public safety operations continued without interruption.
70. More than a year after unauthorized access to its network was detected, Madera Community Hospital has begun notifying patients about a data breach that may have exposed sensitive personal and health information. The California hospital said an unauthorized party accessed its network between May 28 and 29, 2025, and while investigators found no definitive evidence that data was removed, subsequent findings led the organization to believe files from part of its network were acquired. The potentially compromised information includes names, dates of birth, contact information, login credentials, Social Security numbers, and other government-issued identification, financial account information, and limited medical and biometric data. Madera Community Hospital is offering complimentary credit monitoring and identity theft protection services, although the total number of affected individuals has not yet been disclosed.
71. Australian collectibles retailer Downies Collectables is investigating a cybersecurity incident after Settra ransomware group claimed it had stolen more than 500 GB of company data and listed the business on its leak site. Downies confirmed it detected suspicious activity within its IT network on July 6, 2026, and determined that a malicious actor had accessed and removed data without authorization. The company has engaged forensic specialists, notified the Australian Signals Directorate, the Australian Federal Police, the Victoria Police, and the Office of the Australian Information Commissioner, and is working to identify affected individuals while investigating the ransomware group’s claims.
72. Melbourne-based property management firm LR Reed is investigating a suspected security incident after Kairos ransomware group claimed it had stolen 335 GB of company data and listed the business on its leak site. As proof of its claims, the group published sample files that reportedly included employee records, client documents, financial information, and internal business records. In response, LR Reed said it has found no evidence that customer information was compromised and confirmed that its core systems remain secure and fully operational. The company added that it is continuing to work with cybersecurity specialists to investigate the ransomware group’s claims and determine whether any data was accessed.
73. Unlimited Technology Systems (UTS), an Ohio-based revenue cycle management and practice management software provider, disclosed a data breach after determining that an unauthorized third party may have copied files from a commercial data center between October 5 and 10, 2025. The compromised information may have included names, addresses, email addresses, phone numbers, dates of birth, health insurance information, patient balance information, Social Security numbers, diagnoses, and scanned government-issued identification documents. UTS emphasized that full medical records, medical images, and financial information were not affected. The total number of affected individuals has not yet been disclosed.
74. Little Flower Children and Family Services, a New York-based provider of services for individuals with developmental disabilities and their families, is notifying affected individuals following a network intrusion that occurred between March 12 and 20, 2026. Although its review of the compromised files is still ongoing, the organization said the exposed information may include names, contact details, dates of birth, Social Security numbers, government-issued identification, financial account and payment card information, biometric data, Medicare and Medicaid numbers, health insurance information, diagnoses, treatment and prescription information, and treatment cost details.
75. DentaQuest, one of the largest dental benefits administrators in the United States, has begun notifying more than 15 million individuals affected by a large-scale cybersecurity incident that exposed personal and protected health information. The company said attackers gained unauthorized access to a limited portion of its network in May 2026, and the compromised data may include names, addresses, dates of birth, Social Security numbers, Medicare and Medicaid identifiers, health insurance information, and dental or vision treatment details. Separately, ShinyHunters extortion group claimed responsibility for the attack and leaked approximately 234 GB of stolen data after ransom negotiations reportedly failed.
76. Swiss rail manufacturer Stadler Rail refused to pay a CHF 10 million ($12.3 million) ransom after Everest ransomware group breached a data exchange platform shared with one of its suppliers using compromised credentials. The attackers stole technical information belonging to the supplier, but Stadler said its internal IT systems, production facilities, and rail operations were not affected, and no personal or safety-critical data was compromised. The company has filed a criminal complaint with Swiss authorities and stated it will not negotiate with the extortionists despite the threat to publish the stolen files.
77. Carlyle Senior Care Management Company, a South Carolina-based operator of independent living, assisted living, and skilled nursing facilities, has reported a data breach affecting 4,060 individuals to the U.S. Department of Health and Human Services. While the organization has not publicly disclosed details of the incident or the types of information involved, Insomnia ransomware group claimed responsibility, alleging it stole patient records, internal documents, and other sensitive data before publishing the files on its leak site after the company reportedly failed to respond to its demands. Carlyle Senior Care has not confirmed the ransomware group’s claims.
