Skip to content
AI Protection

Breaches we’re tracking

What was exposed in each one, and what to do next.

All tracked breaches
No letter, but worried?

Enter your email and we’ll tell you which breaches include you.

Check my email
Scams in your state

The local patterns, the agencies to call, and printable posters.

Pick your state

Breaches

Data breaches we’re tracking

When a company discloses a breach that exposed personal information, we publish a page on what is known, what information was involved, and what affected people can consider doing.

Check my email

No letter, but worried? Enter your email and we’ll tell you which breaches include you.

Incident pages

  1. Disclosed September 14, 2026 CenterPoint Energy data breach People affected: Unconfirmed Form 8-K (September 14, 2026): unauthorized third party obtained personal information relating to a portion of customers; investigation of scope ongoing. Read about the breach
  2. Disclosed September 14, 2026 Accela data breach People affected: 8,629+ (CA) Government-software vendor breach; California AG sample filed September 14, 2026, with mailed notices the same day (8,629+ CA residents named). Read about the breach
  3. Disclosed August 28, 2026 (SEC); Sept. 8 consumer notice McKesson data breach People affected: Unconfirmed Unauthorized access to third-party applications with data exfiltration; substitute notice says personal information, including PHI, may have been impacted for people served through McKesson customers. Read about the breach
  4. Disclosed September 17–18, 2026 Call-on-Doc data breach People affected: Undisclosed Online healthcare provider; Notice of Data Breach / California AG sample around September 17–18, 2026, after unauthorized network access potentially involving PHI. Read about the breach
  5. Disclosed September 3–4, 2026 LHC Group data breach People affected: 6,602+ (WA verified; national TBD) Vendor-credential patient data breach; substitute notice and mailed notices around September 3–4, 2026. Read about the breach
  6. Disclosed September 8, 2026 Hibbett Retail data breach People affected: Not disclosed nationally Employee/personnel data breach; Notices of Data Breach dated September 8, 2026, with a sample filed to the California AG. Read about the breach
  7. Disclosed September 4, 2026 Catalyst Brands data breach People affected: Not disclosed HR/payroll vendor data breach; Notices of Data Breach dated September 4, 2026, with a sample filed to the California AG. Read about the breach
  8. Disclosed September 8, 2026 Veradigm data breach People affected: Not disclosed Third-party vendor cybersecurity incident affected certain data tied to a small number of Veradigm customers (Form 8-K). Read about the breach
  9. Disclosed September 2, 2026 Thomson Reuters C-Track data breach People affected: Not disclosed Unauthorized party obtained certain C-Track court case management files; notifications underway for a subset of people in affected court records. Read about the breach
  10. Disclosed September 1, 2026 IDScan.net data breach People affected: Unconfirmed Dark-web identity theft service claimed exposure of 153M+ U.S. and Canadian driver's license scans; company confirmation of scope still pending. Read about the breach
  11. Disclosed August 31, 2026 Bimbo Bakeries USA data breach People affected: Not disclosed Oracle E-Business Suite zero-day; unauthorized parties acquired files from the EBS application. Notifications underway with complimentary monitoring. Read about the breach

For organizations

Responding to a breach at your organization?

If your organization has experienced a data breach, talk with AI Protection about protecting the people affected.

Breach response for organizations