Breaches
Data breaches we’re tracking
When a company discloses a breach that exposed personal information, we publish a page on what is known, what information was involved, and what affected people can consider doing.
Check my email
No letter, but worried? Enter your email and we’ll tell you which breaches include you.
Incident pages
- CenterPoint Energy data breach Form 8-K (September 14, 2026): unauthorized third party obtained personal information relating to a portion of customers; investigation of scope ongoing. Read about the breach
- Accela data breach Government-software vendor breach; California AG sample filed September 14, 2026, with mailed notices the same day (8,629+ CA residents named). Read about the breach
- McKesson data breach Unauthorized access to third-party applications with data exfiltration; substitute notice says personal information, including PHI, may have been impacted for people served through McKesson customers. Read about the breach
- Call-on-Doc data breach Online healthcare provider; Notice of Data Breach / California AG sample around September 17–18, 2026, after unauthorized network access potentially involving PHI. Read about the breach
- LHC Group data breach Vendor-credential patient data breach; substitute notice and mailed notices around September 3–4, 2026. Read about the breach
- Hibbett Retail data breach Employee/personnel data breach; Notices of Data Breach dated September 8, 2026, with a sample filed to the California AG. Read about the breach
- Catalyst Brands data breach HR/payroll vendor data breach; Notices of Data Breach dated September 4, 2026, with a sample filed to the California AG. Read about the breach
- Veradigm data breach Third-party vendor cybersecurity incident affected certain data tied to a small number of Veradigm customers (Form 8-K). Read about the breach
- Thomson Reuters C-Track data breach Unauthorized party obtained certain C-Track court case management files; notifications underway for a subset of people in affected court records. Read about the breach
- IDScan.net data breach Dark-web identity theft service claimed exposure of 153M+ U.S. and Canadian driver's license scans; company confirmation of scope still pending. Read about the breach
- Bimbo Bakeries USA data breach Oracle E-Business Suite zero-day; unauthorized parties acquired files from the EBS application. Notifications underway with complimentary monitoring. Read about the breach
For organizations
Responding to a breach at your organization?
If your organization has experienced a data breach, talk with AI Protection about protecting the people affected.