78. More than 169,000 current and former patients of Anatomic and Clinical Laboratory Associates (ACLA) were affected by a data breach after an unauthorized party gained access to the Tennessee-based pathology group’s network. The investigation, launched after suspicious activity was detected on December 1, 2025, found that sensitive personal and protected health information had been exposed, including names, dates of birth, Social Security numbers, taxpayer identification numbers, medical record and patient account numbers, medical histories, diagnoses, treatment information, and provider names. ACLA completed its review of the compromised data in April 2026 and began notifying affected individuals in June, offering complimentary credit monitoring and identity theft protection services to those whose information was most at risk.
79. Lifeways Inc., a nonprofit provider of mental health and addiction treatment services in Idaho and Oregon, disclosed a data breach after multiple employee email accounts were compromised following unauthorized access to one account in January 2026. The incident was confined to the organization’s email environment but exposed a broad range of sensitive personal and protected health information, including names, dates of birth, Social Security numbers, driver’s license details, financial account information, medical record numbers, diagnoses, treatment and prescription information, Medicare and Medicaid numbers, and health insurance data. Lifeways said it has no evidence that the compromised information has been misused, and filings with the Oregon Attorney General indicate that at least 343 individuals were affected.
80. Brinks Home, one of North America’s largest residential security providers, disclosed a cybersecurity incident after detecting unauthorized access to a portion of its IT systems on July 20, 2026. The company said the attackers have threatened to publicly release stolen information, although it is still determining what data was accessed and who may have been affected. Separately, ShinyHunters extortion group claimed responsibility, alleging it stole 4.9 million Salesforce records, including customer contact information, employee personal data, and millions of customer support chat logs through a Microsoft Entra vishing attack. Brinks Home emphasized that its alarm monitoring services and core security products were not affected and that it is working with external forensic experts while continuing its investigation.
81. Telehealth software provider ZenPatient has begun notifying patients after a cybersecurity incident allowed an unauthorized party to access its network for more than two months and exfiltrate sensitive files. The intrusion occurred between December 5, 2025, and February 12, 2026, with the California-based company discovering the suspicious activity on February 27. The compromised information included names, addresses, dates of birth, and medical information. The company has notified regulators, although the total number of impacted individuals has not yet been disclosed.
82. Dutch speed skating venue Thialf confirmed it was targeted in a ransomware attack after The Gentlemen claimed responsibility and threatened to publish allegedly stolen data unless a ransom was paid. The group said it had obtained internal documents, employee information, financial contracts, and other sensitive files. However, following a forensic investigation involving internal and external cybersecurity experts, Thialf said the incident had minimal impact, with no evidence that its data or operational processes were compromised. The arena, which is set to host long-track speed skating events during the 2030 Winter Olympics, added that scheduled events would continue as planned.
83. Australian energy provider Origin Energy confirmed that customer information was compromised in a data breach after initially investigating claims made by a threat actor earlier in July. The company said the incident exposed personal information belonging to current and former customers, including names, addresses, dates of birth, phone numbers, account details, and partial bank account or credit card numbers that cannot be used to conduct transactions. Origin is continuing to notify affected customers, provide identity and cybersecurity support services, and work with Australian authorities as its investigation continues. Subsequent updates confirmed that approximately 900,000 customers were affected, significantly fewer than early estimates.
84. Payload ransomware group claimed responsibility for an attack on CKR Consulting Engineers, a South African engineering firm involved in major infrastructure projects including Sun City, Montecasino, Eskom facilities, and data centers for the Johannesburg Stock Exchange and Liquid Telecommunications. The group alleged it exfiltrated 55 GB of internal company data and listed CKR on its leak site, although it did not disclose the contents of the allegedly stolen files. CKR has not publicly confirmed the incident or responded to the ransomware claims.
85. Portuguese public transport operator Metro Mondego confirmed it was the victim of a ransomware attack after The Gentlemen claimed responsibility and threatened to publish stolen company data. While the attack did not disrupt Metrobus operations or compromise payment card information, the company said it is now likely that attackers copied personal data belonging to holders of personalized travel passes, including names, dates of birth, contact details, photographs, tax and identification numbers, and travel pass usage data. Metro Mondego has notified affected individuals, engaged external cybersecurity experts, and alerted Portugal’s National Cybersecurity Center and other authorities as its investigation continues.
86. South Carolina-based health system AnMed was hit by a ransomware attack that forced the temporary closure of dozens of outpatient clinics, imaging centers, oncology services, and other care facilities across South Carolina and Georgia. The attackers reportedly gave the organization 72 hours to respond to their extortion demands after deploying malware that disrupted IT systems, internet connectivity, phones, and clinical operations, although emergency departments remained open. AnMed has engaged external cybersecurity experts, notified law enforcement, and is continuing to restore affected systems while investigating whether any patient or employee data was accessed or stolen. No ransomware group has publicly claimed responsibility for the incident.
87. More than a year after detecting unauthorized access to its network, Whitfield Regional Hospital in Alabama has begun notifying patients about a data breach involving sensitive personal and health information. The hospital determined that an unauthorized party had access to parts of its network between May 15 and June 8, 2025, exposing information including names, dates of birth, Social Security numbers, driver’s license numbers, medical information, financial account details, and health insurance information. Tombigbee Healthcare Authority, which operates the hospital, completed its review of the compromised data in June 2026 and has begun mailing notification letters while offering complimentary credit monitoring and identity theft protection services. The total number of affected individuals has not yet been disclosed.
88. Michigan Surgical Center has confirmed a cybersecurity incident affecting some of its patients, although the organization has not yet disclosed how many individuals were impacted or what types of information were exposed. The affected individuals have been offered 12 months of complimentary credit monitoring, credit reports, and credit score services. The Gentlemen ransomware group claimed responsibility for the incident after adding the East Lansing-based facility to its dark web leak site in early June, alleging it had stolen data from the healthcare provider. However, Michigan Surgical Center has not publicly confirmed the group’s claims or whether ransomware was involved.
89. Penobscot Valley Hospital, a critical access hospital in Lincoln, Maine, is notifying patients after a cybersecurity incident resulted in the potential exposure of sensitive personal and medical information. The hospital determined that an unauthorized party accessed its network before the intrusion was discovered in February 2026, with the affected data including names, addresses, dates of birth, Social Security numbers, financial information, and medical records. The total number of affected individuals has not yet been disclosed.
90. An investigation into a June 2025 cybersecurity incident at Wildwood Surgical Center found that an unauthorized party accessed the Ohio-based provider’s network for two days and removed files containing sensitive patient information. The compromised data included names, dates of birth, Social Security numbers, driver’s license and passport numbers, diagnostic and treatment information, medical billing details, payment card and bank account information, and health insurance information. The organization has since enhanced its cybersecurity safeguards and begun notifying affected individuals but has not yet disclosed how many people were impacted.
91. A cyberattack on healthcare management and revenue cycle management company MCBS has exposed the personal and protected health information of 1,261,464 individuals, making it one of the largest healthcare data breaches disclosed this year. Attackers gained unauthorized access to the company’s network between September 22 and 26, 2025, compromising data that included names, addresses, dates of birth, Social Security numbers, health insurance information, medical records, and financial information belonging to patients of multiple healthcare providers. PEAR ransomware group claimed responsibility for the breach, alleging it stole more than 3 TB of data, including patient records, financial documents, emails, and internal business files.
92. South Korean EV charging platform Chaevi disclosed a data breach affecting 298,333 users after a hacking attack exposed member account information. The compromised data included 164,858 email addresses, 131,411 email address and encrypted password combinations, and a smaller number of records containing encrypted names, contact details, gender, and dates of birth, with some also including encrypted passwords. Chaevi said it immediately blocked the attack path, notified the Personal Information Protection Commission and the Korea Internet & Security Agency (KISA), and is urging affected users to change their passwords. The company emphasized that it does not collect resident registration numbers, passport details, or financial information, and therefore those data types were not affected.
93. Australian gold miner West African Resources is investigating alleged breach claims after DeadLock ransomware group added the company to its dark web leak site. The threat actors claimed to have compromised the miner’s network and threatened to publish stolen data unless negotiations began, with reports indicating the allegedly exfiltrated information includes accounting and financial documents linked to the company’s mining operations in Burkina Faso. West African Resources has not publicly confirmed the incident or the authenticity of the ransomware group’s claims.
94. The Gentlemen ransomware group has claimed responsibility for an alleged attack on HBS Group, a Melbourne-based engineering firm specializing in heritage restoration and conservation projects across Australia. The group added HBS Group to its dark web leak site but provided little evidence to support its claims beyond publicly available company information and a countdown timer threatening the release of allegedly stolen data. HBS Group has not publicly acknowledged the incident or confirmed whether its systems or data had been compromised.
95. INC ransomware group has claimed responsibility for an alleged attack on Cabin Creek Health Systems, a West Virginia-based Federally Qualified Health Center that provides primary care, dental, and behavioral health services across Kanawha County. The group added the nonprofit healthcare provider to its dark web leak site on July 23, although it did not disclose how many patient records were allegedly compromised or provide details on the extent of the breach. Cabin Creek Health Systems has not publicly confirmed the incident or notified regulators or affected individuals, leaving the scope of any potential data exposure unclear.
96. Nearly 10,000 individuals were affected by a data breach at Averhealth Holdings, the parent company of drug testing provider Avertest, after an unauthorized party gained access to parts of its network between December 19, 2025, and January 21, 2026. The compromised information varied by individual but included names alongside clinical and diagnostic information, medical histories, treatment details, health insurance information, medical record numbers, dates of birth, driver’s license numbers, digital signatures, patient account numbers, and, in some cases, Social Security numbers. Averhealth said it is unaware of any misuse of the exposed information but has offered complimentary credit monitoring to individuals whose Social Security numbers were affected and has reported the incident to the U.S. Department of Health and Human Services.
97. PayoutsKing threat group claimed responsibility for a cyberattack on Eyemart Express, alleging it stole 435 GB of customer and employee data before leaking the files when its ransom demands were not met. The nationwide optical and optometry provider later confirmed that an unauthorized party accessed its network on February 12, 2026, exposing personal and protected health information including names, addresses, dates of birth, Social Security numbers, prescription information, insurance details, and eyeglass purchase records. The breach potentially affected up to 25,000 individuals, with complimentary credit monitoring and identity theft protection offered to those whose Social Security numbers were compromised.
98. India’s Bank of Baroda confirmed a cybersecurity incident after customer data and internal documents surfaced on the dark web, revealing that a compromised employee email account had allowed unauthorized access to certain information. While the bank said its core banking systems were not affected and remain secure, it has launched a forensic investigation to determine the full scope of the breach. TripleX extortion group claimed responsibility, alleging it leaked up to 1 TB of data containing customer KYC records, loan documents, internal audit reports, and other sensitive files, although the bank has not verified the extent of the alleged data exposure.
99. Australian mining equipment manufacturer AusProof has been targeted by M3RX, which claims to have stolen 460 GB of data comprising more than 373,000 files. The threat actors added the Queensland-based company to their dark web leak site and published a file listing as proof of the alleged breach, threatening to release the data if negotiations were not initiated. AusProof, which designs and manufactures electrical cable couplers for the mining and tunneling industries, has not publicly acknowledged the incident or confirmed the authenticity of the ransomware group’s claims.
100. Romania’s National Agency for Cadastre and Land Registration (ANCPI) confirmed that a ransomware attack encrypted and deleted part of its virtualization infrastructure, disrupting land registry services and bringing property transactions across the country to a standstill. Authorities stressed that the central cadastral database containing property ownership records was not compromised, although digital services remained unavailable for weeks while systems were rebuilt and migrated to the Government Cloud. The government has not identified the attackers or disclosed whether a ransom demand was received, but the incident prompted emergency legislative action to extend reduced VAT eligibility for homebuyers affected by the disruption.
101. Angola’s largest telecommunications provider, Unitel, suffered a major cyberattack just hours before its long-awaited stock market debut, disrupting voice, mobile data, and internet services for more than 21 million subscribers nationwide. The company said it immediately activated its incident response procedures and deployed technical and cybersecurity teams to restore affected systems, although it did not disclose the nature of the attack or identify those responsible. Despite the widespread outage, Unitel’s IPO proceeded as planned, with no indication that the listing process or trading infrastructure was affected.
102. Cybersecurity researchers uncovered an active ransomware campaign targeting semiconductor company V-Silicon after attackers accidentally exposed their own staging server, allowing investigators to reconstruct the intrusion before it was publicly disclosed. The exposed infrastructure was linked to INC ransomware group, which later added V-Silicon to its dark web leak site and claimed responsibility for the attack. According to researchers, the leaked attacker tooling revealed evidence of network reconnaissance, credential theft, and malware designed to run across multiple architectures, suggesting the campaign may have been intended to target not only traditional IT systems but also embedded and industrial environments. V-Silicon has not publicly commented on the incident or confirmed the extent of any data compromise.
103. Romania’s National Administration of Penitentiaries (ANP) was hit by a ransomware attack that forced the agency to suspend several critical digital services, including its public website, online prison visit scheduling system, inmate telephone network, VPN connections between prisons, and internal IT platforms. The attack also prompted the temporary suspension of inmate transfers while cybersecurity specialists from the Romanian National Cyber Security Directorate (DNSC) worked alongside ANP staff to isolate affected systems and restore operations. Authorities have not identified the threat actor or disclosed whether any data was compromised, and a criminal investigation has been launched as efforts to determine the full scope of the incident continue.
104. ShinyHunters extortion group has claimed responsibility for the recent Ernst & Young (EY) data breach, alleging it gained access through a supply-chain attack that compromised a third-party IT service management platform used to support tax-related client work. EY previously confirmed that attackers accessed the platform between March 28 and April 12, 2026, downloading support tickets containing sensitive tax documents with client names, addresses, Social Security numbers, payment card details, and other financial information. ShinyHunters further claimed the stolen credentials allowed it to access EY’s internal Jira, GitHub, and Azure environments, although the firm has not verified those allegations.
105. A ransomware attack claimed by The Gentlemen targeted Soniva Dental Care, a Texas-based dental services provider operating 14 locations across the state. The company detected suspicious remote access activity on May 26, 2026, and quickly contained the intrusion by disabling remote desktop access, terminating external connections, and locking down its infrastructure. Although patient record systems were rapidly restored and archived data was unaffected, Soniva said it could not rule out unauthorized access to files containing names, addresses, dates of birth, driver’s license numbers, other government-issued identification numbers, and medical information. The incident may have affected up to 30,000 Texas residents.
106. New York-based Hudson Valley Medical Billing & Credentialing has begun notifying 5,459 patients after unauthorized access to systems containing protected health information was discovered in March 2026. Although the company was unable to determine whether any patient data was viewed or exfiltrated before the intrusion was contained, it is notifying potentially affected individuals out of an abundance of caution. Hudson Valley Medical Billing & Credentialing has since strengthened its technical safeguards and is offering complimentary credit monitoring and identity theft protection services to those impacted.
107. ExfilSquad extortion group has claimed responsibility for a cyberattack on the UK Department for Education (DfE) that resulted in the theft of approximately 607,000 records from the department’s help desk and Turing Scheme portals. The leaked data reportedly includes the names, job titles, email addresses, and phone numbers of teachers, school leaders, university staff, government officials, and parents who had interacted with the department. The DfE said the breach was limited to customer service contact information, with no evidence that core systems or more sensitive data were compromised, and is working with the National Cyber Security Centre, the National Crime Agency, and the Information Commissioner’s Office as the investigation continues.
108. Contact Group, a Tasmanian provider of building services and technology solutions, is investigating alleged breach claims after CMD Organization ransomware group listed the company on its dark web leak site. The threat actors claimed to have stolen company data and put it up for auction, publishing sample files that reportedly included scans of driver’s licenses containing names, addresses, signatures, license classes, and document numbers. Contact Group, which serves commercial, government, healthcare, and education clients, has not publicly confirmed the incident or the authenticity of the ransomware group’s claims.
109. Semiconductor manufacturer Analog Devices disclosed that attackers gained unauthorized access to its systems and exfiltrated company files in a cyberattack detected on June 23, 2026. The company said it immediately activated its incident response procedures, engaged external cybersecurity experts, and notified law enforcement, adding that the incident has not disrupted operations and is not expected to have a material impact on its business. ExfilSquad extortion group claimed responsibility, alleging it stole approximately 570,000 customer records containing personally identifiable information and addresses. Analog Devices has not verified those claims and said its investigation into the scope of the compromised data remains ongoing.
110. Court Services Victoria (CSV) has confirmed a data breach after hacker 2019 allegedly leaked nearly 30,000 lines of court-related information on an underground forum. The breach involved a system used to link participants to online hearings in the Magistrates’ Court of Victoria and the Children’s Court of Victoria, exposing information from matters heard between 2022 and 2026 across several regional court locations. While much of the compromised data was already publicly available, the exposed records also included email addresses and participant roles, such as lawyers, court staff, and observers. CSV said it has closed the access point used in the breach, strengthened security measures, and is continuing to investigate alongside relevant authorities.
111. Loyalist College has restored all systems and services following a ransomware attack discovered on July 9. The incident disrupted email, internet access, online classes, student registration, and tuition payment systems.The Ontario college confirmed that attackers gained unauthorized access to files containing personal information belonging to current and former students, employees, and other affiliated individuals, although the full scope of the compromised data remains under investigation. Loyalist has engaged third-party cybersecurity and forensic experts, notified the appropriate authorities, and continues to assess the impact while working to identify everyone affected.
Ransomware Report
Related Posts
The State of Ransomware: July 2026
Rebecca Harpur2026-08-04T13:57:55+01:00August 4th, 2026|
BlackFog's state of ransomware July 2026 measures publicly disclosed and non-disclosed attacks globally.
BlackFog Q2 2026 Ransomware Report: Undisclosed Ransomware Attacks Surge 40% Year on Year
Brenda Robb2026-07-29T11:09:53+01:00July 30th, 2026|
BlackFog Q2 2026 Ransomware Report: Undisclosed Ransomware Attacks Surge 40% Year on Year
2026 Q2 Ransomware Report
Rebecca Harpur2026-07-29T11:14:00+01:00July 30th, 2026|
BlackFog’s 2026 Q2 Ransomware Report - Beneath The Surface: Why Stable Attack Numbers Hide A Rapidly Escalating Data Theft Crisis
MedusaHVNC: A Hidden Desktop That Steals Live Windows Sessions
Darren Williams2026-07-28T13:51:33+01:00July 27th, 2026|
MedusaHVNC is a newly uncovered hidden desktop malware family that gives operators access to live, logged-in browser sessions on a victim’s Windows device.
American Alarm Moves From Reactive Security To Proactive Data Protection With BlackFog
Brenda Robb2026-07-23T13:34:42+01:00July 23rd, 2026|
Discover how American Alarm strengthened cybersecurity with BlackFog, preventing data exfiltration, improving AI governance, and reducing cyber risk.
What Are Recommended Best Practices For Implementing AI Assurance In Organizations?
Brenda Robb2026-07-28T13:44:02+01:00July 21st, 2026|
Discover best practices for implementing AI assurance to build secure, transparent and trustworthy AI usage across your organization.







